[quote='818622021, mobiusmoonglade, /thread/818622, /profile/mobiusmoonglade'] Is there a documented, MDM-compatible way to inject a specific binary path into the ACL of a private key? [/quote] No. Our direction in this space is the ManagedApp framework. It’s super cool. For a short intro, watch WWDC 2025 Session 203 Get to know the ManagedApp Framework. However, it won’t work for you because it’s not available on the Mac. Also note that its focus is on apps and app extensions, so it’s not clear how it would work for a launchd daemon. If you’d like to see ManagedApp support your use case, I recommend that you file an enhancement request describing your requirements. And if you do that, please post your bug number, just for the record. Beyond that, the only option that I’m aware for provisioning a daemon is via the super obscure mechanism [1]. However, that’s really meant for configuration settings rather than credentials. You could obviously jam a credential into it, but that has significant drawbac
Topic:
Privacy & Security
SubTopic:
General
Tags: