Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Filevault master password question

Filevault master password question
Thread Tools
Dedicated MacNNer
Join Date: Aug 2003
Status: Offline
Reply With Quote
Jul 21, 2010, 07:59 PM
 
Is it possible to open up a filevault sparesebundle that is copied on a different mac with the master password from the machine it originated from?

I notice that if I have a FV master password set for a machine, even if I don't have a particular user's password, I can type in the incorrect password 3 times in a row, which will then prompt me for the master password. The master password then logs me into the user's account.

However, if I were to copy the sparse bundle onto a different mac, the sparsebundle will not open with the master password.

Is there a way around this?
     
Professional Poster
Join Date: Sep 2002
Location: New York, NY
Status: Offline
Reply With Quote
Jul 21, 2010, 08:36 PM
 
You can only open the image if you have the original password or the master password. There is no way around it. If there was, it wouldn't be that secure, would it?
Vandelay Industries
     
Dedicated MacNNer
Join Date: Aug 2003
Status: Offline
Reply With Quote
Jul 22, 2010, 10:50 AM
 
The master password will unlock the user's filevaulted account on the machine it originated from (i.e. when you attempt to login) , but it does not open the bundle for me when I copy the bundle over to a different machine (disk image/sparsebundle). How do you force the bundle to open with the master password? In my case it only accepts the user's password. thanks
     
Professional Poster
Join Date: Sep 2002
Location: New York, NY
Status: Offline
Reply With Quote
Jul 22, 2010, 11:19 AM
 
From my understanding, there is a master keychain that stores the individual filevault passwords. So, when you use the master password on the Mac that the filevault was created on, the master keychain is unlocked and it supplies the individual password to unlock the image. If you can figure out where that keychain is and transfer it to the other Mac, then you'd be able to open it on the other Mac with the master password.
Vandelay Industries
     
Professional Poster
Join Date: Sep 2002
Location: New York, NY
Status: Offline
Reply With Quote
Jul 22, 2010, 11:25 AM
 
The keychain and it's certificate are in /Library/Keychains. However, they are not accessible via KeyChain Access even if you add them manually. The master keychain will show up but you can't unlock it.
Vandelay Industries
     
Dedicated MacNNer
Join Date: Aug 2003
Status: Offline
Reply With Quote
Jul 24, 2010, 01:41 PM
 
I see. So I guess it's not possible then
     
Mac Enthusiast
Join Date: Feb 2005
Status: Offline
Reply With Quote
Jul 25, 2010, 03:32 AM
 
It may be possible to move the keychain containing the master password...

See http://images.apple.com/support/secu...nfig_v10.6.pdf
Chapter 7, page 154 onward.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 02:01 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2