jamf encryptDisk- What is the recovery key?

nkalister
Valued Contributor

So, I was playing around with enabling FV2 using the JAMF binary today, and I noticed that the personal recovery key appears to be generated, but there's no obvious way to figure out what it is. After running the command, stdout echoes simply "Recovery Key=(...)". Also, the JSS didn't list the recovery key after running a recon, either- the machine showed invalid recovery key there . . . .
Anyone know how to capture the recovery key when FV2 is enabled in this way?

4 REPLIES 4

RaulSantos
Contributor

This will help with FV2 http://derflounder.wordpress.com/.

nkalister
Valued Contributor

Thanks, Raul, but Rich doesn't cover using the jamf binary to enable encryption.
I was able to get the recovery key up to the jss using the binary in conjunction with the "redirect recovery key to jss" configuration profile, but I'd still like to know if it's possible to get the recovery key to the JSS without that profile in place.

matt_jamison
Contributor

There is no way to get the recovery key into JSS without the profile but there is a feature request asking for something similar to that. https://jamfnation.jamfsoftware.com/featureRequest.html?id=1861

matt_jamison
Contributor

err... wrong one. https://jamfnation.jamfsoftware.com/featureRequest.html?id=1083 but this one you have to have the key and then manually enter it into JSS.

I agree though that if you enable FV with the jamf binary, it should upload the key directly.