stephen.willis.smith

Q: profiles and file vault

Ok so this is strange and I am not sure if the two are related or not.

We have a mac os x server mainly used for profile management.  We have complex password requirements for our mac because we are in the health care field. So the profiles have a password requirement:

 

1.  10 Characters long

2.  1 upper case letter

3.  1 number

4   1 Special Character

5.  Password must be changed every 60 days

6.  Password can not be the same for the next 10 password changes.

 

We had been using profiles for years but we didn't start using the password profile but for the last couple months.  During this time we also turned on FileVault on all the macs.  One by one the macs are having the same issues.

The users password stops working, the admin password on the mac will still work so I can reset the users password but as soon as they log off or the computer is reset the password no longer works.  Eventually the admin password stops working until I enter in the file vault key and then shut off file vault.  Once I turn off file vault the passwords no longer need to be reset.  I am not sure if it is a combination of the profiles and file vault so I tried to remove the complex password profile and even when I delete the profile (tried deleting all in terminal too) the complex password requirements are still on the computer and I cannot figure out how to stop that.  So at this point the only thing I can do is shut off file vault but our HIPAA audit said we are required to have out computers encrypted......

 

Anyways any one have this problem ever?  I have a call into apple and they are trying to figure out the issue but no luck yet.

 

 

Update:

So another crazy thing that is happening on two of the macs (Mac mini and Macbook air) is that there are two log in screens so the first log in the original password works but once that screen clears (same as the regular log in) a second log in screen pops up and the original or new password won't work.  This will happen and then soon after this happens the admin account password stops working.  This is when I'll put in the file vault key.

 

The other thing to note is we are on the latest version of OS X and it is happening on all types of macs 1 mac mini, 1 iMac, 2 macbook airs and 1 macbook pro.  So far only two computers are not effected one macbook air and one mac book pro.

Mac mini, OS X Mavericks (10.9.2), Running Server.app

Posted on Aug 18, 2016 10:31 AM