Copying login keychains between Macs fails on Secure Enclave Macs with Tahoe

Users of macOS Tahoe are finding that login keychains can no longer be easily migrated between Macs equipped with the Secure Enclave. This change is due to Apple's updated security architecture, which requires a hardware-bound round trip to the Secure Enclave to decrypt keychain data.
Why it matters
This security update complicates system administration and data migration for power users and IT professionals who rely on manual keychain management.
I recently encountered an issue with the login keychain on macOS. For those not familiar with the login keychain, it’s a keychain that macOS automatically creates for each user account on a Mac. The password for a user’s login keychain matches the password used to log in to the Mac. It is stored as an encrypted database file and unlocks automatically when the user logs in, since the login password and keychain password are the same by default.
As of macOS Tahoe, the login keychain is a SQLite database file named login.keychain-db . It is stored in the user’s home folder in the following directory:
/Users/username_goes_here/Library/Keychains
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in