Access Keys:
Skip to content (Access Key - 0)

Switch from FileVault (home folder encryption) to FileVault (whole disk encryption) after upgrading to OS X 10.7 (Lion) or 10.8 (Mountain Lion)

Primer

  • Affected population: FileVault users upgrading from Mac OS X 10.6 (Snow Leopard) to OS X 10.7 (Lion) or 10.8 (Mountain Lion).
  • This tutorial will show users how to migrate from the old iteration of FileVault to the newer, more secure iteration.
  • FileVault 2 in Lion and Mountain Lion is based on a whole disk encryption (WDE) schema.
  • This feature provides added security for data stored on a computer's disk.

Please consult with your System Administrator before enabling FileVault on your machine

Instructions

Before enabling FileVault 2, it is important to make sure that PGP (if used before) is completely uninstalled. If you are not sure if PGP was used on your machine before, please consult your system administrator. Instructions on how to manually remove PGP from OS X.
  1. Navigate to the System Preferences menu.
    Apple > System preferences

  2. Choose the Security & Privacy preference pane.
    System preferences screen

  3. You should be prompted with a message that reads "You're using an old version of FileVault". Click the button labeled Turn Off Legacy FileVault.
    Note: if you are not automatically prompted with this message you may not be utilizing "Legacy FileVault". If you would like to turn FileVault on in OS X Lion or Mountain Lion please see [this tutorial].

    Legacy FileVault message

  4. Enter the password for your user account when prompted.
    System preferences login screen

  5. Enter the password for your user account again when prompted.
    Security and privacy password screen

  6. When prompted by the message "You are ready to turn off Legacy FileVault protection", click the button labeled Turn Off Legacy FileVault.
    Turn off Legacy FileVault screen

  7. Your home folder will now begin to decrypt. You cannot use your machine during this time (~40 minutues).
    Decryption progress bar

  8. When the home folder finishes decrypting you will be at the OS X login screen. Please login with your username and password.
  9. The "Security & Privacy" preference pane should automatically open again. Click on the lock icon in the lower left-hand corner to unlock the preference pane.
    Lock icon

  10. When prompted, authenticate with your user account username and password.
    Login screen

  11. You will again find yourself at the Security & Privacy window. Click the button labeled Turn on FileVault...
    Security & Privacy screen

  12. If there are multiple users accounts on this machine you will be prompted to give additional users access. All users that need the ability to use this machine should be given disk access-rights by clicking the button labeled Enable user..., entering that user's password, and clicking the button labeled Continue.
    User access screen

  13. The following screen will display the disk's recovery key. If a disk password is lost or forgotten this is the ONLY way to recover the data on the encrypted disk. Please write this 24 character string down and store it in a secure place. Click the button labeled Continue.
    Recovery key screen

  14. OS X Lion or Mountain Lion will display a prompt asking if you wish to store your recovery key with Apple. Select the radio button labeled Do not store the recovery key with Apple and click the button labeled Continue.
    Store recovery key with Apple screen

  15. OS X will now prompt you to restart to enable FileVault and begin the whole disk encryption process. Click Restart.
    Restart computer message

  16. The login process now takes place when OS X reboots. This authentication serves two purposes: it unlocks the disk and logs the selected user in.
  17. Upon reboot, the Security & Privacy window will open and display the amount of time remaining until the disk is fully encrypted. The machine can be used during this time period.
    Encryption progress bar

IS&T Contributions

Documentation and information provided by IS&T staff members


Last Modified:

October 05, 2017

Get Help

Request help
from the Help Desk
Report a security incident
to the Security Team
Labels:
c-macos-lion c-macos-lion Delete
filevault filevault Delete
encryption encryption Delete
switch switch Delete
migrate migrate Delete
change change Delete
old old Delete
snow snow Delete
leopard leopard Delete
home home Delete
folder folder Delete
file file Delete
vault vault Delete
lion lion Delete
mountain mountain Delete
2 2 Delete
Enter labels to add to this page:
Please wait 
Looking for a label? Just start typing.
Feedback
This product/service is:
Easy to use
Average
Difficult to use

This article is:
Helpful
Inaccurate
Obsolete
Adaptavist Theme Builder (4.2.3) Powered by Atlassian Confluence 3.5.13, the Enterprise Wiki