FileVault 2 Encryption Recovery

ekkehard
Contributor

If a drive was encrypted without the use of Casper. Is there an easy way to rotate and then capture a new recovery key?

2 ACCEPTED SOLUTIONS

rtrouton
Release Candidate Programs Tester

No. You would need to decrypt it, then re-encrypt using a Casper policy. That way, Casper can capture the new recovery key and store it on the JSS.

View solution in original post

mm2270
Legendary Contributor III

I think you need to decrypt it fully, then apply the Disk Encryption Configuration you have set up in Casper to it to re-encrypt and capture the key.

Though, there is a method outlined in another post on exactly how the Casper Suite captures that recovery key. It apparently gets stored in an xml file at time the recovery key is created and then the recon phase pulls that information in, populating the field in the JSS db and deleting the xml file on disk.

Take a look at this FR thread for more information on that:
https://jamfnation.jamfsoftware.com/featureRequest.html?id=1083
If you know what the current recovery key is, you can possibly use this method. Keep in mind though that since the encryption didn't get initiated from Casper, any Institutional key you may be using won't work to unlock that system,

Personally I think it would be best to decrypt and re-encrypt it properly, especially if you're also using an Institutional Master key, but there are the options.

View solution in original post

2 REPLIES 2

rtrouton
Release Candidate Programs Tester

No. You would need to decrypt it, then re-encrypt using a Casper policy. That way, Casper can capture the new recovery key and store it on the JSS.

mm2270
Legendary Contributor III

I think you need to decrypt it fully, then apply the Disk Encryption Configuration you have set up in Casper to it to re-encrypt and capture the key.

Though, there is a method outlined in another post on exactly how the Casper Suite captures that recovery key. It apparently gets stored in an xml file at time the recovery key is created and then the recon phase pulls that information in, populating the field in the JSS db and deleting the xml file on disk.

Take a look at this FR thread for more information on that:
https://jamfnation.jamfsoftware.com/featureRequest.html?id=1083
If you know what the current recovery key is, you can possibly use this method. Keep in mind though that since the encryption didn't get initiated from Casper, any Institutional key you may be using won't work to unlock that system,

Personally I think it would be best to decrypt and re-encrypt it properly, especially if you're also using an Institutional Master key, but there are the options.