Open robbash opened 3 years ago
@robbash after tampering system volume and breaking the seal boot is possible thanks to creating new bootable snapshot. but integrity check indeed fails, so SIP can't be fully enabled, unless volume is sealed again. I don't know clear way to re-seal volume, but apparently installer does that, probably there might be answers at Dortania (OpenCore Legacy Patcher),
I'm not sure if they manage to re-seal the volume, but at least, forcing FireVault2 to work with broken seal is mentioned in their code base:
Couple of questions to the @fxgst:
Thanks!
Hey,
thanks for the tool, I did those steps all manually though. All looks good after my changes.
BUT: Have you achieved to re-enable SIP and FileVault? I'm on an M1. Trying to re-enable SIP results in "failed to set system integrity configuration in boot policy". Similar error message on trying
csrutil clear
.Any ideas?
Cheers