Skip to main content
Question

FileVault helper script


loceee
Forum|alt.badge.img+10

This little guy helps you enable FV2. In our workflow, we have laptops with mobile network accounts. We don't want the initial FV provision to be done on the local admin / management account (for obvious reasons).

FVHelper will check and skip account names that match the skipaccounts array ...
it will then prompt users to enable FV ...
it calls the jamf policy (with attached FV config so FV is enabled and key escrow is handled by jamf) ...
then force them to logout, so they can enter their passwords and start the encryption process ...

You can run it on the login trigger and / or via Self Service.

https://github.com/loceee/OSXCasperScripts/tree/master/FVHelper

6 replies

loceee
Forum|alt.badge.img+10
  • Author
  • Contributor
  • 182 replies
  • October 13, 2014

external image link


Forum|alt.badge.img+7
  • Contributor
  • 40 replies
  • October 14, 2014

Awesome!


Forum|alt.badge.img+3
  • New Contributor
  • 9 replies
  • October 14, 2014

Love this! Been looking for a less invasive way for current users to be able to FV without having them stop what they're doing.

Any plans to implement a defer timer, a la Patchoo, where users can no longer defer?


loceee
Forum|alt.badge.img+10
  • Author
  • Contributor
  • 182 replies
  • October 15, 2014

Hey yeah, there are few things I'd like to add to it. It's quick and dirty to get the job done right now. More robust and error checking. Feature wise:

- Defer counter.
- Add additional FV users

Any other ideas that people come up with that might be useful. Thanks for the feedback and glad it's helping a few people out. Making our FV deployment much less painful!


loceee
Forum|alt.badge.img+10
  • Author
  • Contributor
  • 182 replies
  • October 22, 2014

Latest commit
-defermode (5 defers by default) !
-localise your prompts
-remove checking for receipt and check fv status with fdesetup

Get it while it's hot!


loceee
Forum|alt.badge.img+10
  • Author
  • Contributor
  • 182 replies
  • November 5, 2014

A new commit to fix osascript display from root. Weird it didn't affect any of my test vms, or all of my clients.
This work better.

https://github.com/loceee/OSXCasperScripts/tree/master/FVHelper


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings