Contrary to a conclusion I reached in my earlier blog post, Apple’s documentation does not reference keys stored in a Mac’s Secure Enclave. Instead a keychain may now reference what Apple is referring to as an entropy file. In this context, an entropy file is a file which contains randomized and unpredictable data, apparently used as part of the cryptographic key that unlocks the login keychain.
What this means is the following:
macOS 26.3 and earlier: The password for the login keychain was used to derive the cryptographic key used to unlock the login keychain.
macOS 26.4 and later: The information in the entropy file is now required, alongside the password, to derive the cryptographic key used to unlock the login keychain.
Per Apple’s documentation, this entropy file is stored in the following directory:
/var/db/SystemKeys
This directory is protected by System Integrity Protection (SIP) and not readable or writable unless SIP is disabled. This directory may also contain multiple entropy files, which are named using the salt value of the keychain. In the context of Apple’s keychains, the salt is a unique value associated with each keychain. This unique value is also fed into the process used to derive the cryptographic key used to unlock the keychain. For example, a login keychain may have the following salt:
D4E8A17F3C09B5D26A4E8F017C3B9D506AE4F18
The login keychain’s associated entropy file would be the following:
You can find the salt value for your login keychain by running the following command:
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
You should see output similar to what’s shown below:
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
The salt value is the alphanumeric string which appears after salt=.
Per Apple’s documentation, copying both the login keychain and the entropy file to a new Mac should allow the login keychain to be unlocked on the new Mac. The copied entropy file must be stored in the /var/db/SystemKeys directory on the destination Mac, which means that SIP will need to be turned off on the destination Mac in order to allow access to that protected directory. (SIP can be re-enabled once the entropy file has been successfully copied to the /var/db/SystemKeys directory.)
Harold Oakley covers this issue in more detail, including how the change affects Migration Assistant and Time Machine backups. His post is available via the link below:
Apprenez à installer et à utiliser Claude Code sur Windows ou Linux, en GUI ou CLI, pour commencer à lire, écrire et exécuter du code sur votre machine.
GLPI 11.0.11 et GLPI 10.0.28 corrigent 8 failles, dont une injection SQL. Teclib' annonce aussi que GLPI 10.0.28 sera la dernière version de la branche 10.
TeamViewer a corrigé cinq failles dans ses clients Windows, Linux et macOS, dont une exploitable à distance (CVSS 8,8 sur 10). Voici les versions à installer.
Leviia Storag3 propose un stockage S3 où les données sont stockées en France : découvrez comment l'utiliser pour stocker vos sauvegardes immuables Veeam Backup.
Les Pays-Bas développent DAWO, un poste de travail souverain sous NixOS déjà testé dans huit communes. De quoi pérenniser des PC incompatibles Windows 11.
Windows 11 26H2 est disponible. Microsoft recense déjà trois problèmes connus : et vous, avez-vous rencontré des bugs après l'installation de cette version ?
Bug du CPU à 100 %, e-mails absents du dossier Envoyés, 76 failles de sécurité : Thunderbird 157 corrige tout ça et ajoute deux stratégies pour les admins.