Skip to main content
Answer

Filevault - Boot Partition Encrypted

  • January 21, 2013
  • 9 replies
  • 33 views

Forum|alt.badge.img+18

How would you go about finding out why casper is only reporting: Boot Partition Encrypted vs All Partitions Encrypted, when I go into the inventory, I only see one drive and it says 100% encrypted.

Best answer by rich.trouton

To follow up on that, I've got an extension attribute available here:

https://github.com/rtrouton/rtrouton_scripts/tree/master/rtrouton_scripts/filevault_2_encryption_check

9 replies

Forum|alt.badge.img+13
  • Valued Contributor
  • January 22, 2013

FV1 vs FV2?


Forum|alt.badge.img+24
  • Valued Contributor
  • January 22, 2013

I've seen this in cases where an external disk was also plugged into the system while it was inventoried. I've never seen this occur when there was only one local disk. Do you have network drives that mount? I wonder if there was a mounted network disk which may make FileVault report "boot disk encrypted" instead and a network disk wouldn't show up in the "hard drives" section in the Casper inventory.


Forum|alt.badge.img+1
  • New Contributor
  • January 22, 2013

Bootcamp or Grub loader installed? Just started evaling casper this last week and the first thing I deployed was filevault 2 to a set of test machines. The one with bootcamp came back as "Boot Partition Encrypted". Since it will not be able to of course encrypt the other partition I would assume it comes by as only the boot partition was encrypted and not the rest.


Forum|alt.badge.img+24
  • Valued Contributor
  • January 22, 2013
Bootcamp or Grub loader installed? Just started evaling casper this last week and the first thing I deployed was filevault 2 to a set of test machines. The one with bootcamp came back as "Boot Partition Encrypted". Since it will not be able to of course encrypt the other partition I would assume it comes by as only the boot partition was encrypted and not the rest.

'

This is a great point. Technically speaking, FV2 is a volume-based encryption tool, not full disk. However in most cases there is only 1 volume anyway...


Forum|alt.badge.img+18
  • Author
  • Honored Contributor
  • January 22, 2013

Found it to be the users that had external HD'S plugged in.. Even though the drives were encrypted casper reported it as boot partition encrypted, instead of all..


mm2270
Forum|alt.badge.img+24
  • Legendary Contributor
  • January 22, 2013

I suggest you build your own Extension Attribute (or grab one out there already) to report on FileVault 2 status. Don't rely on the one built into Casper. its hard to pull any actual report on the state of encryption with it.


Forum|alt.badge.img+33
  • Hall of Fame
  • Answer
  • January 22, 2013

To follow up on that, I've got an extension attribute available here:

https://github.com/rtrouton/rtrouton_scripts/tree/master/rtrouton_scripts/filevault_2_encryption_check


Forum|alt.badge.img+18
  • Author
  • Honored Contributor
  • January 22, 2013

Awesome thanks Rich! Great blog by the way


Forum|alt.badge.img+19
  • Contributor
  • January 22, 2013

ooooh, that's a NICE fv2 ea! thanks, rich!!