
Enter the master password to unlock the startup disk.Security unlock-keychain /Volumes/ThumbDrive/FileVaultMaster.keychain Security unlock-keychain /path Example for a volume named ThumbDrive: In this step and all remaining steps, if the keychain is stored in an encrypted disk image, remember to include the name of that image in the path. Replace /path with the path to FileVaultMaster.keychain on the external drive. Use the following command to unlock the FileVault master keychain.Hdiutil attach /Volumes/ThumbDrive/PrivateKey.dmg Hdiutil attach /path Example for a disk image named PrivateKey.dmg on a volume named ThumbDrive: Replace /path with the path to the disk image, including the. If you stored the private recovery key in an encrypted disk image, use the following command in Terminal to mount that image.From the menu bar in macOS Recovery, choose Utilities > Terminal.Connect the external drive that contains the private recovery key.You will need this information in a later step. If you see ”CoreStorage Logical Volume Group” instead of ”APFS Volume” or ”Mac OS Extended,” the format is Mac OS Extended. If you don't know the name (such as Macintosh HD) and format of the startup disk, open Disk Utility from the macOS Utilities window, then check the information Disk Utility shows for that volume on the right.On the client Mac, start up from macOS Recovery by holding Command-R during startup.Next make a copy of your FileVaultMaster.keychain file.Two "File Vault Recovery Key" items should appear, one that is a private key and another that is a certificate. Once a keychain is created, drag and drop the FileVaultMaster.p12 file into the keychain.

Create a new Keychain named FileVaultMaster (Keychain Access > File > New Keychain).Open up Keychain Access on an OS X machine (Applications > Utilities > Keychain Access).This file will be called FileVaultMaster.p12. Find the IRK that was originally downloaded or download it from Dashboard.Again this key is used to unlock a device encrypted by Meraki via FileVault. Using Dashboard to Unlock a User's Startup DiskĪside from downloading the recovery certificate, Meraki also stores the Institutional Recovery Key on the Organization > MDM page of Dashboard.
