← Shirt Pocket Watch

Controlled Craziness

Recently, Apple released an update to TN3137 that discusses backing up keychains.

Specifically, as of macOS 26.4, the login keychain, and perhaps others, cannot be decrypted on other Macs, or after a restore. The Tech Note indicates that backup programs should be sure to back up a folder that contains special system keys…but also says that the folder is not accessible when System Integrity Protection (SIP)1 is on.

This is obviously not a good user solution, because no one is going to boot to Recovery, turn off SIP, back up, boot back to Recovery, and turn SIP back on. Thinking they would do so is kind of crazy.2

Breathe: it’s OK

Fortunately, SuperDuper handles this situation. When you make a bootable copy, the required keys are copied without requiring any special steps. Even though Smart Update cannot access those files, it preserves them on the backup so they’re available if needed.

What that means for you

It’s always a good idea to make a bootable backup, even if you have no plan to boot from it. Update it with Smart Update, update the OS when SuperDuper indicates you should, and you’ll be in good shape should you need to restore…even if you need to restore your keychains on a different Mac.


  1. System Integrity Protection—basically, a process that prevents any programs, other than Apple-authorized ones, from performing certain activities. You can read more about it here. ↩︎

  2. This all may change in the future. The Tech Note hedges a lot in the Warning and Important sections, which suggests to me that they realize this isn’t a great situation. ↩︎