Je suis passé de Windows à macOS depuis 6 mois : voici mon retour d’expérience

Après 6 mois sur macOS, je fais le bilan de ma migration depuis Windows : adaptation, outils, compatibilité et limites rencontrées au quotidien.

Le post Je suis passé de Windows à macOS depuis 6 mois : voici mon retour d’expérience a été publié sur IT-Connect.

Copying macOS login keychains to different Macs on macOS Tahoe 26.4 and later

Earlier this year, I had written a post about a problem I observed with manually copied login keychains not working when moved to another Mac. To follow up on this topic, Apple has now provided information on how to back up keychain files as part of its developer tech note TN3137.

Contrary to a conclusion I reached in my earlier blog post, Apple’s documentation does not reference keys stored in a Mac’s Secure Enclave. Instead a keychain may now reference what Apple is referring to as an entropy file. In this context, an entropy file is a file which contains randomized and unpredictable data, apparently used as part of the cryptographic key that unlocks the login keychain.

What this means is the following:

  • macOS 26.3 and earlier: The password for the login keychain was used to derive the cryptographic key used to unlock the login keychain.
  • macOS 26.4 and later: The information in the entropy file is now required, alongside the password, to derive the cryptographic key used to unlock the login keychain.

Per Apple’s documentation, this entropy file is stored in the following directory:

/var/db/SystemKeys

This directory is protected by System Integrity Protection (SIP) and not readable or writable unless SIP is disabled. This directory may also contain multiple entropy files, which are named using the salt value of the keychain. In the context of Apple’s keychains, the salt is a unique value associated with each keychain. This unique value is also fed into the process used to derive the cryptographic key used to unlock the keychain. For example, a login keychain may have the following salt:

D4E8A17F3C09B5D26A4E8F017C3B9D506AE4F18

The login keychain’s associated entropy file would be the following:

/var/db/SystemKeys/D4E8A17F3C09B5D26A4E8F017C3B9D506AE4F18

You can find the salt value for your login keychain by running the following command:



This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters


security show-keychain-info -s $HOME/Library/Keychains/login.keychain-db
view raw

gistfile1.txt

hosted with ❤ by GitHub

You should see output similar to what’s shown below:



This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters


username@computername ~ % security show-keychain-info -s $HOME/Library/Keychains/login.keychain-db
Keychain "/Users/username/Library/Keychains/login.keychain-db" no-timeout salt=D4E8A17F3C09B5D26A4E8F017C3B9D506AE4F18
username@computername ~ %
view raw

gistfile1.txt

hosted with ❤ by GitHub

The salt value is the alphanumeric string which appears after salt=.

Per Apple’s documentation, copying both the login keychain and the entropy file to a new Mac should allow the login keychain to be unlocked on the new Mac. The copied entropy file must be stored in the /var/db/SystemKeys directory on the destination Mac, which means that SIP will need to be turned off on the destination Mac in order to allow access to that protected directory. (SIP can be re-enabled once the entropy file has been successfully copied to the /var/db/SystemKeys directory.)

Harold Oakley covers this issue in more detail, including how the change affects Migration Assistant and Time Machine backups. His post is available via the link below:

https://eclecticlight.co/2026/10/02/how-to-copy-login-keychains-that-can-be-unlocked/

Installation et utilisation de Claude Code : premiers pas

Apprenez à installer et à utiliser Claude Code sur Windows ou Linux, en GUI ou CLI, pour commencer à lire, écrire et exécuter du code sur votre machine.

Le post Installation et utilisation de Claude Code : premiers pas a été publié sur IT-Connect.

GLPI 11.0.11 et GLPI 10.0.28 : 8 failles patchées et la fin annoncée de GLPI 10

GLPI 11.0.11 et GLPI 10.0.28 corrigent 8 failles, dont une injection SQL. Teclib' annonce aussi que GLPI 10.0.28 sera la dernière version de la branche 10.

Le post GLPI 11.0.11 et GLPI 10.0.28 : 8 failles patchées et la fin annoncée de GLPI 10 a été publié sur IT-Connect.

TeamViewer a corrigé 5 failles de sécurité, dont une exploitable à distance

TeamViewer a corrigé cinq failles dans ses clients Windows, Linux et macOS, dont une exploitable à distance (CVSS 8,8 sur 10). Voici les versions à installer.

Le post TeamViewer a corrigé 5 failles de sécurité, dont une exploitable à distance a été publié sur IT-Connect.

Stockage S3 souverain en France : comment créer des sauvegardes Veeam immuables avec Leviia Storag3

Leviia Storag3 propose un stockage S3 où les données sont stockées en France : découvrez comment l'utiliser pour stocker vos sauvegardes immuables Veeam Backup.

Le post Stockage S3 souverain en France : comment créer des sauvegardes Veeam immuables avec Leviia Storag3 a été publié sur IT-Connect.

DAWO : les Pays-Bas misent sur NixOS pour remplacer Windows 11 et Microsoft

Les Pays-Bas développent DAWO, un poste de travail souverain sous NixOS déjà testé dans huit communes. De quoi pérenniser des PC incompatibles Windows 11.

Le post DAWO : les Pays-Bas misent sur NixOS pour remplacer Windows 11 et Microsoft a été publié sur IT-Connect.

Faille Metabase : l’ANSSI et la DINUM victimes d’une fuite de données

Une faille Metabase a permis de compromettre 118 comptes du laboratoire d'innovation de l'ANSSI et deux instances de la DINUM. Voici ce que l'on sait.

Le post Faille Metabase : l’ANSSI et la DINUM victimes d’une fuite de données a été publié sur IT-Connect.

Windows 11 26H2 à peine sorti, Microsoft liste déjà 3 bugs, et chez vous ?

Windows 11 26H2 est disponible. Microsoft recense déjà trois problèmes connus : et vous, avez-vous rencontré des bugs après l'installation de cette version ?

Le post Windows 11 26H2 à peine sorti, Microsoft liste déjà 3 bugs, et chez vous ? a été publié sur IT-Connect.

Thunderbird 157 corrige le bug du CPU à 100 % et 76 failles de sécurité

Bug du CPU à 100 %, e-mails absents du dossier Envoyés, 76 failles de sécurité : Thunderbird 157 corrige tout ça et ajoute deux stratégies pour les admins.

Le post Thunderbird 157 corrige le bug du CPU à 100 % et 76 failles de sécurité a été publié sur IT-Connect.