<!-- llms-explorer concept facts · https://llms-explorer.com/tree/fdesetup-authrestart-and-filevault-pre-boot-unlo/ · pack 2026-10-05 · ~1833 tokens -->

# fdesetup authrestart and FileVault pre-boot unlock for headless Macs

> authrestart was added in OS X 10.8.2 (2012). It asks for the password or recovery key of an account enabled for FileVault 2, puts an unlock key in system memory, and reboots; the reboot clears the key from memory, so the bypass is one use. The Mac then goes to the normal login window, not to the ...

Parent: [Mac local LLMs: Serving ops and multi-model](https://llms-explorer.com/tree/mac-local-llms-serving-ops-and-multi-model/) · 1 facets · 27 facts · page: https://llms-explorer.com/tree/fdesetup-authrestart-and-filevault-pre-boot-unlo/

## Facts

- authrestart was added in OS X 10.8.2 (2012). It asks for the password or recovery key of an account enabled for FileVault 2, puts an unlock key in system memory, and reboots; the reboot clears the key from memory, so the bypass is one use. The Mac then goes to the normal login window, not to the desktop. — [source](https://derflounder.wordpress.com/2012/09/22/fdesetup-authrestart-filevault-2s-one-time-encryption-bypass-feature/)
- Remote form: `sudo fdesetup authrestart -delayminutes -1` (a forum answer quotes -1, meaning restart is not scheduled by a timer but happens when the machine is next restarted by other means; this reading of the flag is the answerer's context, not verified against the man page). — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- Apple documents SSH unlock directly: on Apple silicon with macOS 26 or later, FileVault can be unlocked over SSH after a restart if Remote Login is on and a network connection is available. — [source](https://support.apple.com/guide/security/managing-filevault-sec8447f5049/web)
- Pre-boot SSH needs Remote Login (Sharing, "Remote Access") enabled in advance; the administrator logs in over SSH before user login and enters the account password to unlock, after which normal SSH and Screen Sharing work. — [source](https://www.jeffgeerling.com/blog/2025/you-can-finally-manage-macs-filevault-remotely-tahoe/)
- 2012 OS X 10.8.2: authrestart added. 2025 macOS Tahoe 26: pre-boot SSH unlock. Jeff Geerling's 2025 post first reported it only worked over Ethernet; his update says that as of macOS 26.5 unlock over Wi-Fi also worked. — [source](https://www.jeffgeerling.com/blog/2025/you-can-finally-manage-macs-filevault-remotely-tahoe/)
- authrestart cannot bypass OS updates; the Mac still stops at the FileVault screen after an update restart. — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- It is not a persistent setting. If a user, power loss or panic restarts the Mac instead of an issued authrestart, the Mac stops at the FileVault lock screen. — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- With FileVault on, Apple Remote Desktop and Screen Sharing cannot reach the Mac before unlock; the unlock screen has no network connectivity (the 2024 answers predate macOS 26 SSH unlock). — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- On Apple silicon at least one account must hold a Secure Token to enable FileVault, and only Secure Token holders can unlock at the FileVault screen. A service account created without a token cannot unlock. — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- Apple silicon institutional recovery keys do not give functional value (they cannot reach recoveryOS), so they are no substitute for authrestart or SSH unlock on a headless Mac. — [source](https://support.apple.com/guide/security/managing-filevault-sec8447f5049/web)
- For a local-LLM host: any LaunchDaemon (llama-server, Ollama, oMLX) stays down after an unplanned reboot until someone unlocks. Planned maintenance should be `fdesetup authrestart`; unplanned recovery needs SSH unlock with an administrator password, so that password must be reachable by whoever operates the box. — source: `asserted`
- Astropad (existing dossier) says run FileVault off for a home headless Mac. Apple's 26 documentation and Geerling treat FileVault plus remote SSH unlock as a workable headless setup. The trade is disk-at-rest encryption against hands-off recovery; neither source measures LLM workloads. — [source](https://support.apple.com/guide/security/managing-filevault-sec8447f5049/web)
- Whether authrestart's one-time key survives a kernel-panic reboot is still untested (the sources say it clears at reboot). — source: `asserted`
- Whether pre-boot SSH unlock works on a Mac whose only admin has no Secure Token, or with key-only SSH, is not stated. — source: `asserted`
- Whether Apple's 26 SSH unlock uses the same lightweight pre-boot SSH on every Apple silicon model, and its behaviour on Intel Macs, is not covered. — source: `asserted`
- fdesetup authrestart was introduced in OS X 10.8.2. — [source](https://derflounder.wordpress.com/2012/09/22/fdesetup-authrestart-filevault-2s-one-time-encryption-bypass-feature/)
- authrestart requires the password or recovery key of an account enabled for FileVault 2. — [source](https://derflounder.wordpress.com/2012/09/22/fdesetup-authrestart-filevault-2s-one-time-encryption-bypass-feature/)
- authrestart places an unlock key in memory and the reboot clears it, so the bypass is single use. — [source](https://derflounder.wordpress.com/2012/09/22/fdesetup-authrestart-filevault-2s-one-time-encryption-bypass-feature/)
- After authrestart the Mac boots to the standard login window, not directly into a session. — [source](https://derflounder.wordpress.com/2012/09/22/fdesetup-authrestart-filevault-2s-one-time-encryption-bypass-feature/)
- authrestart cannot bypass the FileVault screen after an OS update restart. — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- authrestart is not a persistent setting; a user-initiated restart still lands on the FileVault lock screen. — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- Apple silicon Macs require at least one Secure Token user, and only Secure Token users can log in at the FileVault screen. — [source](https://community.jamf.com/general-discussions-2/file-vault-mac-os-sonoma-33828)
- Apple states FileVault can be unlocked over SSH after restart on Apple silicon with macOS 26 or later when Remote Login is on and a network connection is available. — [source](https://support.apple.com/guide/security/managing-filevault-sec8447f5049/web)
- On Apple silicon institutional recovery keys have no functional value because they cannot access recoveryOS. — [source](https://support.apple.com/guide/security/managing-filevault-sec8447f5049/web)
- macOS 26 pre-boot SSH unlock requires Remote Login enabled and an administrator password entered over SSH. — [source](https://www.jeffgeerling.com/blog/2025/you-can-finally-manage-macs-filevault-remotely-tahoe/)
- Pre-boot SSH unlock initially worked only over Ethernet; as of macOS 26.5 it worked over Wi-Fi in the author's test. — [source](https://www.jeffgeerling.com/blog/2025/you-can-finally-manage-macs-filevault-remotely-tahoe/)
- A headless LLM host on FileVault needs planned reboots via authrestart and an SSH-unlock procedure for unplanned ones (inferred). — source: `asserted`
