Is it possible to inventory a recovery key for an Already Encrypted FileVault volume?

powellbc
Contributor II

We have a number of machines in our inventory which were Filevault 2 encrypted prior to upgrading to JSS 8.6. Is there a way for their individual recovery keys to be inventoried and retrieved or do the machines need to be unencrypted and then re-encrypted using the JSS?

1 ACCEPTED SOLUTION

rtrouton
Release Candidate Programs Tester

You will need to decrypt the Mac, then encrypt the Mac again using a Casper policy. That will enable the JSS to record the new individual recovery key as part of the encryption process.

View solution in original post

2 REPLIES 2

rtrouton
Release Candidate Programs Tester

You will need to decrypt the Mac, then encrypt the Mac again using a Casper policy. That will enable the JSS to record the new individual recovery key as part of the encryption process.

powellbc
Contributor II

That is what I thought. Thanks for the info!