Menu

Full system encryption failed

2016-09-01
2016-09-02
  • Sebastan Eriksson

    Earlier today i tried to do a full system encryption with veracrypt.

    First: i cant choose "encrypt the whole drive", only "encrypt the windows system partition".

    Second: after i choose a password and the computer reboots, i get this message: "veracrypt has been blocked by the current security policy". When i return to windows i get this message: "the veracrypt system encryption pretest failed". It also says "if the veracrypt boot loader did not ask you to enter the password before windows started, it is possible the your operating system does not boot from the drive on wich it is installed. This is not supported" I guess this is my problem? Any way to go around it?

    I have two discs on my computer, one where windows and everything else is installed and one wich seems to contain drivers from Lenovo.

    OS: windows 10
    Computer: Lenovo ideapad

    Thanks!

     
  • Enigma2Illusion

    Enigma2Illusion - 2016-09-01

    Do you have Secure Boot enabled in the BIOS? If yes, disable Secure Boot in the BIOS.

     
    • Sebastan Eriksson

      I have disabled it now, will try again tomorrow.

      Thanks!

       
  • Sebastan Eriksson

    What about not being able to select "encrypt the whole drive", can that also be connected to Secure boot being enabled?

     
  • Alex

    Alex - 2016-09-01

    EFI boot disk can't be full encrypted. GPT and EFI system boot volume has to be open because loader starts from EFI system boot volume

    Clarifications:
    1) EFI system volume is small (~100MB) volume FAT formatted with loader.
    To check contents of EFI system volume from cmd admin.
    mountvol z: /s
    dir z:

    2) OS volume is volume with Windows (several GB)

    OS volume is encrypted
    EFI system volume is open and contains VeraCrypt loader in EFI\VeraCrypt directory.

     

    Last edit: Alex 2016-09-01
  • Sebastan Eriksson

    How does it effect security that i'm only able to encrypt the windows system partition and not the whole drive? Sound to me that only the operating system will be encrypted and not all the contents on my harddrive?

    As you might understand i dont have advanced computer knowledge, just want my personal files to be safe.

     
  • Alex

    Alex - 2016-09-02

    Data written on system drive (e.g. C:) is encrypted. If there are other drives (e.g. D: E: etc.) data on these drives have to be encrypted as ordinary VeraCrypt volumes.

     
  • Martin

    Martin - 2017-04-06

    I have had the same 'veracrypt has been blocked by the current security policy'
    I've disabled By BootLog in Bias and still no luck.
    I've turned off McAfee and still no luck.

    Anyone have any suggestions please?

     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.