Skip to content

The Eclectic Light Company

Macs & painting – 🦉 No AI content
Main navigation
  • Downloads
  • Freeware
  • All Macs
  • M1-M5 Macs
  • Troubleshooting
  • Painting
  • Mac Front Page
hoakley October 2, 2026 Macs, Technology

How to copy login keychains that can be unlocked

Over the last few weeks, it has become clear that macOS Tahoe 26.4 changed access to login keychains, blocking their unlocking in many circumstances that have been important and well-used in the past. This was first reported by Rich Trouton, further investigated by Jeff Johnson and explored here. On 24 September, Apple at last added a brief section to its developer tech note TN3137 outlining what has changed. This article explains.

Before 26.4

Since Mac OS X 10.6 Snow Leopard in 2009, macOS has supported two different types of keychain.

Login and other file-based keychains are SecKeychains derived from older types, stored as encrypted databases in single files, such as those in ~/Library/Keychains. Although file-based SecKeychains were deprecated in El Capitan, they continue to be used in all Macs, and include the essential login keychain, unlocked automatically when you enter your login password, and still used by apps.

When iPhones were introduced, iOS introduced the more secure Data Protection keychain, supported by Snow Leopard and now used for the iCloud Keychain; when that’s not shared in iCloud it’s shown as Local Items.

Although the login keychain can be copied across from a suitable backup by Migration Assistant, as a single file it has been common practice to copy or restore it, and to unlock it using its password, the same as the login password for the Mac that created and used it.

One major disadvantage of file-based keychains has become clear with stealer malware: exfiltrate the login keychain and it’s quick and cheap to crack its password, and access all the secrets within it. That’s likely to have been the main reason for Apple changing them earlier this year.

Tahoe’s extra secret

macOS Tahoe 26.4 broke the copying of login keychains in almost all circumstances. Although Rich Trouton suggested this resulted from encryption using an additional secret held in the Secure Enclave, Jeff Johnson came closest with the observation that the additional secret is volume-specific. It turns out that secret is stored in a locked directory in Data volumes, in /var/db/SystemKeys.

File-based keychains, specifically but not necessarily exclusively the login keychain, might now require both their password and a protected entropy file, stored in /var/db/SystemKeys. Without the latter, login keychains, and possibly some other file-based keychains, can’t be unlocked and used. Thus, if you copy one of these protected keychains and its entropy file becomes inaccessible, that copy can’t be unlocked.

Copy login keychains

If you want to copy a file-based keychain between Macs or boot volumes you must therefore copy across its protected entropy file, to be located in /var/db/SystemKeys on the destination Data volume. To enable that, System Integrity Protection (SIP) must be disabled, and the entropy file identified by dumping the keychain’s salt, using the command
security show-keychain-info -s path
where path is the full path to the keychain, typically ~/Library/Keychains/login.keychain-db for a login keychain. When you run that command, you will be prompted to enter that keychain’s password, and without that the command will fail.

This will return something like
Keychain "/Users/hoakley/Documents/zKeychains/login.keychain-db" no-timeout salt=30993ABCECBE29D91ED95C2A3827326DB5C39B2F
indicating that keychain’s entropy file is
/var/db/SystemKeys/30993ABCECBE29D91ED95C2A3827326DB5C39B2F

All file-based keychains return values for salt, but only those requiring entropy will have an entropy file of that name.

Backups

This procedure also applies to backups, presenting backup software with the challenge of backing up the entropy files in their locked directory, and restoring them should the user need to copy or restore that keychain. This explains how Migration Assistant can still copy fully functional login keychains between Macs, and should be able to do so when migrating from a backup, provided that contains the /var/db/SystemKeys directory with its entropy files.

For some time now, each Time Machine backup has consisted of two phases, one for protected files. Since macOS 26.4, its backups of Data volumes have also included the protected directory /var/db/SystemKeys, also protected in those backups. This has presumably ensured that performing a one-Mac migration using a Time Machine backup can copy both the login keychain and its entropy file.

Although I have checked the documentation for some third-party backup products, I can see no explicit details of whether they back up the protected directory, or how they can restore entropy files for login keychains.

Key points

  • Login keychains from macOS Tahoe 26.4 onwards require an additional secret to unlock them.
  • That additional secret is an entropy file stored in a protected directory /var/db/SystemKeys.
  • Copying a login keychain successfully now requires copying its entropy file as well.
  • Backup software must back up that protected directory, and restore its entropy file(s) with any keychains that require them.
  • Time Machine has backed up entropy files since macOS 26.4, and Migration Assistant will copy them when necessary during migration.
  • If you use third-party backup software, check it supports entropy files correctly.
  • If you have old login keychains from 26.4 onwards that aren’t stored with their entropy files, you may as well delete them now, as you will never be able to unlock them.
  • macOS Tahoe 26.4 was released on 24 March 2026. Apple documented this for developers only on 24 September 2026, exactly six months later.

References

Apple’s TN3137, see the section at the end on backing up a file-based keychain.
Apple’s user documentation, which has been incorrect for over six months.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on Reddit (Opens in new window) Reddit
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Threads (Opens in new window) Threads
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Email a link to a friend (Opens in new window) Email
  • Print (Opens in new window) Print
Like Loading...

Related

Posted in Macs, Technology and tagged backup, encryption, keychain, Keychain Access, login, migration, security, Time Machine. Bookmark the permalink.

2Comments

Add yours
  1. 1
    Alan B's avatar
    Alan B on October 2, 2026 at 7:02 am
    Reply

    Thankfully I use TM as my primary backup tool. I also use CCC and I’ve asked Bombich Inc. if their product can copy and restore /var/db/SystemKeys and its contents. A very useful article – thanks.

    LikeLiked by 1 person

    • 2
      hoakley's avatar
      hoakley on October 2, 2026 at 8:11 am
      Reply

      Thank you, Alan. I only came across the updated TN3137 yesterday, so haven’t had a chance to invite comments from Mike Bombich or anyone else. Hopefully Apple made them aware before the TN was released, maybe even back in March? It would be nice to think so.
      Howard.

      LikeLiked by 1 person

Leave a comment Cancel reply

Quick Links

  • Free Software Menu
  • System Updates
  • Mac Troubleshooting Summary
  • M-series Macs
  • Painting

Search

Monthly archives

  • October 2026 (3)
  • September 2026 (78)
  • August 2026 (80)
  • July 2026 (75)
  • June 2026 (73)
  • May 2026 (78)
  • April 2026 (73)
  • March 2026 (82)
  • February 2026 (71)
  • January 2026 (72)
  • December 2025 (75)
  • November 2025 (74)
  • October 2025 (75)
  • September 2025 (78)
  • August 2025 (76)
  • July 2025 (77)
  • June 2025 (74)
  • May 2025 (76)
  • April 2025 (73)
  • March 2025 (78)
  • February 2025 (67)
  • January 2025 (75)
  • December 2024 (74)
  • November 2024 (73)
  • October 2024 (78)
  • September 2024 (77)
  • August 2024 (75)
  • July 2024 (77)
  • June 2024 (71)
  • May 2024 (79)
  • April 2024 (75)
  • March 2024 (81)
  • February 2024 (72)
  • January 2024 (78)
  • December 2023 (79)
  • November 2023 (74)
  • October 2023 (77)
  • September 2023 (77)
  • August 2023 (72)
  • July 2023 (79)
  • June 2023 (73)
  • May 2023 (79)
  • April 2023 (73)
  • March 2023 (76)
  • February 2023 (68)
  • January 2023 (74)
  • December 2022 (74)
  • November 2022 (72)
  • October 2022 (76)
  • September 2022 (72)
  • August 2022 (75)
  • July 2022 (76)
  • June 2022 (73)
  • May 2022 (76)
  • April 2022 (71)
  • March 2022 (77)
  • February 2022 (68)
  • January 2022 (77)
  • December 2021 (75)
  • November 2021 (72)
  • October 2021 (75)
  • September 2021 (76)
  • August 2021 (75)
  • July 2021 (75)
  • June 2021 (71)
  • May 2021 (80)
  • April 2021 (79)
  • March 2021 (77)
  • February 2021 (75)
  • January 2021 (75)
  • December 2020 (77)
  • November 2020 (84)
  • October 2020 (81)
  • September 2020 (79)
  • August 2020 (103)
  • July 2020 (81)
  • June 2020 (78)
  • May 2020 (78)
  • April 2020 (81)
  • March 2020 (86)
  • February 2020 (77)
  • January 2020 (86)
  • December 2019 (82)
  • November 2019 (74)
  • October 2019 (89)
  • September 2019 (80)
  • August 2019 (91)
  • July 2019 (95)
  • June 2019 (88)
  • May 2019 (91)
  • April 2019 (79)
  • March 2019 (78)
  • February 2019 (71)
  • January 2019 (69)
  • December 2018 (79)
  • November 2018 (71)
  • October 2018 (78)
  • September 2018 (76)
  • August 2018 (78)
  • July 2018 (76)
  • June 2018 (77)
  • May 2018 (71)
  • April 2018 (67)
  • March 2018 (73)
  • February 2018 (67)
  • January 2018 (83)
  • December 2017 (94)
  • November 2017 (73)
  • October 2017 (86)
  • September 2017 (92)
  • August 2017 (69)
  • July 2017 (81)
  • June 2017 (76)
  • May 2017 (90)
  • April 2017 (76)
  • March 2017 (79)
  • February 2017 (65)
  • January 2017 (76)
  • December 2016 (75)
  • November 2016 (68)
  • October 2016 (76)
  • September 2016 (78)
  • August 2016 (70)
  • July 2016 (74)
  • June 2016 (66)
  • May 2016 (71)
  • April 2016 (67)
  • March 2016 (71)
  • February 2016 (68)
  • January 2016 (90)
  • December 2015 (96)
  • November 2015 (103)
  • October 2015 (119)
  • September 2015 (115)
  • August 2015 (117)
  • July 2015 (117)
  • June 2015 (105)
  • May 2015 (111)
  • April 2015 (119)
  • March 2015 (69)
  • February 2015 (54)
  • January 2015 (39)

Tags

APFS Apple Apple silicon backup Big Sur Blake Bonnard bug Catalina Consolation Console Corinth Delacroix Disk Utility El Capitan extended attributes Finder firmware Gatekeeper Gérôme High Sierra history history of painting iCloud Impressionism landscape LockRattler log M1 Mac Mac history macOS macOS 10.12 macOS 10.13 macOS 10.14 macOS 10.15 macOS 11 macOS 12 macOS 13 macOS 14 macOS 15 malware Metamorphoses Mojave Monet Monterey Moreau myth narrative OS X Ovid painting performance Pissarro Poussin privacy Renoir riddle Rubens Sargent security Sequoia Sierra SilentKnight Sonoma Swift Time Machine Tintoretto Turner update upgrade Ventura xattr Xcode XProtect

Statistics

  • 23,098,208 hits
Blog at WordPress.com.
Footer navigation
  • About & Contact
  • Free Software Menu
  • Macs
  • Painting
  • Downloads
  • SilentKnight, Skint, SystHist, silnite, LockRattler & Scrub
  • XProCheck, T2M2, LogUI, Ulbow, blowhole and log utilities
  • Mints: a multifunction utility
  • xattred, SpotTest, Providable, Spotcord, Metamer & xattr tools
  • Versatility & Revisionist
  • DelightEd & Podofyllin
  • Precize, Alifix, UTIutility, Sparsity, alisma, Taccy, Signet
  • System Updates
  • Spundle, Cormorant, Stibium, DropSum, Dintch, Fintch and cintch
  • Virtualisation on Apple silicon
  • Cirrus & Bailiff
  • Text Utilities: Textovert, Disclipper, Nalaprop, Dystextia and others
  • sysctl information
  • Extended attributes (xattrs)
  • 32-bitCheck & ArchiChect
  • Keychains & Permissions
  • PDF
  • VisualLookUpTest
  • Updates
  • Long Reads
  • Mac Troubleshooting Summary
  • Saturday Mac Riddles
  • Last Week on My Mac
  • Painting topics
  • Mac problem-solving
  • M-series Macs
Secondary navigation
  • Search

Post navigation

Painting a good story: Multiplex returns

Begin typing your search above and press return to search. Press Esc to cancel.

  • Comment
  • Reblog
  • Subscribe Subscribed
    The Eclectic Light Company
    Join 9,379 other subscribers

    Have a WordPress.com account? Log in now.

  • The Eclectic Light Company
    Copy shortlinkView post in Reader
    Manage subscriptionsSign upLog in
    Report this content
    Collapse this bar
%d