homebysix / jss-filevault-reissue

A framework for re-escrowing missing or invalid FileVault keys with Jamf Pro.
Apache License 2.0
186 stars 56 forks source link

Script runs, but key does not sync to Jamf. #52

Closed shane-rxrevu closed 2 years ago

shane-rxrevu commented 2 years ago

Summary

Hi There! The script runs on our macs and the new key is successfully generated, but the new key does not sync to Jamf and remains "unknown" in the encryption status. Any experience with this?

homebysix commented 2 years ago

Hi @shane-rxrevu - Does this "unknown" status persist even after two sudo jamf recon runs?

RHI0 commented 2 years ago

The answer for me to that question Elliot would be yes, my policy runs the script followed by back to back recons. I've even manually run another two after that just to be 100% certain and I'm still left with unknown in Jamf.

I wonder if @shane-rxrevu has an environment like mine where the user isn't admin (this is new to us) and if that would make a difference? I wouldn't think so as Jamf should run all things via Self Service as elevated.

To be clear, this happens only on about 10% of the machines I've run it on and it usually plagues that machine indefinitely but for no reason that I've been able to find to 100% correlate resulting in me just fixing the issue manually.

homebysix commented 2 years ago

When you say "fixing the issue manually," is that this command?

sudo fdesetup changerecovery -personal

If so, I'd be interested in the output of the script, and the output of the above command in isolation.

RHI0 commented 2 years ago

I’ll make sure to grab the logs from Jamf and send them over next time I hear of it.

When this occurs, the script still reports out as successful.

Rhio Champine Workstation Engineering


From: Elliot Jordan @.> Sent: Tuesday, March 22, 2022 12:28:02 AM To: homebysix/jss-filevault-reissue @.> Cc: Rhio Champine @.>; Comment @.> Subject: [EXTERNAL] Re: [homebysix/jss-filevault-reissue] Script runs, but key does not sync to Jamf. (Issue #52)

CAUTION: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.

When you say "fixing the issue manually," is that this command?

sudo fdesetup changerecovery -personal

If so, I'd be interested in the output of the script, and the output of the above command in isolation.

— Reply to this email directly, view it on GitHubhttps://urldefense.com/v3/__https://github.com/homebysix/jss-filevault-reissue/issues/52*issuecomment-1074742105__;Iw!!FSOJMA!ZzX7K7v53LaWn6PBtQK5dloFIEY-naaHTxTukOZAtQfqKtcGbxOMDlOo3VhkXF2H$, or unsubscribehttps://urldefense.com/v3/__https://github.com/notifications/unsubscribe-auth/AJL6TIHZXSNWNLKNSZVJSKTVBFK6FANCNFSM5M4JGSEA__;!!FSOJMA!ZzX7K7v53LaWn6PBtQK5dloFIEY-naaHTxTukOZAtQfqKtcGbxOMDlOo3Zc8gMto$. You are receiving this because you commented.Message ID: @.***>

This email and any files transmitted with it are confidential, proprietary and intended solely for the individual or entity to whom they are addressed. If you have received this email in error please delete it immediately.