Has anyone had issues with FileVault 2 automatically reenabling itself?
Several months ago I set up a Self Service policy to encrypt boot drives with an Institutional + Individual key. After some successful testing I scoped it to 3 of my own Macs and encrypted those boot drives. Everything has been working fine and I have not had any reason to think anything is amiss. I even recently successfully tested it again with two test Macs. So I now have 5 devices encrypted with this policy.
I’m now needing to mass deploy FileVault configurations in other JSSs I control, and for the sake of reinforcing my knowledge from my past effort, I decided I wanted to start with a clean slate and create new keys and new policies.
So I started the process by turing off FileVault on two of the Macs, one being my own. The decrypting process went without a hitch. Then upon rebooting one of the Macs I was presented with the same encryption process dialog I would exptect to receive after initiating an encryption policy through Self Service and following through with the reboot. I hadn’t noticed the behavior on the test Macs because I was reimaging them instead of decrypting them. But they too re-encrypt after the reboot following decryption.
The same thing happens with 3/4 of the other Macs (I haven’t touched the 5th one yet). I turn off encrytion, and upon reboot encryption is forced.
I tried several things in the JSS like disabling the policy, removing scoped devices etc. but nothing works. I finally deleted the policy and still no change.
There is noting in the policy logs about these events, nor in the policy log histories of the devices, nor do any FileVault policies appear in the Management/Policy tab for the devices, which led me to my next experiment: With one of the test Macs I ran sudo jamf removeFramework and decrypted the drive and removed the device from the JSS, and encryption was still forced after reboot.
I did discover with my own Mac if I log in to a local admin account I do not get the prompt to encrypt, however when I log in to my own account I do get the prompt. So it seems there is something cached and associated with my user account that is causing this to happen.
Any thoughts?
