Posted on 03-27-2013 07:04 AM
If a drive was encrypted without the use of Casper. Is there an easy way to rotate and then capture a new recovery key?
Solved! Go to Solution.
Posted on 03-27-2013 07:08 AM
No. You would need to decrypt it, then re-encrypt using a Casper policy. That way, Casper can capture the new recovery key and store it on the JSS.
Posted on 03-27-2013 07:14 AM
I think you need to decrypt it fully, then apply the Disk Encryption Configuration you have set up in Casper to it to re-encrypt and capture the key.
Though, there is a method outlined in another post on exactly how the Casper Suite captures that recovery key. It apparently gets stored in an xml file at time the recovery key is created and then the recon phase pulls that information in, populating the field in the JSS db and deleting the xml file on disk.
Take a look at this FR thread for more information on that:
https://jamfnation.jamfsoftware.com/featureRequest.html?id=1083
If you know what the current recovery key is, you can possibly use this method. Keep in mind though that since the encryption didn't get initiated from Casper, any Institutional key you may be using won't work to unlock that system,
Personally I think it would be best to decrypt and re-encrypt it properly, especially if you're also using an Institutional Master key, but there are the options.
Posted on 03-27-2013 07:08 AM
No. You would need to decrypt it, then re-encrypt using a Casper policy. That way, Casper can capture the new recovery key and store it on the JSS.
Posted on 03-27-2013 07:14 AM
I think you need to decrypt it fully, then apply the Disk Encryption Configuration you have set up in Casper to it to re-encrypt and capture the key.
Though, there is a method outlined in another post on exactly how the Casper Suite captures that recovery key. It apparently gets stored in an xml file at time the recovery key is created and then the recon phase pulls that information in, populating the field in the JSS db and deleting the xml file on disk.
Take a look at this FR thread for more information on that:
https://jamfnation.jamfsoftware.com/featureRequest.html?id=1083
If you know what the current recovery key is, you can possibly use this method. Keep in mind though that since the encryption didn't get initiated from Casper, any Institutional key you may be using won't work to unlock that system,
Personally I think it would be best to decrypt and re-encrypt it properly, especially if you're also using an Institutional Master key, but there are the options.