FileVault recovery key encryption

Has anyone found a way to decrypt the recovery key for MacOS FileVault, when you choose to save it into MobiControl platform?

It appears correctly into "Device Details", at the bottom, but the support team has been unable to explain how to decrypt it.

Any help would be appreciated, thank you.

3 years ago
SOTI MobiControl
ANSWERS
D
DJMOD@SOTI Bronze Contributor
3 years ago

Hi Manilo,

Thanks for requesting a response from SOTI Support Staff,

The actual encryption/decryption are implemented by the device firmware and initiated by the device end-user  (not by MobiControl server or agent), and MobiControl codes only check the encryption status reported by the device kernel and can trigger appropriate alert(s) to be reported back to the server/administrator.

MF
Manlio Fundaro
3 years ago

Hi there,

Thanks for your email.

This is not true, there is in fact a Mac Device profile that enables FileVault Disk encryption in the device and that is triggered by the agent, not the user. The same profile allows also to save the recovery key into MobiControl and that actually appears into "Device Details" tab, upon enabling it.

Problem is that the key is encrypted and we would need someone to explain us how to decrypt that key and make usable at all. Surprised that a feature MobiControl offers is not supported by SOTI, support team doesn't know anything about that and in this channel we get also misinformation. Disappointed.