Post

Replies

Boosts

Views

Activity

Reply to macOS 26.3.1: creating and verifying a disabled local service account without a password credential
Thank you for pointing me to sysadminctl -roleAccount. No account has been created. For macOS 26.3.1, could you clarify its supported guarantees for these requirements? Can it create the account directly disabled, without an externally available enabled password-authenticating intermediate state? Does it establish DisabledUser, or a different mechanism? Can creation avoid ever assigning or storing a usable account password or equivalent authentication secret? Please distinguish absent, empty, generated/unknown and disabled credentials. Which authentication paths are excluded—GUI/console, SSH password and other Open Directory-backed authentication—and can launchd still execute a controlled daemon under that UID? What supported read-only attributes or APIs verify both the disabled state and credential absence without authentication attempts or exposing secrets? If these guarantees are outside the tool’s supported contract, could you identify the relevant documentation or support route? The related questions about pwpolicy disableuser and DisabledTags;SecureToken also remain open.
10h
Reply to macOS 26.3.1: creating and verifying a disabled local service account without a password credential
Thank you for pointing me to sysadminctl -roleAccount. No account has been created. For macOS 26.3.1, could you clarify its supported guarantees for these requirements? Can it create the account directly disabled, without an externally available enabled password-authenticating intermediate state? Does it establish DisabledUser, or a different mechanism? Can creation avoid ever assigning or storing a usable account password or equivalent authentication secret? Please distinguish absent, empty, generated/unknown and disabled credentials. Which authentication paths are excluded—GUI/console, SSH password and other Open Directory-backed authentication—and can launchd still execute a controlled daemon under that UID? What supported read-only attributes or APIs verify both the disabled state and credential absence without authentication attempts or exposing secrets? If these guarantees are outside the tool’s supported contract, could you identify the relevant documentation or support route? The related questions about pwpolicy disableuser and DisabledTags;SecureToken also remain open.
Replies
Boosts
Views
Activity
10h