Servicing a FileVault 2 MacBook

FastGM3
Contributor

So we've just hit our first snag since implementing FileVault 2 on our new Teacher MacBooks. How the heck do we service them without the user's password? We have some data to copy over for a Teacher but don't have her account info, she's unavailable.

Is there any way? What about our other user accounts that were initially on the computer, how could we log with them and maybe copy the data to a public folder?

Is the master Casper encryption password helpful in this case at all?

TIA,
Chuck

2 REPLIES 2

jarednichols
Honored Contributor

Boot from an external disk. diskutil corestorage unlockVolume is your friend.

Have a look at Rich Trouton's info: http://derflounder.wordpress.com/2011/11/23/using-the-command-line-to-unlock-or-decrypt-your-filevau...

mm2270
Legendary Contributor III

Did you deploy FileVault 2 from your Casper environment to it? If so, you should have captured the Recovery key for the Mac. Use that to log into the Mac or unlock the volume while booted up from another drive.

If you need some help with that, post back. Also check out Rich Trouton's blog for more on how to work with a FileVault encrypted Mac. He's got a ton of great info on there.
http://derflounder.wordpress.com/

If you do not know or did not capture the recovery key and you also don't know a FileVault enabled user's password, you're going to be out of luck I'm sorry to say. if it were easy to get past the encryption layer without one or the other above items, it wouldn't be very secure, would it.