TweetFollow Us on Twitter

MacEnterprise: FileVault in the Enterprise, Part 2

Volume Number: 24 (2008)
Issue Number: 09
Column Tag: MacEnterprise

MacEnterprise: FileVault in the Enterprise, Part 2

Data security for OS X administrators

By Greg Neagle, MacEnterprise.org

Previously in MacTech

Data security is a hot topic in Enterprise IT these days. As laptop usage increases, pushing out traditional desktops, the risk to company data is greater than ever. If a laptop is stolen or lost, the replacement cost of the hardware may be a pittance compared to the value of the data stored on the laptop's hard drive.

Therefore many companies are mandating some sort of data encryption for company laptops. If a laptop is then stolen or lost, the data would be inaccessible to the thief. "Whole–disk encryption" is a direction many companies are moving toward, but as of this writing, there are no shipping products that will encrypt a Mac boot volume. So Mac administrators must work with what is available: a technology Apple calls "FileVault," which secures users' home directories with AES–128 encryption.

In part one of this series, we covered preparation and implementation of FileVault in an enterprise environment.

In this installment, we'll examine some of the issues you may encounter when implementing and supporting FileVault in an enterprise environment, and techniques and tools to use to deal with some of these issues.

Living with FileVault

Once encrypted, a FileVault–protected home directory is relatively transparent in operation to the user when he or she logs in. The main clue you'll see when using a FileVault–protected account is the FileVault icon replaces the "normal" home icon in the Finder.

It's important to realize that while the user is logged in, any other user that has access to the machine (either physically or over the network, say via SSH) and that has root or sudo privileges can still access the files in the user's home directory. This can be a good thing, or a bad thing, depending on your point of view. Only when the user is logged out are the files inaccessible, because the encrypted disk image is unmounted.


FileVault–protected home directory in the Users folder

This points out a security hole: what if a laptop is stolen while the user is logged in? In fact, this is a very likely scenario many users rarely log out or shut down; instead they simply put the machine to sleep by closing the lid. If a machine is stolen in such a state, the FileVault disk image is unencrypted and mounted, so the user's files are accessible.

To close this security hole, you'll want to enforce the Require password to wake this computer from sleep or screen saver setting found in the Security preference pane.


Security preference pane

This setting can be enforced using MCX policy. If a thief were to take a laptop configured in this manner, the password request would prevent them from accessing the logged–in user's files.

FileVault Issues

Some applications may behave poorly with FileVault–encrypted home directories. Some examples:

Final Draft 7 would crash at startup when launched from a FileVault–protected account; this was fixed in version 7.1.3:

http://media.finaldraft.com/downloads/readme_fd713.txt

  • Some Automator actions fail on FileVault–protected accounts:

    http://www.macosxhints.com/article.php?story=20051020203919140

    iMovie and GarageBand have known performance issues with FileVault home directories:

    http://docs.info.apple.com/article.html?artnum=93460

    http://docs.info.apple.com/article.html?artnum=42964

    http://docs.info.apple.com/article.html?artnum=93699

    http://docs.info.apple.com/article.html?artnum=93618

    http://docs.info.apple.com/article.html?path=GarageBand/4.0/en/6567.html

    FinalCut Pro and Express have performance issues as well:

    http://docs.info.apple.com/article.html?artnum=93454

    Other applications that need high–performance disk access may be similarly affected.

    There are certainly other applications that have issues. Be sure to test the important applications you use.

    In most cases, there are workarounds for the FileVault issues, but most of the workarounds open up data security issues once again, as they rely on moving data to a non–encrypted part of the disk. You'll need to decide how to handle this.

    Reclaiming unused space

    In 10.4 (Tiger), FileVault makes use of what Apple calls "Encrypted Sparse Disk Images"; the image files are very space–efficient. But as items are added and deleted, these image files can grow bigger than they need to be and some housekeeping must be done to recover unused space. If this is not done, eventually the disk image file will grow to fill all available hard drive space. Periodically at logout, the user is notified that the image is using more space than is needed and asks for permission to recover the unused space. If the user is in a hurry to shutdown, restart, or log back in, they can cancel this housekeeping task – but they shouldn't put it off forever! Depending on the size of the home directory and the amount of recoverable space, recovery can be quite fast, or take a very long time. Train your users to treat the computer with kid gloves during the space recovery – if they were to get impatient and turn off the computer or force a restart during the recovery process, they could corrupt the disk image, which could then lead to total loss of the home directory contents!

    With 10.5, the user experience is improved. FileVault now makes use of "sparsebundles", in which the disk image data is kept in a collection of files inside an enclosing directory. This revised format has several advantages, but the one relevant here is that unused space recovery is much, much faster. In fact, it's so fast that Apple no longer asks at logout if you want to reclaim unused space it just goes ahead and does it at each logout.

    A related issue: a user sees their hard drive is getting too full. They delete a bunch of files from their home directory and empty the trash. They are confused when there is no change in the available space on the hard drive. This is because the space is not reclaimed from the disk image file until logout (and, in Tiger, after the user agrees). Your support staff should be made aware of this issue, as it can cause much confusion.

    Recovering from a lost FileVault password

    If the user forgets their password, or changes their login password in a way that doesn't also update the FileVault password, they may find themselves locked out of their FileVault home directory. If you have the FileVault master password (and keychain), you can reset the password on the FileVault disk image.

    If password hints are turned on, after three unsuccessful attempts, a password hint will be shown, if one is set for the user's account. If there is no user password hint, or the user still enters an incorrect password, the login window will change, showing text directing the user (or an administrator) to enter the FileVault master password to reset the user's password and to unlock FileVault.

    In practice, I've found this to work only with purely local accounts protected with FileVault. Mobile accounts (those with Portable Home Directories) never show a password hint or the Master Password prompt, at least when testing in my environment. Fortunately, there is another way to unlock a FileVault–protected home directory: via the command line.

    Command–line FileVault Recovery

    Here's how to change the FileVault password from the command line. Log in as root, or with an account that has sudo privileges to act as root (Admin accounts by default on OS X have this ability). Watch the line breaks in the example below, all commands are entered as one single line:

    [mbp:~] gneagle% sudo security unlock–keychain /Library/Keychains/FileVaultMaster.keychain
    password to unlock /Library/Keychains/FileVaultMaster.keychain: 
    <enter FileVault master password>
    [mbp:~] gneagle% sudo hdiutil chpass /Users/someuser/someuser.sparseimage –recover /Library/Keychains/FileVaultMaster.keychain newstdinpass
    Enter new disk image passphrase:
    <enter your desired password>

    Be careful, as you are not prompted to confirm the new password. If you make a mistake, just run hdiutil chpass again.

    Leopard improvements

    A common scenario requiring the FileVault password to be changed is when the user changes their login password by some method other than the Mac OS X Accounts preference pane. For example, many organizations provide a web page to change network passwords. If a user changes their network account password in this manner, the FileVault password cannot be updated. The same issue occurs if the user uses multiple machines and changes their password on a machine other than the one with the FileVault–protected home directory.

    Under Tiger, this password mismatch almost always required administrator assistance to recover from. Leopard makes users' and administrators' lives easier in this regard: if a user authenticates at the login window with their correct network credentials, but the FileVault disk image cannot be unlocked with the current network password, the OS will now display a dialog asking the user to enter their previous login password. If the entered password can unlock the FileVault disk image, the disk image password is updated, and the user is able to login.

    Miscellaneous trivia

    You may have a need to determine if FileVault is turned on for a particular user of a machine. Since waiting for the user to step away from their machine so you can peek at the Security preferences pane while they are logged in isn't always practical, it's helpful to have another way.

    The most accurate way to determine if FileVault is enabled is to use dscl:

    [mbp:~] gneagle% dscl . read /Users/gneagle HomeDirectory
    HomeDirectory: <home_dir><url>file://localhost/Users/gneagle/gneagle.sparsebundle</url></home_dir>

    Note the file:// URL and the filename ending with ".sparsebundle" (or ".sparseimage" in Tiger). This is your proof positive that the account is using a FileVault–protected home directory.

    You might be a bit confused here. If the sparsebundle (or sparseimage) is stored inside /Users/username, how can it be made available at /Users/username when the user logs in?

    When the user is not logged in, the /Users directory looks something like this:

    [mbp:/Users] root# ls –al
    drwxr–xr–x    7 root    admin   238 May  2 16:01 .
    drwxrwxr–t   46 root    admin  1632 Apr 25 16:14 ..
    –rw–rr    1 root    wheel     0 Sep 23  2007 .localized
    drwxrwxrwt   24 root    wheel   816 Apr 30 14:46 Shared
    drwxrr  115 gneagle staff  3978 May  2 12:28 gneagle

    The gneagle.sparsebundle file is inside the gneagle directory. But once gneagle logs in, the /Users directory looks like this:

    [mbp:/Users] root# ls –al
    drwxr–xr–x    7 root    admin   238 May  2 16:01 .
    drwxrwxr–t   46 root    admin  1632 Apr 25 16:14 ..
    dr–x+   6 gneagle staff   204 Apr 30 12:06 .gneagle
    –rw–rr    1 root    wheel     0 Sep 23  2007 .localized
    drwxrwxrwt   24 root    wheel   816 Apr 30 14:46 Shared
    drwxrr  115 gneagle staff  3978 May  2 12:28 gneagle

    Note the new ".gneagle" directory. Further investigation will show the gneagle.sparsebundle file is now inside the .gneagle directory, and the disk image is mounted on /Users/gneagle:

    [mbp:/Users] root# mount
    /dev/disk0s3 on / (hfs, local, journaled)
    devfs on /dev (devfs, local)
    fdesc on /dev (fdesc, union)
    map –hosts on /net (autofs, automounted)
    map auto_home on /home (autofs, automounted)
    /dev/disk1s2 on /Users/gneagle (hfs, local, nodev, nosuid, journaled)

    So let's put this knowledge to use.

    On rare occasions on Tiger machines, you may encounter a situation where a FileVault–protected user cannot log in. You login to the machine with an admin account, and look in the /Users/username folder, and find the sparseimage file missing! Instead of panicking, you use your hard–earned systems administration knowledge, and you remember to look for a ".username" directory under /Users. You find it, and inside, the username.sparseimage file. You then move the sparseimage file back into the /Users/username directory, remove the /Users/.username directory, and tell the user to try to log in. They succeed, and you are a sysadmin hero.

    What has happened is that the machine crashed while the user was logged in, and the sparseimage file was not moved back into /Users/username, as it would be after a normal logout. When this happens, Tiger does not always fix things after the reboot, so you may need to help things along.

    Wrap–up

    Thus concludes our look at implementing FileVault in an enterprise environment. We've looked at preparation tasks and deployment options. We've identified some common issues and user experiences, and demonstrated some tools and strategies to deal with these. You now have the knowledge to confidently help protect your organization's private data and intellectual property with FileVault's home directory encryption.


    Greg Neagle is a member of the steering committee of the Mac OS X Enterprise Project (macenterprise.org) and is a senior systems engineer at a large animation studio. Greg has been working with the Mac since 1984, and with OS X since its release. He can be reached at gregneagle@mac.com.

  •  
    AAPL
    $98.15
    Apple Inc.
    -0.23
    MSFT
    $43.58
    Microsoft Corpora
    -0.31
    GOOG
    $587.42
    Google Inc.
    +1.81

    MacTech Search:
    Community Search:

    Software Updates via MacUpdate

    Knock 1.1.7 - Unlock your Mac by knockin...
    Knock is a faster, safer way to sign in. You keep your iPhone with you all the time. Now you can use it as a password. You never have to open the app -- just knock on your phone twice, even when it's... Read more
    Mellel 3.3.6 - Powerful word processor w...
    Mellel is the leading word processor for OS X and has been widely considered the industry standard since its inception. Mellel focuses on writers and scholars for technical writing and multilingual... Read more
    LibreOffice 4.3.0.4 - Free Open Source o...
    LibreOffice is an office suite (word processor, spreadsheet, presentations, drawing tool) compatible with other major office suites. The Document Foundation is coordinating development and... Read more
    Freeway Pro 7.0 - Drag-and-drop Web desi...
    Freeway Pro lets you build websites with speed and precision... without writing a line of code! With it's user-oriented drag-and-drop interface, Freeway Pro helps you piece together the website of... Read more
    Drive Genius 3.2.4 - Powerful system uti...
    Drive Genius is an OS X utility designed to provide unsurpassed storage management. Featuring an easy-to-use interface, Drive Genius is packed with powerful tools such as a drive optimizer, a... Read more
    Vitamin-R 2.15 - Personal productivity t...
    Vitamin-R creates the optimal conditions for your brain to work at its best by structuring your work into short bursts of distraction-free, highly focused activity alternating with opportunities for... Read more
    Toast Titanium 12.0 - The ultimate media...
    Toast Titanium goes way beyond the very basic burning in the Mac OS and iLife software, and sets the standard for burning CDs, DVDs, and now Blu-ray discs on the Mac. Create superior sounding audio... Read more
    OS X Yosemite Wallpaper 1.0 - Desktop im...
    OS X Yosemite Wallpaper is the gorgeous new background image for Apple's upcoming OS X 10.10 Yosemite. This wallpaper is available for all screen resolutions with a source file that measures 5,418... Read more
    Acorn 4.4 - Bitmap image editor. (Demo)
    Acorn is a new image editor built with one goal in mind - simplicity. Fast, easy, and fluid, Acorn provides the options you'll need without any overhead. Acorn feels right, and won't drain your bank... Read more
    Bartender 1.2.20 - Organize your menu ba...
    Bartender lets you organize your menu bar apps. Features: Lets you tidy your menu bar apps how you want. See your menu bar apps when you want. Hide the apps you need to run, but do not need to... Read more

    Latest Forum Discussions

    See All

    Ice Wings Plus (Games)
    Ice Wings Plus 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: THE GREAT ENDLESS RUNNER OF COMBAT JETS IS BACK !! With more than 680.000 downloads in the App Store, Ice Wings: Skies of Steel... | Read more »
    Murl the Squirrel (Games)
    Murl the Squirrel 1.0 Device: iOS Universal Category: Games Price: $.99, Version: 1.0 (iTunes) Description: Meet Murl. He is teased by a group of flying squirrels because he can't fly. Determined to show them he's can fly, he meets... | Read more »
    Celleste (Games)
    Celleste 0.1 Device: iOS Universal Category: Games Price: $2.99, Version: 0.1 (iTunes) Description: Lots of cute action with amazing 3D graphics and a new type of gameplay! Take control over the forces of the universe to help a group... | Read more »
    Super Heavy Sword (Games)
    Super Heavy Sword 0.0.1 Device: iOS Universal Category: Games Price: $.99, Version: 0.0.1 (iTunes) Description: Get Ready to Get HEAVY! Monster Robot Studios presents SUPER Heavy Sword! The sequel to the smash hit HEAVY sword which... | Read more »
    Angels In The Sky (Games)
    Angels In The Sky 1.00 Device: iOS Universal Category: Games Price: $6.99, Version: 1.00 (iTunes) Description: - A.I.S will only run smoothly on iPhone 5s. It's NOT compatible with iPad, iPhone 5 or earlier devices.- In order to... | Read more »
    80 Days (Games)
    80 Days 1.0.2 Device: iOS Universal Category: Games Price: $4.99, Version: 1.0.2 (iTunes) Description: 1872, with a steampunk twist. Phileas Fogg has wagered he can circumnavigate the world in just eighty days. Choose your own route... | Read more »
    Micromon (Games)
    Micromon 1.0 Device: iOS Universal Category: Games Price: $.99, Version: 1.0 (iTunes) Description: 130+ Animated Monsters to Catch & Battle! No waiting, play at your own pace! Embark on an epic monster capture RPG like none... | Read more »
    Empire Manager (Games)
    Empire Manager 1.0 Device: iOS iPhone Category: Games Price: $3.99, Version: 1.0 (iTunes) Description: Become ruler of an empire. Manage your economy, develop technology, hire an army and conquer the world in this addictive turn-... | Read more »
    Empire Manager HD (Games)
    Empire Manager HD 1.0 Device: iOS Universal Category: Games Price: $7.99, Version: 1.0 (iTunes) Description: Become ruler of an empire. Manage your economy, develop technology, hire an army and conquer the world in this addictive... | Read more »
    Star Admiral Review
    Star Admiral Review By Rob Thomas on July 30th, 2014 Our Rating: :: ADMIRABLE ADMIRALSUniversal App - Designed for iPhone and iPad While this new digital CCG may feel a bit familiar, Star Admiral offers a sci-fi twist and galaxy’s... | Read more »

    Price Scanner via MacPrices.net

    iPad Cannibalization Threat “Overblown”
    Seeking Alpha’s Kevin Greenhalgh observes that while many commentators think Apple’s forthcoming 5.5-inch panel iPhone 6 will cannibalize iPad sales, in his estimation, these concerns are being... Read more
    Primate Labs Releases July 2014 MacBook Pro P...
    Primate Labs’ John Poole has posted Geekbench 3 results for most of the new MacBook Pro models that Apple released on Tuesday. Poole observes that overall performance improvements for the new MacBook... Read more
    Apple Re-Releases Bugfixed MacBook Air EFI Fi...
    Apple has posted a bugfixed version EFI Firmware Update 2.9 a for MacBook Air (Mid 2011) models. The update addresses an issue where systems may take longer to wake from sleep than expected, and... Read more
    Save $50 on the 2.5GHz Mac mini, plus free sh...
    B&H Photo has the 2.5GHz Mac mini on sale for $549.99 including free shipping. That’s $50 off MSRP, and B&H will also include a free copy of Parallels Desktop software. NY sales tax only. Read more
    Save up to $140 on an iPad Air with Apple ref...
    Apple is offering Certified Refurbished iPad Airs for up to $140 off MSRP. Apple’s one-year warranty is included with each model, and shipping is free. Stock tends to come and go with some of these... Read more
    $250 price drop on leftover 15-inch Retina Ma...
    B&H Photo has dropped prices on 2013 15″ Retina MacBook Pros by $250 off original MSRP. Shipping is free, and B&H charges NY sales tax only: - 15″ 2.3GHz Retina MacBook Pro: $2249, $250 off... Read more
    More iPad Upgrade Musings – The ‘Book Mystiqu...
    Much discussed recently, what with Apple reporting iPad sales shrinkage over two consecutive quarters, is that it had apparently been widely assumed that tablet users would follow a two-year hardware... Read more
    13-inch 2.5GHz MacBook Pro on sale for $999,...
    Best Buy has the 13″ 2.5GHz MacBook Pro available for $999.99 on their online store. Choose free shipping or free instant local store pickup (if available). Their price is $100 off MSRP. Price is... Read more
    Save up to $300 on an iMac with Apple refurbi...
    The Apple Store has Apple Certified Refurbished iMacs available for up to $300 off the cost of new models. Apple’s one-year warranty is standard, and shipping is free. These are the best prices on... Read more
    WaterField Unveils 15″ Outback Solo & 13″...
    Hard on the heels of Apple’s refreshed MacBook Pro Retina laptops announcement, WaterField Designs has unveiled a 15-inch version of the waxed-canvas and leather Outback Solo and a 13-inch version of... Read more

    Jobs Board

    Sr. Product Leader, *Apple* Store Apps - Ap...
    **Job Summary** Imagine what you could do here. At Apple , great ideas have a way of becoming great products, services, and customer experiences very quickly. Bring Read more
    Sr Software Lead Engineer, *Apple* Online S...
    Sr Software Lead Engineer, Apple Online Store Publishing Systems Keywords: Company: Apple Job Code: E3PCAK8MgYYkw Location (City or ZIP): Santa Clara Status: Full Read more
    Sr Software Lead Engineer, *Apple* Online S...
    Sr Software Lead Engineer, Apple Online Store Publishing Systems Keywords: Company: Apple Job Code: E3PCAK8MgYYkw Location (City or ZIP): Santa Clara Status: Full Read more
    *Apple* Solutions Consultant (ASC) - Apple (...
    **Job Summary** The ASC is an Apple employee who serves as an Apple brand ambassador and influencer in a Reseller's store. The ASC's role is to grow Apple Read more
    Sr. Product Leader, *Apple* Store Apps - Ap...
    **Job Summary** Imagine what you could do here. At Apple , great ideas have a way of becoming great products, services, and customer experiences very quickly. Bring Read more
    All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.