Site icon

Ownership of Apple silicon Macs matters: how it can stop external bootable disks

The three different types of Mac handle external bootable disks quite differently: Intel Macs without a T2 chip boot straight from a suitable disk with macOS installed on it; those with T2 chips have to be allowed to do so in Startup Security Utility; Apple silicon Macs rely on an elaborate system of ownership and security policies known as LocalPolicies. As a result, some find it difficult or impossible to get an M1 or M2 Mac to start up from what should be a bootable external disk. This article examines what could go wrong, and how you can investigate ownership.

Initial key and certificate creation

There are two situations in which an Apple silicon Mac needs to be set to its default state: when it’s brand new, and when it has been fully erased and restored in DFU mode using Apple Configurator 2. As Apple explains: “When macOS is first installed in the factory, or when a tethered erase-install is performed, the Mac runs code from temporary restore RAM disk to initialize the default state. During this process, the restore environment creates a new pair of public and private keys which are held in the Secure Enclave. The private key is referred to as the Owner Identity Key (OIK). If any OIK already exists, it’s destroyed as part of this process.”

Read more at eclecticlight.co

Exit mobile version