Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-2983: Smart Card support for FileVault 2 on Mac OS X.

Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:18 AM

Applies to: All versions of Centrify DirectControl on Mac OS X

Question:

Can smart cards be used to unlock Mac systems encrypted with FileVault 2?


Answer:

FileVault 2 is not compatible with smart card authentication. 

The only types of accounts that can unlock FileVault 2 are:
  1. Local user accounts
  2. Network accounts that are converted into Mobile Accounts. 

This is a restriction in the EFI, which only Apple has control of. Please see the following Apple white paper for more information: 

Notes: 
  • This restriction only affects the unlocking portion of FileVault at boot-time - Smart card authentication can still be used after the Mac has been unlocked - this means that a restricted local account could be created solely for unlocking the FileVault login screen, after which the smart card user can login as normal at the standard login screen.
     
  • On OS X 10.8 and below, FileVault 2 is designed to automatically log the user straight into their Desktop session after unlocking FileVault. This means the "unlocking account" will need to logout to get to the login screen after unlocking the disk:
  • On OS X 10.9, Apple introduced the ability to disable this behaviour and let the authorised user to only unlock the FileVault and then go straight to the login screen:
  • For steps on setting up FileVault with Centrify group policies, see:


(All external links provided as a courtesy)

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.