Is it possible to enable Legacy FileVault for a network user

filevaultnetwork-useropen-directoryosx-server

I am running Mac OS X 10.8 Server with File Sharing and Open Directory providing home directories to network users, so when users log in their home directory is automatically mounted over AFP.

Is it possible to enable "Legacy" FileVault (FileVault 1) where the user's home directory resides inside an encrypted DMG sparsebundle when the user is an Open Directory user whose home directory resides on a network share?

I know this could be done in 10.6 server for mobile clients but I do not know if it can be done in 10.8 server.

Best Answer

I haven't seen anyone hack together a script to re-implement the FileVault encrypted disk image settings, but I have heard of people using a pre-Mountain Lion machine to make more local users and then migrate them to OS X 10.8.

It requires a second machine (or VM if that is up your alley) but I haven't seen any downsides to moving more FileVault 1 type accounts to new systems other than the obvious downsides associated with those accounts:

  • backups to Time Machine only run when unlocked
  • compacting of free space can be problematic
  • slight slow down and chance of breaking some software that assumes hard coded file paths