Skip to main content
Question

Report "Secure Boot" status?

  • July 24, 2018
  • 5 replies
  • 52 views

donmontalvo
Forum|alt.badge.img+36

Is there a way (yet) to report Secure Boot status, for example "Full Security" vs "No Security"?

Looked through System Profiler, didn't see anything...we need to flag computers that are not set to our desired "Full Security" setting.

@dan.kubley

5 replies

Forum|alt.badge.img+18
  • Honored Contributor
  • July 24, 2018

We really need a way to manage these settings!!!


Forum|alt.badge.img+16
  • Honored Contributor
  • July 24, 2018

I opened a ticket, for config profile control of "SIP" before it was released to the public ... Apple eng said I was nuts and current they are saying use a firmware password.

C


Forum|alt.badge.img+18
  • Employee
  • July 24, 2018

Hi @donmontalvo ,
We currently have the ability to report on System Integrity Protection:
Enabled under the Security section of an inventory record. As to Secure Boot, that would be a feature request. Please file that if you so desire.


Forum|alt.badge.img+16
  • Valued Contributor
  • July 24, 2018

Given it's a whole new hardware subsystem that might have it's own storage who knows...
But given SIP status is stored in NVRAM (csr-active-config), it might be worth looking at nvram -p to see if there are any security settings included now.
If the behaviour was the same as SIP they would only show if they had been changed from the default setting.


Forum|alt.badge.img+8
  • Contributor
  • May 15, 2019

Try this if you're still looking: Secure Boot EA