OS X El Capitan System Integrity Protection - Ability to bless volumes

Originator:eriknicolasgomez
Number:rdar://21310286 Date Originated:09-June-2015
Status:Open Resolved:No
Product:OS X El Capitan Product Version:15A178w
Classification:OS X Security Reproducible:Yes
 
Summary:
With OS X El Capitan, you can no longer use the bless command to target a netboot volume.

Bless is essential to many imaging solutions when the server is hosted on another subnet.

Steps to Reproduce:
1. Attempt to bless a machine on OS X El Capitan pointing to a NetBoot volume. 

sudo bless --netboot --server bsdp://10.10.10.10 --nextonly --verbose

EFI states boot arguments are set.

2. Reboot machine

Expected Results:
Machine should connect to NetBoot default instance.

Actual Results:
Machine reboots back into OS X El Capitan

Version:
OS X El Capitan Developer Beta 1 / 15A178w

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!