FileVault Drive Encryption

Overview
Drive Preparation
FileVault Step-by-Step
Best Practices
Additional Resources

FileVault Overview

FileVault an encryption system built--in with OS 10.3 and later. It uses the Advanced Encryption Standard (AES) with 128-bit keys and encrypts the data in your Home directory in real time. Your username and password is what unlocks the encryption on your home directory, but if you forget your password the master password can also be used to access the encrypted data on your computer. And, while you can create encrypted virtual disk images using the Apple Disk Utility only the home directory on your computer will be encrypted.

Back to Top

 

Drive Preparation

Back to Top

 

FileVault Step-by-Step

  1. Click on the Apple menu, on the top left hand corner of the screen and go to the System Preferences menu.
    apple menu

  2. From the System Preferences menu, click on the Security icon under the Personal section
    System Prefences

  3. In the Security section you will be presented with FileVault options.   The first thing to do is set your options to look like the image below.  We recommend requiring a password to wake up the computer from sleep or screen saver, disable automatic login, logout after 15 minutes, and to use secure virtual memory.  Once those are set click on Set Master Password…


  4. This will take you to the screen to set a Master Password.  Here you will want to choose a secure password that will unlock your data in the event that you forget your password or for some reason you’re unable to get into your account.   Make sure you keep a record of this password in a secure place and with your departmental IT person. Using an easily memorable phrase with a few misspellings or other unique modifications is a good way to select a strong master password.  


  5. Once you set the Master Password click on the button to Turn on FileVault…  Make sure you click the option to Use Secure Erase. All that’s left to do is confirm your decision by clicking the button that says Turn On FileVault.


  6. Once you’ve gone through these steps your machine will want to log out.  While you are logging out your computer will be encrypting your home directory.  Because it is encrypting your home directory it will take longer to log out this time than you may be used to.  After this is done make sure that you restart your computer so that the option for using Secure Virtual Memory can take effect.

  7. You will be able to tell that the encryption went through by seeing a padlock over your home directory in the finder:


    And the Security section of System Preferences will now show that FileVault is turned on:

Back to Top

 

Best Practices

Back to Top

Back to Help Desk Encryption Support Center

Last Updated: 04/24/2008

Copyright © 2008, The University of Iowa, all rights reserved.