I used this process to rekey/ key escrow all my Macs on High Sierra and Mojave, and it seems to be working fine.
https://github.com/homebysix/jss-filevault-reissue
I am seeing some strange behavior, however. Someone told me they were asked to Rekey/Escrow multiple times. Upon checking the policy logs, I can see a few users were asked to Rekey again a few weeks after they've initially Rekeyed.
I can't seem to find any similarities between the computers that this is happening to.
Has anyone experienced this?
Its almost like the key goes bad or gets corrupted.
