@Paris1948 In theory, yes if you could put your bootloader back exactly the way it was, then the "platform integrity check" would succeed and the TPM would release the key to unlock your Windows partition. But I don't know if that's actually feasible. Even if you set up those partitions and OSes again and created entries for them in Grub, I don't know if that would be EXACTLY the way it was. I don't know Grub very well, so I don't know if there are randomly generated IDs involved in some aspect of this, in which case it wouldn't be exactly the same even if you built something that looked and worked exactly the same. You might be stuck until you can get that Recovery Key. Going forward I would recommend storing those types of keys somewhere that is safe but that you can also access remotely. I personally use LastPass as a password manager, and it has a Secure Notes feature that I use to store other sensitive text data like these keys.
jphughan
9 Legend
•
14K Posts
0
January 7th, 2021 08:00
@Paris1948 In theory, yes if you could put your bootloader back exactly the way it was, then the "platform integrity check" would succeed and the TPM would release the key to unlock your Windows partition. But I don't know if that's actually feasible. Even if you set up those partitions and OSes again and created entries for them in Grub, I don't know if that would be EXACTLY the way it was. I don't know Grub very well, so I don't know if there are randomly generated IDs involved in some aspect of this, in which case it wouldn't be exactly the same even if you built something that looked and worked exactly the same. You might be stuck until you can get that Recovery Key. Going forward I would recommend storing those types of keys somewhere that is safe but that you can also access remotely. I personally use LastPass as a password manager, and it has a Secure Notes feature that I use to store other sensitive text data like these keys.
Paris1948
2 Posts
0
January 7th, 2021 23:00
Thank you @jphughan for your reply.
I guess I will give it a try since this is the only thing I can do at the moment. Indeed I will adopt better security practices going forward.