Good afternoon all. I deployed encryption to a test environment by creating a policy and adding computers manually to the scope, after setting up the FileVault configuration using "Current or Next User" and "Institutional" key. I had been given a key created on a Mac laptop and exported to me that served as an institutional recovery key.
So, to test the thing I went ahead and coveniently "forgot" my password on my encrypted MacBook Air and attempted to get in. This MacBook Air is running 10.11.6 and I don't login with AD credentials.
I went into OS X Recovery and ran the terminal commands and found out that the exported file wasn't right? It was a .pem file and it wanted a .keychain file? So, I then created a keychain in keychain access and put the recovery key in it. That did not work eith. I got an error that indicated: "Unable to unlock the core storage volume".
So after speaking with JAMF support I tried to get the private key to the keychain I'd previously been given. Well, the person that gave it to me doesn't seem to be able to pass the password challenge to export it. Thank goodness this is a test!
Does anyone have any advice on how to get into this Mac? I just want to know how.
By now it seems obvious to me that the way I deployed encryption can't be the simplest, best practice?
Can you all help me?
Thanks.
Brad Terhune
