Encrypting the OS drive

2025-05-23Last updated

To keep your Streamvault™ appliance and Windows administrator password secure, you must encrypt the OS drive (C:) with BitLocker.

Before you begin

When the OS drive is encrypted with BitLocker, the decryption key is saved on a Trusted Platform Module (TPM) chip located on the system board of the Streamvault appliance. If the OS drive were to be removed or the system board replaced, the information on the OS drive would be lost. The OS drive wouldn’t be able to access the decryption key on the TPM. You can create a recovery key that can be used to decrypt the drive in these scenarios. Without a recovery key, the appliance must be re-imaged and the software re-installed.

The storage disk is primarily used for storing video archives and isn’t encrypted with BitLocker. You can use Security Center features to encrypt video archives at rest.

Note:
The BitLocker feature is available as of SV Control Panel 3.2. The feature also introduces a hardening profile update for appliances with hardening management capabilities. You can get this update by downloading the Streamvault service from the Genetec™ Update Service (GUS) or GTAP. To fully benefit from the BitLocker feature, we encourage you to both encrypt the OS drive and apply the hardening profile update, if applicable.

Procedure

  1. In the SV Control Panel, click the Security tab.
  2. In the BitLocker section, click Protect next to the OS drive field.
    SV Control Panel - Protect OS drive feature on the Security page.
    Note:
    If the OS drive is already encrypted, the Protect button is replaced by a Protected status.
  3. When asked if you want to turn on BitLocker, click Yes.
    The OS drive is encrypted, the decryption key is saved on the TPM, and a recovery key is created. By default, the recovery key is saved on a fixed data drive. If no fixed data drive exists, such as on a workstation, the recovery key is saved on a USB key.
    Important:
    If you save the recovery key on a fixed data drive, ensure that you move the key to a secure location and delete it from the appliance.
  4. (Optional) If there’s no fixed data drive or USB key, you can choose whether to proceed with the encryption without creating a recovery key. Do one of the following:
    • Click Yes to continue without creating a recovery key.
    • Click No to cancel the encryption.
    Note:
    If you choose not to create a recovery key, you can create one later. For more information, see Creating a recovery key.