4 Replies Latest reply on Nov 8, 2016 9:57 PM by slyronit

    TPM/Bitlocker bug with BIOS 0056 NUC5PPYH

    slyronit

      The BIOS update 0056 (PYBSWCEL.86A) for NUC5PPYH doesn't work well with Bitlocker on C:. Here's what happens

       

      1. On BIOS, build 0055, Bitlocker enabled, windows works/boots well without any issues. I suspend Bitlocker protection, update the BIOS to 0056, the OS asks for the recovery key everytime during boot. Suspending and Enabling protection doesn't help, clearing the TPM keys doesn't work either, nor does disabling/enabling secure boot and re-generating the keys from BIOS.

      2. Clean Windows 10 install on BIOS 0056. When I try to enable Bitlocker on C:, it asks me whether I want to perform checks to see whether Bitlocker will work properly. If I perform the checks, Windows reboots and tells me Bitlocker cannot be enabled because C:\ cannot be auto-unlocked on boot. If I choose not to perform these checks, bitlocker asks for the recovery key on every boot. Suspending and Enabling protection doesn't help, clearing the TPM keys doesn't work either, nor does disabling/enabling secure boot and re-generating the keys from BIOS.

      3. Flash back to BIOS 0055, Windows asks for the recovery key, once entered, it doesn't ask for the recovery key during subsequent reboots.