So we've finally moved from a monolithic rebuild every time we needed to update from one OS release to another. Now I'm scratching my head as to patch management for our now FileVault 2 encrypted Macs? I'm testing the process for patching 10.8.2 to .3 and it will require a reboot. Per company policy this should run overnight to minimize production outage time. With the reboot, running via a policy remotely, it will just hang out at the FileVault login screen. I'm scratching my head as to how I should do this. If I were doing it via command line from my desk, I'd run through the fdesetup authrestart process manually, but that's not an option for our operations team.
Thoughts?
