[DISCUSSION] Server 2022 LTSC (21H2) 20348.1 (fe_release)

Discussion in 'Windows Server' started by Enthousiast, Mar 2, 2021.

  1. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    17,201
    90,725
    340
  2. Hacker?pcs

    Hacker?pcs MDL Member

    May 28, 2009
    180
    76
    10
    Will Server 2022 be based on Windows 10 (21h1 or 21h2?) or Windows 11?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. pm67310

    pm67310 MDL Guru

    Sep 6, 2011
    3,349
    2,522
    120
    windows 10 21h2
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. ch100

    ch100 MDL Addicted

    Sep 11, 2016
    841
    704
    30
    None of them. It is more or less an evolution of Windows Server 2019, so in a sense is based on Windows 10 v1809 updated.
     
  5. RobrPatty

    RobrPatty MDL Expert

    Jul 23, 2009
    1,281
    593
    60
    #446 RobrPatty, Aug 15, 2021
    Last edited: Aug 15, 2021
    Another internal update Server 20348.202. Hopefully available soon
     
  6. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,656
    103,420
    450
    please:)
     
  7. DrunkF

    DrunkF MDL Junior Member

    Jun 15, 2010
    78
    23
    0
    Can someone who installed Server 2022 + all updates, be so kind to check that it has successfully managed to "own" their TPM? Basically does BitLocker work (after being installed as a feature) to encrypt boot disk?

    Or can run the "Get-Tpm" cmdlet? It output of "Get-Tpm" should look like this:

    TpmPresent : True
    TpmReady : True
    TpmEnabled : True
    TpmActivated : True
    TpmOwned : True <- Here, owned
    RestartPending : True
    ...

    I have tried everything, Server 2016, 2019 (TPM/Bitlocker work fine), Windows 10 21H1 (again fine) and even Windows 11 (again fine) - but it's just impossible to get 2022 to own the TPM! On 2022 it looks like this:

    TpmPresent : True
    TpmReady : True
    TpmEnabled : True
    TpmActivated : True
    TpmOwned : False <- Here, not owned
    RestartPending : True

    I have tried just about everything to get it going:

    - TPM has been cleared many, many times.
    - TPM has been provisioned many, many times - always results in "reduced functionality"
    - Secure Boot is enabled.
    - Both storage and attestation are Ready.
    - EK certificate chain present and valid (Intel).
    - Management level is "Full" all commands are allowed. Tried many tools including Windows 11's new TPM diag.
    - PCR7 binding is "possible" but has not been "bound" yet.
    - DMA-capable buses are allowed in registry hive.
    - PCR (SHA256) registers seem OK - but I have not done a validation of their values. Will try this.

    All I can think of is that Server 2022 requires more stringent measured boot settings which many boards - except OEMs like Lenovo - leave disabled in PTT firmware. Perhaps even client Windows 11 does not require such stringent security checks?

    Thanks all!
     
  8. pm67310

    pm67310 MDL Guru

    Sep 6, 2011
    3,349
    2,522
    120
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. DougQuaid

    DougQuaid MDL Junior Member

    Aug 15, 2012
    56
    86
    0
    @DrunkF on 7th gen intel NUC, secure boot disabled
    Code:
    TpmPresent                : True
    TpmReady                  : True
    TpmEnabled                : True
    TpmActivated              : True
    TpmOwned                  : True
    RestartPending            : True
    ManufacturerId            : 1229346816
    ManufacturerIdTxt         : IFX
    ManufacturerVersion       : 5.62.3126.0
    ManufacturerVersionFull20 : 5.62.12.13824
    
    ManagedAuthLevel          : Full
    OwnerAuth                 :
    OwnerClearDisabled        : False
    AutoProvisioning          : Enabled
    LockedOut                 : False
    LockoutHealTime           : 2 hours
    LockoutCount              : 0
    LockoutMax                : 32
    SelfTest                  : {}
     
  10. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,656
    103,420
    450
  11. ch100

    ch100 MDL Addicted

    Sep 11, 2016
    841
    704
    30
    Homebrew? :cool:
     
  12. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,656
    103,420
    450
    MS DaRT integration;)
     
  13. ch100

    ch100 MDL Addicted

    Sep 11, 2016
    841
    704
    30
    I know what it is, I did my own DaRT ISOs in the past, but stopped at Windows 8.1 which still works for most purposes on Win 10.
    Maybe I should pay more attention to your work and update my tools.

    BTW, it was a joke, mostly for the understanding of the other people reading this thread, this is a multipurpose tool used primarily for recovery beyond the capabilities of the regular Windows ISO and it is not a Windows image, so it can hardly be classified as homebrew. :D
     
  14. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,656
    103,420
    450
    After using the tool on an ISO, the ISO will be considered homebrew :D
     
  15. DrunkF

    DrunkF MDL Junior Member

    Jun 15, 2010
    78
    23
    0
    Many thanks!

    Wow - did not even know of any NUCs with dedicated, 3rd party, TPMs (IFX); thought all relied of Intel's own ME/PTT. Will try another system then.
     
  16. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,656
    103,420
    450
  17. oilernut

    oilernut MDL Senior Member

    Jul 8, 2007
    462
    358
    10
    Also released this morning on the VLSC site, so it's pretty much officially released now.
     
  18. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    17,201
    90,725
    340
  19. microtechton

    microtechton MDL Member

    Sep 11, 2018
    112
    810
    10
    #460 microtechton, Aug 19, 2021
    Last edited: Aug 19, 2021