Hey all,
I'm running into some issues with how Casper handles FileVault 2 encryption, and I'm hoping the community can provide some suggestions. I'll list them in order of which I'd like to get resolved first:
Macs enrolled (either via Imaging or QuickAdd) do not seem to reliably report their inventory information back to the JSS. Hardware, OS info, Applications and the such all appear to be reported accurately, but a Smart Computer Group with the criteria "FileVault 2 Partition Encryption State is Encrypted or FileVault 2 Partition Encryption State is Encrypting" is always empty as the partition encryption state always becomes "Unknown" once encryption has finished. However, I can still see the recovery key under the management tab for systems that have successfully encrypted via the JSS. The goal here is to have an ongoing policy to enable FV2, unless the computer is a part of the "already encrypted" smart group.
In our environment, when we enable FV2 for users, we enable both our management account and the user's account. Casper only gives the option for one or the other. The users should definitely be able to unlock their own drives or they have very expensive paperweights upon restart. The management account should also be able to do this in a pinch, though if we have the key, this is less important. Still, convention dictates that we should be able to do both and I haven't been able to find an easy way to do so.
We have a number of Macs out in the wild that are already encrypted, and I suspect that simply enrolling the computer and getting its inventory information will not give us the recovery key associated with it. We have an Excel spreadsheet (yay) containing a list of the Macs we have encrypted along with their recovery keys. Is there an easy way to import this information into the JSS? If not, what's the best way of going about getting all recovery keys stored in the JSS?
The second two may be large enough to warrant their own threads, but I'll see what happens.
Thanks in advance!
