14F27: Changing AD password doesn't update FileVault 2 pre-boot login screen

Originator:fti
Number:rdar://22452336 Date Originated:27-Aug-2015 09:34 AM
Status:Open Resolved:
Product:OS X Product Version:10.10-10.11
Classification:UI/Usability Reproducible:Always
 
Summary:
14F27: Changing AD password doesn't update FileVault 2 pre-boot login screen 
Same issue on 10.11 (15A263e)

Steps to Reproduce:
1. Use an AD account. 
2. setup FV2 using Airwatch (it asks for the current user password). 
3. After a few days, I get a prompt at loginwindow telling me the password will soon expire. 
4. change the password. Upon rebooting, FV2 need old password. loginwindow works with new password, but doesn't update FV2 pre-login screen




Expected Results:
FV2 password should be synced to login password

Actual Results:
FV2 password is not synced. 

Version:
10.10.5 14F27
Same issue on 10.11 (15A263e)

Notes:

mini-de-admin:~ levaufr1$ pmset -g
System-wide power settings:
 DestroyFVKeyOnStandby		1

mini-de-admin:~ levaufr1$ sudo fdesetup list -extended -verbose
ESCROW  UUID                                                                     TYPE USER
Yes     9A2B875D-3B24-4855-835C-5E05EADE88DE                   Personal Recovery User
        A1CF47FC-C5C7-4B38-8721-0AB85AFA8A2B                                  OS User levaufr1

See https://forums.developer.apple.com/message/8028


Configuration:


Attachments:
successfully uploaded.

See also: rdar://16410396

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!