Hi all,
I'm currently evaluating Casper Suite for my org, and found it makes a bunch of things we want to do really really easy. There's one thing that I couldn't completely figure out, though, and that's how to enable FileVault2 on the startup disk at imaging time. We do create a user for the "owner" of the machine at imaging time, so it would in theory be possible to use their password to activate FV2 on the startup disk. However, I haven't found an option to do so.
I can set a policy to enable FV2 when the computer is done imaging & when the main user has activated it, but that is too late for us - a bunch of the things that we wish to install on the machine must (by policy) live on encrypted volumes only.
I couldn't find an option to do this in Imaging (it does let me create user accounts, which can then later be used to activate FileVault2); I suppose I could build a post-imaging PKG or a script that runs fdesetup, but that too seems kinda convoluted (and I believe it would have to prompt the imaging person for the user's account password - something that the imaging tool already asks for at the beginning of the process). So - does anyone here have a sensible way to auto-enable FV2 before handing over the machine to someone else? (:
