Posted on 01-21-2013 02:20 PM
How would you go about finding out why casper is only reporting: Boot Partition Encrypted vs All Partitions Encrypted, when I go into the inventory, I only see one drive and it says 100% encrypted.
Solved! Go to Solution.
Posted on 01-22-2013 11:49 AM
To follow up on that, I've got an extension attribute available here:
Posted on 01-22-2013 06:12 AM
FV1 vs FV2?
Posted on 01-22-2013 06:24 AM
I've seen this in cases where an external disk was also plugged into the system while it was inventoried. I've never seen this occur when there was only one local disk. Do you have network drives that mount? I wonder if there was a mounted network disk which may make FileVault report "boot disk encrypted" instead and a network disk wouldn't show up in the "hard drives" section in the Casper inventory.
Posted on 01-22-2013 10:16 AM
Bootcamp or Grub loader installed? Just started evaling casper this last week and the first thing I deployed was filevault 2 to a set of test machines. The one with bootcamp came back as "Boot Partition Encrypted". Since it will not be able to of course encrypt the other partition I would assume it comes by as only the boot partition was encrypted and not the rest.
Posted on 01-22-2013 10:50 AM
Bootcamp or Grub loader installed? Just started evaling casper this last week and the first thing I deployed was filevault 2 to a set of test machines. The one with bootcamp came back as "Boot Partition Encrypted". Since it will not be able to of course encrypt the other partition I would assume it comes by as only the boot partition was encrypted and not the rest.
'
This is a great point. Technically speaking, FV2 is a volume-based encryption tool, not full disk. However in most cases there is only 1 volume anyway...
Posted on 01-22-2013 11:11 AM
Found it to be the users that had external HD'S plugged in.. Even though the drives were encrypted casper reported it as boot partition encrypted, instead of all..
Posted on 01-22-2013 11:43 AM
I suggest you build your own Extension Attribute (or grab one out there already) to report on FileVault 2 status. Don't rely on the one built into Casper. its hard to pull any actual report on the state of encryption with it.
Posted on 01-22-2013 11:49 AM
To follow up on that, I've got an extension attribute available here:
Posted on 01-22-2013 01:26 PM
Awesome thanks Rich! Great blog by the way
Posted on 01-22-2013 02:28 PM
ooooh, that's a NICE fv2 ea! thanks, rich!!