So it's coming down from our security team that we need to encrypt our Mac Laptops with some kind of encryption. I've been pouring over the forums, apple's white paper, casper's white paper, and Rich Trouton's video of FV2. I saw that in 10.8.2 there's a bug with AD and FV2, but it wasn't clear if it was fixed in 10.8.3. I have a couple other questions though...
What's the difference between the institutionalized and the individual keys and what instance which would be used? I believe the institutionalized keys are ones that IT sets as the password and the individual keys are set per user?
I see the fdesetup is a 10.8.x thing, so casper wouldn't be able to automate the 10.7.x machines?
What's the easiest way to automate the setup of FV2 on a new machine (10.8.x)? Would that be add the 2 local admin accounts and then once the AD user logs in they are set too?
How does recovery work? Say a machine gets dropped or gets somethign spilled on it and they need a new machine. How can we recover the data off the drive? On a PC we pull the drive out and slave it off another machine, put in the recovery key, and everything is unlocked. How does that work?
Is there a way to prevent a user from removing FV2?
