Q: Partition Strategy for Bitlocker
This conversation was started over here: https://discussions.apple.com/message/22752994#22752994.
I run bootcamp and Parallels (the latter using the bootcamp installation as the guest OS) on a 15" rMBP with 256GB SSD. I use Win8 as the guest OS and Mountain Lion on the host. I have been trying to enable bitlocker in the guest OS and when I attempt to create another partition (required with bitlocker on a system drive) using the Win8 command:
BdeHdCfg.exe -target c: shrink -newdriveletter x: -size 1500 -quiet –restart
I receive the error:
Disk already has the maximum number of primary and extended partitions. Use the
'-driveinfo' command for a list of valid target drives.
This of course is related to the issue originally noted in this thread about hybrid MBR as I already have all four allowed partitions. It looks like there may be a way around this using some of the techniques described in this thread however rather than creating another partition visible to OSX (which is what OP did) I want to create two partitions visible to Win8. Would someone be so kind as to walk through how I would accomplish that?
Thank you!
In hopes of increasing the Google-ability of this thread for future people with this issue, Bitlocker Drive Encryption returns the message "Bitlocker Setup could not find a target system drive. You may need to manually prepare your drive for Bitlocker." The Event Log contains the following errors in the Bitlocker-DrivePreparationTool log:
Error Code: 0xC0A00007
Error Text: BitLocker Setup could not find a target system drive. You may need to manually prepare your drive for BitLocker.
and
A volume failed to meet the requirements for a target volume.
Volume Name: \\?\GLOBALROOT\Device\HarddiskVolume4
Reason: The system drive cannot be used for the merge operation.
Posted on Aug 17, 2013 2:30 PM
@Christopher Murphy
Thanks for all the feedback. Given the complexity of pulling this off, lack of assurances of future compatibilty and stability, and that I plan to update to both Mavericks and Win8.1 in the next couple months, I've decided not to attempt this.
For future folks who are interested in doing something similar I'll archive a bit of my research here. My goal was to have dual booting with OSX and Windows (bootcamp) as well as VM support via Parallels against the bootcamp install of Windows and have both OSes encrypted. The Parallels aspect only becomes a complication for one approach (more on that in a moment) but it appears that given current technology this is not possible without hacks and even that appears to be a bit iffy. Here are the approaches I looked into:
FileVault2: this is installed and working on the OSX partition, it does occupy a partition as the recovery partition is then manditory, more on that below.
Bitlocker: I was able to bypass the TPM requirement (this is well documented elsewhere, Google it) but with FileVault2 in place I could not provide enough partitions to use Bitlocker on the bootcamp system drive for Windows. Christopher has provided theoretical guidance above but this appears difficult and fraught with upgrade risk. If you did not need FileVault2 it appears that you could remove the recovery drive partition and then Bitlocker just on the Win/bootcamp side would be possible. I did not test that though as I want FileVault2 as well.
TrueCrypt: I looked into this next but it appears this has problems with the OSX GPT and not having enough space prior to the table to install required boot process code. In other words not currently supported for OSX with bootcamp. http://apple.stackexchange.com/questions/94135/bootcamp-and-macbook-pro-and-true crypt
Symantec PGP Drive Encryption: this appears to be a possibility if I were not trying to run the bootcamp install as a "VM" in parallels. Big warning though, Symantec's own documentation contridicts itself as whether whole drive encryption is possible with bootcamp. The latest guide states both that it IS and IS NOT possible. I found a statement from a Symantec support tech stating that it IS but the post was incoherent and seemed to be regurgitating some KB article without any real understanding of the underlying tech. This wasn't a valid solution for me but if you decide to pursue I would get confirmation from someone knowledgeable at Symantec first. http://www.symantec.com/connect/forums/justification-needed-how-does-pgp-wde-ens ure-security-apple-boot-camp
What I've decided to do is remove bootcamp. Since setting it up and immediately installing Parallels I've never hit bootcamp direct again and really never plan to as I the performance of Parallels has always been great for me. I always access it as a Parallels VM within OSX. I'll be importing to a Parallels VHD and relying on the fact that FileVault2 will be encrypting the VHD withing my OSX partition as my strategy. I may be back for advice on how to clean up the bootcamp partition and reclaim the space soon
Thank you Christopher and I hope my research is beneficial to someone else down the line.
Posted on Aug 18, 2013 3:03 PM
