fdesetup authrestart and FileVault pre-boot unlock for headless Macs
Parent: Mac local LLMs: Serving ops and multi-model · Published reference · snapshot 2026-10-05
↓ Facts as markdownall context files
authrestart was added in OS X 10.8.2 (2012). It asks for the password or recovery key of an account enabled for FileVault 2, puts an unlock key in system memory, and reboots; the reboot clears the key from memory, so the bypass is one use. The Mac then goes to the normal login window, not to the ...
These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.
Facts
- authrestart was added in OS X 10.8.2 (2012). It asks for the password or recovery key of an account enabled for FileVault 2, puts an unlock key in system memory, and reboots; the reboot clears the key from memory, so the bypass is one use. The Mac then goes to the normal login window, not to the desktop. [source]
- Remote form: `sudo fdesetup authrestart -delayminutes -1` (a forum answer quotes -1, meaning restart is not scheduled by a timer but happens when the machine is next restarted by other means; this reading of the flag is the answerer's context, not verified against the man page). [source]
- Apple documents SSH unlock directly: on Apple silicon with macOS 26 or later, FileVault can be unlocked over SSH after a restart if Remote Login is on and a network connection is available. [source]
- Pre-boot SSH needs Remote Login (Sharing, "Remote Access") enabled in advance; the administrator logs in over SSH before user login and enters the account password to unlock, after which normal SSH and Screen Sharing work. [source]
- 2012 OS X 10.8.2: authrestart added. 2025 macOS Tahoe 26: pre-boot SSH unlock. Jeff Geerling's 2025 post first reported it only worked over Ethernet; his update says that as of macOS 26.5 unlock over Wi-Fi also worked. [source]
- authrestart cannot bypass OS updates; the Mac still stops at the FileVault screen after an update restart. [source]
- It is not a persistent setting. If a user, power loss or panic restarts the Mac instead of an issued authrestart, the Mac stops at the FileVault lock screen. [source]
- With FileVault on, Apple Remote Desktop and Screen Sharing cannot reach the Mac before unlock; the unlock screen has no network connectivity (the 2024 answers predate macOS 26 SSH unlock). [source]
- On Apple silicon at least one account must hold a Secure Token to enable FileVault, and only Secure Token holders can unlock at the FileVault screen. A service account created without a token cannot unlock. [source]
- Apple silicon institutional recovery keys do not give functional value (they cannot reach recoveryOS), so they are no substitute for authrestart or SSH unlock on a headless Mac. [source]
- For a local-LLM host: any LaunchDaemon (llama-server, Ollama, oMLX) stays down after an unplanned reboot until someone unlocks. Planned maintenance should be `fdesetup authrestart`; unplanned recovery needs SSH unlock with an administrator password, so that password must be reachable by whoever operates the box. [source]
- Astropad (existing dossier) says run FileVault off for a home headless Mac. Apple's 26 documentation and Geerling treat FileVault plus remote SSH unlock as a workable headless setup. The trade is disk-at-rest encryption against hands-off recovery; neither source measures LLM workloads. [source]
- Whether authrestart's one-time key survives a kernel-panic reboot is still untested (the sources say it clears at reboot). [source]
- Whether pre-boot SSH unlock works on a Mac whose only admin has no Secure Token, or with key-only SSH, is not stated. [source]
- Whether Apple's 26 SSH unlock uses the same lightweight pre-boot SSH on every Apple silicon model, and its behaviour on Intel Macs, is not covered. [source]
- fdesetup authrestart was introduced in OS X 10.8.2. [source]
- authrestart requires the password or recovery key of an account enabled for FileVault 2. [source]
- authrestart places an unlock key in memory and the reboot clears it, so the bypass is single use. [source]
- After authrestart the Mac boots to the standard login window, not directly into a session. [source]
- authrestart cannot bypass the FileVault screen after an OS update restart. [source]
- authrestart is not a persistent setting; a user-initiated restart still lands on the FileVault lock screen. [source]
- Apple silicon Macs require at least one Secure Token user, and only Secure Token users can log in at the FileVault screen. [source]
- Apple states FileVault can be unlocked over SSH after restart on Apple silicon with macOS 26 or later when Remote Login is on and a network connection is available. [source]
- On Apple silicon institutional recovery keys have no functional value because they cannot access recoveryOS. [source]
- macOS 26 pre-boot SSH unlock requires Remote Login enabled and an administrator password entered over SSH. [source]
- Pre-boot SSH unlock initially worked only over Ethernet; as of macOS 26.5 it worked over Wi-Fi in the author's test. [source]
- A headless LLM host on FileVault needs planned reboots via authrestart and an SSH-unlock procedure for unplanned ones (inferred). [source]
Children
- No children recorded.