google / macops

Utilities, tools, and scripts for managing and tracking a fleet of Macintoshes in a corporate environment
Apache License 2.0
819 stars 86 forks source link

update macdestroyer to work with high sierra and recovery key #66

Open keeleysam opened 7 years ago

googlebot commented 7 years ago

Thanks for your pull request. It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

:memo: Please visit https://cla.developers.google.com/ to sign.

Once you've signed, please reply here (e.g. I signed it!) and we'll verify. Thanks.


keeleysam commented 7 years ago

I signed it!

googlebot commented 7 years ago

CLAs look good, thanks!

tburgin commented 7 years ago

Looks like this will only work for folks using crypt. We will need to find a more general solution for APFS crypto users. fdeadduser does still work when I tested on 10.13, but for HFS only. Make sense, some work will have to be done for APFS.

russellhancox commented 7 years ago

Yeah, I'd like to see a solution that doesn't involve having to have the recovery key on disk but given the prevalence of Crypt in the community I'd be OK with merging if you change the condition on line 65 to also check for the presence of the recovery key file.

If we find a way to fix fdeadduser later we can then revert this or only use it as a backup in case fdeadduser fails.

keeleysam commented 7 years ago

I made a bunch of changes that checks for APFS, SIP, and if the user was actually successfully added. Bash is fun.