Yes, the FileVaultMaster.keychain has both the private key and the certificate inside it. I imported the .keychain into Keychain Access to verify.
I also ran the unlock-keychain command prior to decryption. Master password worked fine to unlock it as it went directly back to the command prompt with no error.
Lucas Moore
>>> "Trouton, Rich R" <trout
...@JANELIA.HHMI.ORG> 11/14/2012 10:58 AM >>>
On Nov 14, 2012, at 10:44 AM, Lucas Moore wrote:
> Through testing of my 10.8 image I've found that I cannot decrypt a FileVault 2 volume through Apple's published methods. I have followed their KB article at
http://support.apple.com/kb/HT5077?viewlocale=en_US just like I did with our 10.7 image. Encryption happens without a hitch. When I reboot into the Recovery Partition to test decryption I get "error -69749: Unable to unlock the Core Storage volume" after running the diskutil cs unlockVolume command from Step 9. The private FileVaultMaster.keychain is on an external drive and unlocks fine with our Master Password. I found someone with my similar issue posting here:
https://jamfnation.jamfsoftware.com/discussion.html?id=4588 but the solution to boot into the Recovery Drive does not fix my issue. Running the same commands from the Recovery Drive still offer up the same error message.
Lucas,
Can you verify the following?
1. That the FileVault Master keychain you're using has both the private and public keys inside?
2. Prior to running diskutil cs unlockVolume, that you've unlocked the keychain using the following command?: security unlock-keychain /path/to/FileVaultMaster.keychain
I've got a post available on this: http://derflounder.wordpress.com/2011/11/23/using-the-command-line-to...
The relevant section is named "Using FileVaultMaster.keychain on the command line"
Thanks,
Rich
---
Rich Trouton
trout
...@janelia.hhmi.org
JFRC Help Desk
phone: x4030
email: helpd...@janelia.hhmi.org
The best way to get in touch with me is through email.
_____________________________________________________
MacEnterprise, Inc
http://www.macenterprise.org
Subscription Options and Archives
http://lists.psu.edu/archives/macenterprise.html
_____________________________________________________
MacEnterprise, Inc
http://www.macenterprise.org
Subscription Options and Archives
http://lists.psu.edu/archives/macenterprise.html