NVRAM Password command broken?

Hi people,
I have noticed a strange issue for about a month, most likely caused by the OS X 10.7.2 update:
When you are using the Open Firmware Password tool you can set the bootup password to prevent the usage of bootup commands like CD booting, PRAM reset, Netboot etc. This works fine.
Since I am depoying company-wide Mac distributions I am using the Terminal command to get this to work, the command is:
nvram security-passwort=<PASSWORD ENCODED>
nvram security-mode=command
Up to now (about a month and a half ago) this worked fine, but now I can see the following issues:
When setting the passwort or the command I get the correct value from nvram by checking by command (e.g. 'nvram security-mode' correctly give back the command setting).
If I am setting this on a new Mac it makes no use of it, e.g. I can still access the boot manager without entering the password.
When I try to remove the option to ask for a password on Macs that are asking for it from previous (working) usage of these commands it goes on to ask for the password. E.g. I tell a "blocked" Mac 'nvram security-mode=', reboot and it still asks me for the password when trying to enter the boot manager.
When using the Open Firmware Password Tool, e.g. on the Recovery Disk (yes, it is hidden but can be accessed/started by Terminal) it is working alright.
Has anyone an idea what is going on here or has experienced the same issues?
I appreciate any help.
Regards,
Timo

Thank you, nice idea.
As far as I saw nothing changed, the two settings security-command and security-password are the only ones that have changed as far as I could see. The security-password is only shown when using sudo or root access, so I shouldn't have missed any value.
In about a week I'll be getting a new Mac and I will try to set the NVRAM stuff via terminal first and see if it is working. Maybe this is an issue with our installations, but I could not thing of a possible cause...

Similar Messages

  • /bin/ps shell command broken

    I'm running 10.6.3 and recently noticed the /bin/ps command is broken.
    $ ps -ef
    ps: illegal option -- f
    usage: ps [-AaCcEefhjlMmrSTvwXx] [-O fmt | -o fmt] [-G gid[,gid...]]
    [-u]
    [-p pid[,pid...]] [-t tty[,tty...]] [-U user[,user...]]
    ps [-L]
    How do you log an issue with Apple?

    Yes this discussion should be held in the Mac OS X Technologies Unix forum
    As a point of information, /bin/ps -ef also gives me an illegal -f option.
    HOWEVER, if I become root, it works
    sudo /bin/ps -ef
    UID PID PPID C STIME TTY TIME CMD
    0 1 0 0 19:58.45 ?? 20:07.86 /sbin/launchd
    0 10 1 0 0:03.90 ?? 0:21.57 /usr/libexec/kextd
    0 11 1 0 0:24.04 ?? 0:43.67 /usr/sbin/DirectoryService
    it works nicely.
    Update. The above was run from iTerm session. When I started an Applications -> Utilities -> Terminal session, the /bin/ps -ef WORKED!
    Very strange. I wonder what environmental conditions are affecting the ps option parsing. I find it very hard to beleive that it is the actual terminal emulator.
    Take this discussion over to Mac OS X Technologies -> Unix forum, and let the other interested Unix users have a go at figuring this out.
    Message was edited by: BobHarris

  • G5 lost password command + s not working Help please

    Just took out my old computer g5 thats been put away for about 3 years now. I cant remeber my password to log in and i am trying to enter safe mode to reset password but on start up command + s wont work. I just bought brand new mac keyboard since my was lost. Is there any other way to change the password? I cant figure it out very fustrating.

    Well the oher way is to find a startup dvd and change password via utilities.
    i am trying to enter safe mode to reset password but on start up command + s wont work.
    safe mode is the shift key & doesn't get you in single user mode.
    single user mode:
    You need to get into single use mode for steps one and two that are listed below.
    This page will tell you how to get into single user mode.
    http://support.apple.com/kb/HT1492
    It's lower case s.  Did this today & worked. Hold down until typing comes on screen.
    Basically, you hold down the command + s key **then**  powering on your machine. The command key has a little apple symbol on the lower left. It is between the alt/option key and the space bar. On a PC keyboard, it will be the windows key, I think.  The boot up will take longer than normal.   The filesystem will be checked and repaired.
    I just bought brand new mac keyboard since my was lost.
    Is it wired? Must be wired. Try some pc keyboard.  Use the windows key for the command key.

  • Top command broken in terminal

    OK, the 'top' command in terminal has been broken since I started using Mac OS X. The interactive key commands simply are ignored. Apple needs to fix this, or update the man page to correctly reflect these limitations. For example, typing '?' is supposed to display help information, but does nothing.
    In addition, on my MBP the top command itself seems to use about 40% of the cpu, which is absurd.

    Yes, there are Hosts, but they are very few and have to sift through thousands of posts (mostly looking for those that are abusive or otherwise inappropriate). So it's unlikely that your comment will be seen. The feedback forms are the best way to get comments directly to Apple (and no, you won't get a response, but that doesn't mean that the comments aren't read).

  • Oracle 10.2 RENAME command broken ..

    Hello all,
    I did the following to rename a file:
    "alter database rename file [DATA_FILE_1] to [DATA_FILE_2]'
    But ..
    When I do:
    "select name from v$datafile"
    I see BOTH [DATA_FILE_1] --- AND --- [DATA_FILE_2]
    To me, I should only see [DATA_FILE_2] :-|
    When I try to do the following command to correct the problem,
    "alter database datafile [DATA_FILE_1] offline",
    I get the following error:
    ORA-01145: offline immediate disallowed unless media recovery enabled
    I also did :
    "alter database backup controlfile to trace" and saw that BOTH
    [DATA_FILE_1]
    --- AND ---
    [DATA_FILE_2]
    were listed
    Yikes!
    What happened? Why did the software work this way? How can I solve this problem?
    TIA

    10.2.what?
    Post your actual DDL not a simplified version of it.
    Post the result of this query:
    SELECT file_name, file_id, status, online_status
    FROM dba_data_files;Do not change anything. Do not do a shutdown. Leave everything alone until we can figure out what you are looking at.

  • Wiki "remember password" feature broken after clean install

    I did a clean install, then restored the collaboration folder from an asr backup.
    Only problem is, if clients check the "remember password" box (in the wiki login - not a browser feature), then get the following error:
    The page at <my url here> says:
    Error from server: xmlrpc_digestLogin() takes at most 4 arguments (5 given) (8002)
    Curiously, the text "remember password" is also missing from next to the checkbox.

    Your symptoms imply a mismatch between the web client and the server. It seems the web client is newer (10.5.2) and the wiki server is earlier (pre-10.5.2)
    Could your restore have mismatched items?
    One way to fix this is to do a clean install on another disk, then copy the server bits back over, using ditto or cp. The server bits you'll need live in /usr/share/wikid

  • Is Sequence Layers command broken in After Effects CC 12.2.1.5?

    I select 10 layers.  I select Animation > Keyframe Assistant > Sequence Layers.  I choose the Overlap option.  I set an offset of 9 seconds.  I click OK.  Nothing happens.  Not one thing.  Not one layer is moved at all.  This used to be working.  Is it broken in 12.2.1.5?  Is anyone else experiencing this?  Has anyone found a solution?

    I cannot get this to break... Works fine for me. Try setting all layers to 20 frames and set the overlap to 0.
    Is your comp long enough to hold the sequenced layers. Lets see, I don't know how long the layers are but if the overlap is 9 seconds (wow that's allow dissolve) Then you need 10 times the length of your total footage - 90 seconds for a comp length.

  • Sudo command broken! (UNIX people-- please help a stupid newb :(  )

    To talk to unix people, go here:
    http://discussions.apple.com/forum.jspa?forumID=735

    to fix an that app's perms usually this works:
    sudo chmod -R =rw,+X /Applications/VirtueDesktops.app
    or
    sudo chmod -R =rw,+X,g=u /Applications/VirtueDesktops.app
    a. This returns all files in the app to their usual UNIX defaults.
    b. Some apps will require r/w permissions on the group to function.
    c. All OS X apps should bear admin (80) as the group ID
    d. Some apps require owner be set same as user, most like owner set as root.
    Snow Leopard's Sudo visiblepw flag is no longer set as it was in 10.5.x
    The "visiblepw" option must be entered into the Defaults
    section of the /private/etc/sudoers file in order to allow
    sudo to run in 10.6 when a tty is not allocated. From the
    sudoers manual:
    "visiblepw
    By default, sudo will refuse to run if the user must enter a password but it is not possible to disable echo on the terminal. If the visiblepw flag is set, sudo will prompt for a password even when it would be visible on the screen. This makes it possible to run things like "rsh somehost sudo ls" since rsh(1) does not allocate a tty. This flag is off by default."
    Using visudo, Add the line "Defaults visiblepw" to the Defaults section of the /private/etc/sudoers file and the following error message will no
    longer appear:
    sudo: no tty present and no askpass program specified
    A valid workaround is to use the
    "-S" (capital S) option with sudo.
    I noticed you used su with sudo, that is not cool.
    Kj ♘

  • IMAP-IDLE Command Broken

    Hi all,
    I converted to an IMAP Gmail account two weeks ago, and became hooked to the instantaneous mail downloads thanks to the IDLE command. Now, all of a sudden, emails no longer arrive unless I click on "Get Mail." I have not changed my preferences and the "Use IDLE command if the server supports it" box is still checked.
    I just got off the phone with an Apple rep. who told me that having "Check for New Messages" set to "Manually" was my problem... but I know that she was wrong, as I've been receiving instant messages for two weeks now.
    Your help is appreciated.

    I am also having the same issue and have not been able to find a solution. It just 'stopped' working a few weeks back.
    I have tried deleting and setting up new IMAP account , changing settings...nothing works.
    Message was edited by: mrhud

  • Export command broken

    I select one or more photos from my library. select "share">"export...". a window pops up from which i can choose various types of export. i choose "file export". i go with the default options (format:original, size:full size, name:use filename) then i hit the "export" button.
    my understanding is that at this point, i should get a file dialog where i can select the destination for exporting the files. but i don't. no file dialog appears. the "export" button turns from blue to white when i click it, but other than that, nothing happens - the export dialog just stays there until i hit cancel.
    it doesn't seem to matter whether i've selected one image or a group. it doesn't seem to matter what file export options (size, file format, naming conventions, etc.) i choose. the result is the same.
    I have noticed that the problem occurs when i select "file export" or "quicktime" tabs from the export dialog. if i select "web page", then the problem does not seem to occur, instead a file dialog comes up, as it should.
    i'm sure that this used to work.
    anyone have any suggestions/ideas? should i try re-installing iphoto? and how does one do that, anyway?

    I've never used flicker, however this suggests a possible related cause...
    I use "missing sync" for my treo (palm) phone. missing sync adds an extra tab to the export dialog for exporting photos to the treo. so that could be the cause.
    it also appears that some version of roxio toast that i installed previously added a "toast" tab to the export dialog. so that's another possible cause of the problem. i will attempt to re-install and see if that cleans things up.
    alternatively, does anyone know where "plugins" for iphoto like the ones mentioned above get stored? perhaps i can just remove them.
    thanks for your help.

  • Unable to run export command invalid username and password

    i am trying to run export command to export the complete database but i am getting error of invalid user name and password
    command
    from root i am switching to
    su- oracle
    exp oracle/12345 file=03-2-2013BackupDB.dmp log=backuplog.log
    ORA-01017: invalid username/password; logon denied
    but when i use to login through putty it gives no error
    oracle
    12345
    maybe i am doing something wrong sorry as i am newbie in oracle world
    oracle 11gR2
    Suselinux
    Please help..................

    to make your database in archive log mode you need to give a downtime of your database for this you can do following steps.
    if you are using spfile
    1. shutdown the database.
    2. startup in mount mode
    3. use command 'alter database archivelog';
    4. specify the archive log location using command
    ' alter system set log_archive_dest_1='LOCATION=location_path';'
    5. specify archive log format as
    'alter system set archive_log_format=your choice;'
    6. enable the archive log dest using ' alter system set log_archive_dest_state_1=enable;'

  • Cisco Multicast Manager 3.2 Password recorvery

    Hi, Please can anybody help me how to do a  password recovery on multicast manager 3.2.

    Hi Jose,
    Please find the password recovery steps as below:
    If an administrator password is forgotten, lost, or misconfigured, you need to reset the password on the
    device.
    Note There is no way to restore a lost administrator password. You must reset the password to a new one, as
    described in this procedure.
    To reset the password, do the following:
    Step 1 Establish a console connection to the device and open a terminal session.
    Step 2 Reboot the device.
    While the device is rebooting, watch for the following prompt and press Enter when you see it:
    Cisco CDS boot:hit RETURN to set boot flags:0009
    Step 3 When prompted to enter bootflags, enter the 0x800 value.
    Available boot flags (enter the sum of the desired flags):
    0x0000 - exit this menu and continue booting normally
    8-22
    Backup and Recovery Procedures
    0x2000 - ignore Carrier Detect on console
    0x4000 - bypass nvram config
    0x8000 - disable login security
    [SE boot - enter bootflags]:0x8000
    You have entered boot flags = 0x8000
    Boot with these flags? [yes]:yes
    [Display output omitted]
    Setting the configuration flags to 0x8000 lets you into the system, bypassing all
    security. Setting the configuration flags field to 0x4000 lets you bypass the NVRAM
    configuration.
    Step 4 When the device completes the boot sequence, you are prompted to enter the username to access the CLI.
    Enter the default administrator username (admin).
    Cisco Service Engine Console
    Username: admin
    Step 5 When you see the CLI prompt, set the password for the user using the username password command
    in global configuration mode.
    ServiceEngine# configure
    ServiceEngine(config)# username admin password 0 password
    You can specify that the password be either clear text or encrypted. Zero (0) means the password is
    displayed as a plain word; one (1) means the password is encrypted.The password strength must be a
    combination of alphabetic character, at least one number, at least one special character, and at least one
    uppercase character.
    Note Do not set the user ID (uid).
    Step 6 Save the configuration change by using the write memory command in EXEC mode.
    ServiceEngine(config)# exit
    ServiceEngine# write memory
    Step 7 Optionally, reboot your device by using the reload command.
    ServiceEngine# reload
    Rebooting is optional; however, you might want to reboot to ensure that the boot flags are reset, and to
    ensure that subsequent console administrator logins do not bypass the password check.
    Note In CDS software, the bootflags are reset to 0x0 on every reboot
    If an administrator password is forgotten, lost, or misconfigured, you need to reset the password on the
    device.
    Note There is no way to restore a lost administrator password. You must reset the password to a new one, as
    described in this procedure.
    To reset the password, do the following:
    Step 1 Establish a console connection to the device and open a terminal session.
    Step 2 Reboot the device.
    While the device is rebooting, watch for the following prompt and press Enter when you see it:
    Cisco CDS boot:hit RETURN to set boot flags:0009
    Step 3 When prompted to enter bootflags, enter the 0x800 value.
    Available boot flags (enter the sum of the desired flags):
    0x0000 - exit this menu and continue booting normally
    8-22
    Backup and Recovery Procedures
    0x2000 - ignore Carrier Detect on console
    0x4000 - bypass nvram config
    0x8000 - disable login security
    [SE boot - enter bootflags]:0x8000
    You have entered boot flags = 0x8000
    Boot with these flags? [yes]:yes
    [Display output omitted]
    Setting the configuration flags to 0x8000 lets you into the system, bypassing all
    security. Setting the configuration flags field to 0x4000 lets you bypass the NVRAM
    configuration.
    Step 4 When the device completes the boot sequence, you are prompted to enter the username to access the CLI.
    Enter the default administrator username (admin).
    Cisco Service Engine Console
    Username: admin
    Step 5 When you see the CLI prompt, set the password for the user using the username password command
    in global configuration mode.
    ServiceEngine# configure
    ServiceEngine(config)# username admin password 0 password
    You can specify that the password be either clear text or encrypted. Zero (0) means the password is
    displayed as a plain word; one (1) means the password is encrypted.The password strength must be a
    combination of alphabetic character, at least one number, at least one special character, and at least one
    uppercase character.
    Note Do not set the user ID (uid).
    Step 6 Save the configuration change by using the write memory command in EXEC mode.
    ServiceEngine(config)# exit
    ServiceEngine# write memory
    Step 7 Optionally, reboot your device by using the reload command.
    ServiceEngine# reload
    Rebooting is optional; however, you might want to reboot to ensure that the boot flags are reset, and to
    ensure that subsequent console administrator logins do not bypass the password check.
    Note In CDS software, the bootflags are reset to 0x0 on every reboot

  • Corrupt NVRAM - Possibly????

    Hi,
    I have a really funny problem with my iMac 21" Intel Core 2 Duo.
    It boots really slowly and when it reaches that login screen it has a kind of blue hue faded look. The keyboard and mouse clicks are unresponsive but the mouse cursor moves. I can ARD to the machine and the remote keyboard and mouse work fine. However the machine is slow.
    I have tried to rest the NVRAM but I have the firmware password enabled so the keyboard shortcut is not working.
    NVRAM terminal command errors with the command not supported on this system. This is odd is it works fine on the other machines I have which are identical models.
    I have booted to the installation disc and used the firmware password utility but it doesnt remove the password. I have tried altering the RAM but again it doesnt remove the password.
    I have booted to a known good OS via target disc mode and all problems still exist. I have tested the keyboard and mouse and they are OK.
    I'm sure this is just an NVRAM prob but is there another way to reset it.
    Thanks
    Keith
    iMac 21" (Silva)
    Intel Core 2 Duo
    10.6.8

    Solved.
    I just started taking out RAM and replacing it until it eventually removed the EFI password (had to try both modules a few times each before it work).
    Zapped the PRAM and hey presto all is working sweet.
    Keith

  • I have a macbook pro (13inch). I had a firmware password set on it and updated the firmware when apple update told me to. I cannot change the firmware password or remove it now.

    Hello,
    I have a macbook pro which had a firmware password set on it (security-mode = command).
    Update asked me to install updates and one of them was an EFI update. I proceeded and the macintosh booted just fine.
    I've tried changing the firmware password, and removing the password without success so far. It's almost like the nvram terminal command does nothing as far as security is concerned.
    Help would be appreciated!
    J

    Apparently the newer macbooks use a different utility than the older macbooks.
    setregproptool will ask for the current password, and nvram is not used for these anymore.
    J

  • Firmware password ignored

    Hello
    I set a firmware password but it is ignored at boot time and I can no longer boot from the DVD.
    I booted from the original Apple DVD (by holding the c key) and chose the firmware password from the utilities. After setting the password, I rebooted and boot succeeded without a password prompt. I have shutdown/restarted many times and not seen the prompt.
    I also can no longer boot from DVD. Booting while holding the c key no longer works.
    Note, if it means anything, that the 'nvram -p' command gives 'security-mode command'
    Can anyone help/advise.
    Thanks.

    I have a MBP and just set a firmware password a few hours ago. To make sure it took, I held down option key and also did the keys for open firmware (O + F), C for startup from CD/DVD and T for Firewire target disk mode and nothing worked as it should.
    Here's one option for you. Open Terminal. on the command line type: nvram -p
    This is the unix command for working with open firmware. The '-p' prints the values of the public variables to the terminal window. Amongst all the gibberish, look for the following line:
    security-mode [value here]
    If the [value here] on your system says 'none' then, for some reason open firmware didn't take.
    If the value is 'command' then it should be working correctly
    Also, if you have replaced your internal optical drive with an extra hard disk, make sure you have the volume you want to boot from set correctly in Startup Disk. Amongst the variables that Open Firmware stores is the startup disk. So if you have two internal drives and you set the firmware password on one and you normally boot your computer with the other drive, that could be why its not working for you.
    At the very least, I would take the time to try it one more time via the DVD utility. Startup off the DVD, turn off firmware password, restart the machine, startup off the DVD again and set a firmware password and then restart again. I would think it would be fine at that point.
    Two cautions:
    1) Be careful where and with whom around you use this command as the open firmware password you chose is not encrypted, it is only obfuscated. Unix is actually showing you your firmware password in hexadecimal notation so it could be deciphered by someone who knows how.
    2) While you can use sudo with nvram to change open firmware variables, I do not recommend it as I have not tried it and I don't know how your system would behave. So if you choose to do this you do so at your own risk.
    Let us know what happens.

Maybe you are looking for

  • Error handling and logout in OIF

    For a identity provider, what needs to be done for error handing and logout? Thanks.

  • Mss upgrade from ecc 5.0 to ecc 6.0

    pls share what are all the configurations need to be done for upgrade to ecc 6.0 from 5.0 in mss and is pcr functionality changes or remains same.. pls share any document regaingd the ess/mss configruation document

  • Long tables in iBook author

    Hi there, I try to insert the table that runs across 20 pages in he Word document. iBook author shows only the table on the first page. I can't access and flow the rest of the table. What am I doing wrong? Retyping of this table in IBA is not the opt

  • Please help, after last update photoshop cc stopped working

    Hello, I got a problem. After yesterday update my Photoshop CC doesn't work. I'm getting A. Photoshop CC has stopped working message. Please can you help? Thanks sebastian

  • Service levels in UCCX- include IVR time?

    I`ve been asked a question regarding Service Levels. Within UCCX the levels are set so if the service level is 10 and the % is set to 25% then we expect 25% of  calls to be answered within 10secs however if you have IVR, option 1, press 2 etc should