Skip to content

Instantly share code, notes, and snippets.

@rickmark
Created February 17, 2026 13:17
Show Gist options
  • Select an option

  • Save rickmark/4e6dd48ac8a33f7cc38b621cef95ccec to your computer and use it in GitHub Desktop.

Select an option

Save rickmark/4e6dd48ac8a33f7cc38b621cef95ccec to your computer and use it in GitHub Desktop.
Current local policy:
OS environment:
OS Type : macOS
OS Pairing Status : Not Paired
Local Policy Nonce Hash (lpnh): E390D6EA84FD57A37FD41F35EC4CA3CFD37BF1C9C27F03C8D3A566B5EC58A7A127EEC36777880217CB823C21853E867C
Remote Policy Nonce Hash (rpnh): A2A49BF4A25BFFD75E017FD270BE84CE2D34DC9D25AEC12246C329A9142B7F67E1F007C7EAFE69C553B9F4DE08715785
Recovery OS Policy Nonce Hash (ronh): ED7B8ED249EC4D99568959359B42868B47BA81CC2571EBDD554C56827C8D6AB29C6FF732C225F36C7C568309E33C357E
Local policy:
Pairing Integrity : Valid
Signature Type : BAA
Unique Chip ID (ECID):
Board ID (BORD): 0x46
Chip ID (CHIP): 0x6031
Certificate Epoch (CEPO): 0x1
Security Domain (SDOM): 0x1
Production Status (CPRO): 1
Security Mode (CSEC): 1
Local Boot (lobo): 1
OS Version (love): 25.4.125.0.0,0
Volume Group UUID (vuid):
KEK Group UUID (kuid):
Local Policy Nonce Hash (lpnh): E390D6EA84FD57A37FD41F35EC4CA3CFD37BF1C9C27F03C8D3A566B5EC58A7A127EEC36777880217CB823C21853E867C
Remote Policy Nonce Hash (rpnh): A2A49BF4A25BFFD75E017FD270BE84CE2D34DC9D25AEC12246C329A9142B7F67E1F007C7EAFE69C553B9F4DE08715785
Next Stage Image4 Hash (nsih): 88B519A5293CAD0E56A2B30803B6CE4FB7941F26E38C502A2A1EBF3D7AF34A58FBE699B2F36756FF52CD690C9CD038BD
Cryptex1 Image4 Hash (spih): F74D4EAFB2834AA68C01A325CFE0A5F687FDD4CEF08599EE639823B57573DE044CAF193E2E6FE87749B225A67427B4C1
Cryptex1 Generation (stng): 5
User Authorized Kext List Hash (auxp): absent
Auxiliary Kernel Cache Image4 Hash (auxi): absent
Kext Receipt Hash (auxr): absent
CustomKC or fuOS Image4 Hash (coih): absent
Security Mode: Full (smb0): absent
3rd Party Kexts Status: Disabled (smb2): absent
User-allowed MDM Control: Disabled (smb3): absent
DEP-allowed MDM Control: Disabled (smb4): absent
SIP Status: Enabled (sip0): absent
Signed System Volume Status: Enabled (sip1): absent
Kernel CTRR Status: Enabled (sip2): absent
Boot Args Filtering Status: Enabled (sip3): absent
# DDI - splat
> 1493:d=5 hl=2 l= 9 prim: OBJECT :sha384WithRSAEncryption
> 1504:d=5 hl=2 l= 0 prim: NULL
> 1506:d=4 hl=2 l= 79 cons: SEQUENCE
> 1508:d=5 hl=2 l= 43 cons: SET
> 1510:d=6 hl=2 l= 41 cons: SEQUENCE
> 1512:d=7 hl=2 l= 3 prim: OBJECT :commonName
> 1517:d=7 hl=2 l= 34 prim: UTF8STRING :Apple DDI Secure Boot Root CA - G1
> 1553:d=5 hl=2 l= 19 cons: SET
> 1555:d=6 hl=2 l= 17 cons: SEQUENCE
> 1557:d=7 hl=2 l= 3 prim: OBJECT :organizationName
> 1562:d=7 hl=2 l= 10 prim: UTF8STRING :Apple Inc.
> 1574:d=5 hl=2 l= 11 cons: SET
> 1576:d=6 hl=2 l= 9 cons: SEQUENCE
> 1578:d=7 hl=2 l= 3 prim: OBJECT :countryName
> 1583:d=7 hl=2 l= 2 prim: PRINTABLESTRING :US
> 1587:d=4 hl=2 l= 30 cons: SEQUENCE
> 1589:d=5 hl=2 l= 13 prim: UTCTIME :240328183821Z
> 1604:d=5 hl=2 l= 13 prim: UTCTIME :401114000000Z
> 1619:d=4 hl=2 l= 103 cons: SEQUENCE
> 1621:d=5 hl=2 l= 67 cons: SET
> 1623:d=6 hl=2 l= 65 cons: SEQUENCE
> 1625:d=7 hl=2 l= 3 prim: OBJECT :commonName
> 1630:d=7 hl=2 l= 58 prim: UTF8STRING :ZFF10-TssLive-ManifestKey-ExtraContent-DeviceClass-RevA-DC
> 1690:d=5 hl=2 l= 19 cons: SET
> 1692:d=6 hl=2 l= 17 cons: SEQUENCE
> 1694:d=7 hl=2 l= 3 prim: OBJECT :organizationName
> 1699:d=7 hl=2 l= 10 prim: UTF8STRING :Apple Inc.
> 1711:d=5 hl=2 l= 11 cons: SET
> 1713:d=6 hl=2 l= 9 cons: SEQUENCE
> 1715:d=7 hl=2 l= 3 prim: OBJECT :countryName
> 1720:d=7 hl=2 l= 2 prim: PRINTABLESTRING :US
> 1724:d=4 hl=4 l= 546 cons: SEQUENCE
> 1728:d=5 hl=2 l= 13 cons: SEQUENCE
> 1730:d=6 hl=2 l= 9 prim: OBJECT :rsaEncryption
# Generic
< 1366:d=4 hl=2 l= 3 cons: cont [ 0 ]
< 1368:d=5 hl=2 l= 1 prim: INTEGER :02
< 1371:d=4 hl=2 l= 20 prim: INTEGER :211B7E555E9EE65CCD6B1FD01F370475A4153378
< 1393:d=4 hl=2 l= 13 cons: SEQUENCE
< 1395:d=5 hl=2 l= 9 prim: OBJECT :sha384WithRSAEncryption
< 1406:d=5 hl=2 l= 0 prim: NULL
< 1408:d=4 hl=2 l= 84 cons: SEQUENCE
< 1410:d=5 hl=2 l= 48 cons: SET
< 1412:d=6 hl=2 l= 46 cons: SEQUENCE
< 1414:d=7 hl=2 l= 3 prim: OBJECT :commonName
< 1419:d=7 hl=2 l= 39 prim: UTF8STRING :Apple Extra Content Global Root CA - G1
< 1460:d=5 hl=2 l= 19 cons: SET
< 1462:d=6 hl=2 l= 17 cons: SEQUENCE
< 1464:d=7 hl=2 l= 3 prim: OBJECT :organizationName
< 1469:d=7 hl=2 l= 10 prim: UTF8STRING :Apple Inc.
< 1481:d=5 hl=2 l= 11 cons: SET
< 1483:d=6 hl=2 l= 9 cons: SEQUENCE
< 1485:d=7 hl=2 l= 3 prim: OBJECT :countryName
< 1490:d=7 hl=2 l= 2 prim: PRINTABLESTRING :US
< 1494:d=4 hl=2 l= 30 cons: SEQUENCE
< 1496:d=5 hl=2 l= 13 prim: UTCTIME :240328183815Z
< 1511:d=5 hl=2 l= 13 prim: UTCTIME :411114000000Z
< 1526:d=4 hl=2 l= 110 cons: SEQUENCE
< 1528:d=5 hl=2 l= 74 cons: SET
< 1530:d=6 hl=2 l= 72 cons: SEQUENCE
< 1532:d=7 hl=2 l= 3 prim: OBJECT :commonName
< 1537:d=7 hl=2 l= 65 prim: UTF8STRING :ZFF10-TssLive-ManifestKey-ExtraContent-DeviceClass-Global-RevA-DC
< 1604:d=5 hl=2 l= 19 cons: SET
< 1606:d=6 hl=2 l= 17 cons: SEQUENCE
< 1608:d=7 hl=2 l= 3 prim: OBJECT :organizationName
< 1613:d=7 hl=2 l= 10 prim: UTF8STRING :Apple Inc.
< 1625:d=5 hl=2 l= 11 cons: SET
< 1627:d=6 hl=2 l= 9 cons: SEQUENCE
< 1629:d=7 hl=2 l= 3 prim: OBJECT :countryName
< 1634:d=7 hl=2 l= 2 prim: PRINTABLESTRING :US
< 1638:d=4 hl=4 l= 546 cons: SEQUENCE
< 1642:d=5 hl=2 l= 13 cons: SEQUENCE
< 1644:d=6 hl=2 l= 9 prim: OBJECT :rsaEncryption
< 1655:d=6 hl=2 l= 0 prim: NULL
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment