1427 How To Create an Emergency Disk for an SD 6.1 FileVault Client and Use It To Recover a Client Device

Prev Next

How to create an emergency disk for an SD 6.1 FileVault client and use it to recover a client machine

This article describes how to create and apply recovery information for a Mac FileVault 2 device. This method can be used when a user forget their password and wants to unlock their device:

  1. On SES, right-click Mac FileVault device and choose Create Emergency Disk.
  2. The recovery information is contained in one file (which is the master keychain) and the name of the file is the LVUUID of this device.
  3. A dialog appears which shows you the master password of this keychain. Please take note of it.
  4. Copy this file to removable media.
  5. Restart the Mac FileVault device and press and hold <command> + <R> when you hear the chime to access Recovery HD.
  6. Insert the removable media.
  7. Under Utilities, open up Terminal.
  8. Enter the following commands in Terminal:
    security unlock-keychain <full path to keychain file>
    You will be prompted to enter the master password.
    diskutil cs unlockVolume <LVUUID> -recoveryKeychain <full path to keychain file>
  9. This unlocks the keychain and unlocks the device (most importantly). In Disk Utility, you will see the device appear as mounted.
  10. From this point, users can do one of two things: they can either backup their data or they can disable FileVault for this device.
  11. To disable FileVault from Terminal, first type "MOUNT" in terminal to see what disk number your volume is in. Then enter the following command:
    diskutil cs revert disk(whichever number you found) -recoveryKeychain <full path to keychain file>
  12. Once you reboot, Apple's preboot will no longer be there and the user can access the machine.

Custom Fields

  • Operating System: Mac