Contribute
Register

Explaining OS X El Capitan Security Changes - Workarounds and Current Information

Do you think somebody will come up with a custom kernel that will do away with SIP? I can't even use El Capitan because of Avid C400 drivers issues because of avid's driver kexts unsigned. I find this kinda of a con and I think I'm stopping from upgrading at Yosemite. Even if I fully disable SIP the kexts will not even load. Yes I know this could be because of a OS change itself but Apple is making harder for people and companies. And, another way to for people to pay Apple just to be able to use signed kexts.
 
Touching on this....

I have my system with SIP enabled, but using ALCCommand for my audio.

This places the RealtekALC.kext in EFI 10.11 Kexts.

I noticed that after a few reboots, my audio stops working and have to rebuild cache (whole process of SIP Disable....Rebuild..Enable). This gets the audio back perfectly however like I said after a couple reboots it's greyed out.


Should I place the RealtekALC.Kext into my SLE and then once I rebuild the cache, this issue should subside?



TIA :)

I am having the exact same problem on my build.
The Audio kext are the only one placed in System/labrary/ extensions and after a few reboots sound is greyed out.
Funny thing if i do nothing and just do about two to three reboots sound is back, without doing anything else.

I have no idea how to fix it?
 
From Terminal issue the command: csrutil status

The result, if CsrActiveConfig is set to 0x3 in your config.plist, should look as follows:

View attachment 153505

What does the last line in that terminal output infer ?

"This is an unsupported configuration, likely to break in the future."
 
I have used this method with cloverALC audio injection, what's the best state to leave it in after I've installed it? Do I need to keep it with SIP partially disabled from now on?
 
I am having the exact same problem on my build.
The Audio kext are the only one placed in System/labrary/ extensions and after a few reboots sound is greyed out.
Funny thing if i do nothing and just do about two to three reboots sound is back, without doing anything else.

I have no idea how to fix it?

Same here guys, currently I've kept SIP Partially disabled, this probably isn't the best thing to do? But if I enable SIP after a few reboots it stops working. The only way I've managed to get it consistent is with SIP Partially disabled - any ideas?
 
I've tried setting the RtVariables to disable SIP but it keeps blocking kext injections and reporting "System Integrity Protection status: enabled." My current setup is a little confusing where I have Clover installed on the Mac harddrive but I also have to use a Mac install USB with Clover on it to actually boot the Mac side. The computer has two seperate SSDs, one with Windows 10 and the other with Mac OS 10.11 Beta (15A279b). Anyway, I've edited the config.plist on every instance of Clover to various values throught the tests such as 0x67 and 0x11 but it can never disable SIP. I tried booting into the Recovery HD to just use "csrutil disable" but the Recovery HD has a fatal boot error pertaining to invalid signature.
Screen Shot.png
 
thanks
 
Last edited:
Hi, I'm using Rehabmans plist and according to #1 post in this thread (based on value comparison with my plist) I've got SIP disabled completely, BUT everytime I launch xtrafinder it states that I've SIP Enabled (thus preventing it to work), even tough it's features are working as they should be. It's kinda annoying having to click "ok" everytime. Is there anything I can do about it ?

*) same as above, recovery HD won't boot, it keeps "spinning"

It it also said that disabled SIP fixes broken Open VPN in El Capitan... (it doesn't)


EDIT: "csrutil status" says it's disabled, so problem will be probably elsewhere..
 
Hello people!
I have a little problem with my setup, please help me!
The problem is I can boot into system only if Ii boot into single user mode and:
1. fsck -fy
2. mount -uw /
3. touch /System/Library/Extensions && kextcache -u /
4. reboot

So when I reboot I have the same kernel panic as always and I need to go to single user mode again....
Is the a way to make permanent my booting experience?
I'm using the same RtVariables values as in first post.
Thank you!

P.S.: it reboots after each kernel panic an if I leave it alone it can reach the desktop after some reboots, it may be a couple of reboots or a dozen!
 
Back
Top