Using Mac OS X 10.7 Filevault with Centrify DirectControl August 2011, Revision 2 OS X 10.7's Filevault has the ability to encrypt the entire disk. Full Disk Encryption is compatible with Centrify Active Directory users. However, only Active Directory users configured as mobile users with portable home directories can be granted the authority to unlock the disk. Configuring Active Directory Users with Mobile Home Directories A regular Active Directory user is known as a network user on the Mac. The Mac does not have a user record defined locally in the Users and Groups System Preference panel for this user. A mobile home directory user is both an Active Directory user and someone with a user record defined locally. A mobile home directory user also has a home directory somewhere on the network. When a mobile user is created, the network home directory is linked to the local home directory on the machine. The Mac OS then keeps the two home directories in sync whenever the machine is on the network. Note the user is defined as a Network user 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 1
Filevault encryption requires the Active Directory user to be a mobile user. It requires the user to have the local account record present in the Users and Groups System Preference panel. To create a mobile account for a user, unlock the control panel, then press the Create button next to the Mobile account label. If you want to have the user s home directory synchronized with the network directory, then configure the synchronization settings to automatically sync the home folder. It is possible to configure a mobile user that has no network home directory. Set the Sync popup to Manually and unselect all the listed folders. This will configure the system so that no directories are linked and that syncing would never occur without user intervention. Press the Create button. After creating the mobile account, the user s record will now be listed as a Mobile user. You can also use Centrify s Group Policy modules to configure Mobile Home Directories for all Macs in your environment. Consult the Macintosh Support Center at http://www.centrify.com/support/macsupport-center.asp for more details on Group Policy and Mobile Home directories. 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 2
Enabling Filevault You turn on full disk encryption in the Security and Privacy -> Filevault system preference. You have to specify which users are authorized to unlock the disk. This dialog will include local user accounts and Active Directory users with mobile accounts. You will be presented with a Recovery Key. 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 3
It looks similar to this: It's important to write this down somewhere. If you do not save this key, you can't decrypt your disk if you lose the user passwords. You can also choose to store it with Apple. 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 4
After you turn on Full Disk Encryption, it may take 6-10 HOURS for the encryption to complete. (It didn t really take 19 days to decrypt the disk.) 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 5
Logging on After the computer is restarted, the Mac displays the list of users who can unlock the disk and login. This list can include local users and Active Directory users with portable home directories. It does NOT provide you with a username/password entry dialog box. After the disk has been unlocked and a user has logged in, then it's possible to have other Active Directory users log in. You can then log out, and will get a username/password dialog box, or you can use the Fast User Switch function to enter a different Active Directory user account. Adding Additional Active Directory Users You can authorize additional Active Directory users to unlock the disk by going back to the Security and Privacy -> Filevault system preference. Note the "Some users are not able to unlock the disk." notice. Press the "Enable Users" button to select more users. 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 6
Enable your additional users here. 2011 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. PAGE 7