We have about 550 active macs in our envorinment and we use fileVault to ensure they are safe. We used to use file vault 1 back in the day but moved to FV2 individual when it came out. It was decided at the time that individual was better.
The problem were facing is people are leaving the company and e-discovery needs to scan their machines. So for every 5-6 machines they get about 2 don't have the recovery key in JAMF. It shows that the hard drives are encrypted (and the e-discovery tech can verify that) but under management it says the FV isn't configured. This leads to a big issue since their procedures state that the hard drive has to be remove and kept. A new hard drive costs 500-1000 depending on the size. So they would like this issue resolved.
So first step is I'm working on convincing them that a individual and institutional key system would work better. This way we can always unlock a machine when needed. Problem is that even if we went to this system today - we still have many macs out there who I can't get the current recovery key for.
So it got me thinking - how exactly does Casper get the recovery from the user? When I look at my keychains and look at my recovery key - I can't see the actual key itself. So there must be a way Casper goes into keychain, decrpyts the key, uploads it to casper, and then encrypts it again on their database. So does anyone know the exact process? If it's something that I can replicate my plan is to write a script that gets the key and forces it to update in Caspers database.
Anyone else running into this issue?


