Skip to main content
Question

FileVault 2 Best Practices

  • April 18, 2013
  • 31 replies
  • 96 views

Show first post

31 replies

Forum|alt.badge.img+15
  • Contributor
  • August 9, 2016

To clarify, what I meant is you can't boot into single user mode if FileVault is enabled without having to enter a password first to unlock the volume.

I hadn't had to do this in a while, so I took this opportunity to go through all the steps again and review Apple's kbase article. It looks like the process has been made simpler. If you click the question mark in the password field on the FV unlock screen (or wait a certain amount of time) it now will let you enter the FV key right there. It's probably been like that for a while, but I hadn't noticed it before.


Forum|alt.badge.img+33
  • Hall of Fame
  • August 9, 2016

You can boot into single-user mode with FileVault 2 enabled, though you will need to unlock the volume as part of the process. For those interested, I have a post on this available via the link below:

https://derflounder.wordpress.com/2013/04/26/booting-into-single-user-mode-on-a-filevault-2-encrypted-mac/


Forum|alt.badge.img+15
  • Contributor
  • August 9, 2016

Well, without unlocking it first, I mean

EDIT - Don't know why this post got delayed by 18 hours.


Forum|alt.badge.img+16
  • Honored Contributor
  • August 9, 2016

Don's point about keeping the FV keys out of the JSS is a good one... I have read or heard that some admins are manually enable and re-directing them to AD and/or the same tool that stores BitLocker keys.

I just don't have the resources to do that...

C


Forum|alt.badge.img+15
  • Contributor
  • August 9, 2016

They seem pretty secure in the JSS though. Having them in two locations seems like it would increase the odds of them being exposed by a password leak into one of the (now twice as many) places they would now be stored. As I'm sure the people on this thread know, you can also deselect the checkbox for user privileges in your JSS, in theory giving admins/auditors/etc. access to every single JSS piece of data except the keys if that's what you prefer.


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • August 9, 2016

Our goal is always to leverage existing infrastructure where its possible and makes sense.

If there is a solution in place we can redirect FileVault 2 keys, it makes perfect sense to us.

Both from a security perspective, since the team who will handle already handles Bitlocker keys, but also as a diaper, in case something happens to JSS, like having to migrate to a new JSS because the existing JSS went kablooie (which can happen to ANY solution).