So I decided to try managing FileVault with Casper, and I setup a profile as they did in this video:
http://www.youtube.com/watch?v=mz1H__EsnPM
We bind our Macs to AD with Centrify.
Encryption went fine (although it was showing the users the key, so I got some post-its with "Do you need this"). I was then getting reports that users couldn't change their password, that the button was greyed out. I finally found that by removing the FileVault profile, the button enabled again.
This is despite not setting any options under Security & Privacy => General tab. And then changing "Allow user to change password" both on and off.... didn't matter, still grayed out. Only thing that changed it was removing the profile.
Mavericks 10.9.2, Centrify 5.1.3. Haven't patched our JSS to latest yet, I think I'm one behind.
