I recently saw Rich Trouton's presentation on FileVault 2 deployment from JAMF National Users Conference, and have been working on a deployment method that can be used for my enterprise. The issue is that we are also in the process of moving our machines to being bound to our active directory as well. The strategy I would like to follow is as follows:
- Image Mac with 10.8.2.
- Bind to our AD, set AD accounts to be mobile
- Give to user
- User logs in
- Run fdesetup for deferred current with personal key and institutional keychain
- When user logs out, the FileVault is enabled
- Upon logging back in, a second script is run to enable macAdmin(visible admin account) and casperadmin(hidden account) for unlocking the mac via a plist file.
There are 2 issues I am having: The first is that any time the plist file is used, it does not want to add casperadmin. I am assuming that it is because that account is in /private/var, but I am unsure.
The second is that when doing a deferred filevault setup with an AD user, after putting in the password at logout, an error says that filevault cannot be enabled at this time, and the mac goes to shut down, and will sit indefinitely at the grey screen with a spinning cog, never turning off. once forced off, it powers on fine, but the AD user can no longer log in. When logging in, I get the notification that my AD password will expire soon (so it is communicating with the AD server), but after clicking continue, I get an error stating that I cannot log in with the account, as it failed because an error occured.
Has anybody had luck with enabling FileVault on AD bound machines?
