HorsewareIT

Q: How do I disable Keychain

For our users Keychain is a nightmare - especially because they do not remember the first password - as the network enforces them to change it every 90 days. With this the keychain pop keeps coming up constantly and is affecting the users working. So I would like to know how to stop keychain or to disable it?

Mac Pro (Early 2009), Mac OS X (10.6.8)

Posted on Feb 9, 2012 4:14 AM

Close

Q: How do I disable Keychain

  • All replies
  • Helpful answers

Previous Page 2
  • by rcgrohn,

    rcgrohn rcgrohn Apr 10, 2014 10:24 AM in response to HorsewareIT
    Level 1 (0 points)
    Apr 10, 2014 10:24 AM in response to HorsewareIT

    Or add a feature to the keychain to sync the keychain password with the AD server password?

  • by briegull,

    briegull briegull Apr 30, 2014 7:34 AM in response to HorsewareIT
    Level 1 (0 points)
    Apr 30, 2014 7:34 AM in response to HorsewareIT

    Agreed that it is annoying to remember two passwords to get to one place. I deal with people in a retirement home whose memory is poor, and their getting prompted all the time is infuriating and gets them tied up in knots.

  • by Drew Reece,

    Drew Reece Drew Reece Apr 30, 2014 8:51 PM in response to rcgrohn
    Level 5 (7,721 points)
    Notebooks
    Apr 30, 2014 8:51 PM in response to rcgrohn

    rcgrohn wrote:

     

    Why does Apple not offer a tool to automatically sync the login password with the keychain password when Active Directoy needs to be used? Maybe add a button "Sync with AD" in the user account area?

    If you could just issue a command to change the keychain password without actually knowing the old one it wouldn't be a very secure keychain now would it? You could reset the bosses Keychain & get a raise .

     

     

     

    Has anyone tried changing an empty login.keychain to be owned by root with no access for the user? It should prevent a user writing to that keychain which should prevent any user saving data to it (which causes the unlock prompts).

     

    It's probably a terrible idea, since the OS will not remember any passwords for that user, so try it on a test account.

     

    Another option is you make a script that runs on user login & resets the keychain password (assuming you can query the new & old password from Active Directory - is this even possible).

     

    The 'security' command will allow you to script resetting the keychain password…

    https://developer.apple.com/library/mac/documentation/Darwin/Reference/ManPages/ man1/security.1.html

     

    It will also allow you to set passwords for particular services, apps, URLS etc (like when the AD password for POP/IMAP changes).

     

     

    It's not a simple answer - but this is Apple, you have to think different if you want the OS to behave how you want.

  • by paperstars55,

    paperstars55 paperstars55 Jul 24, 2014 6:36 PM in response to HorsewareIT
    Level 1 (0 points)
    Jul 24, 2014 6:36 PM in response to HorsewareIT

    I would go to the primary Safari menu in the upper left corner, click preferences, passwords, and delete the ones you don't want it to store. The next time you enter your own passwords and keychain access pops up, select never ask to store again. You can also delete the passwords by going to Applications, then Keychain access and delete the web passwords under in the password category.

  • by Bruce Buckland,

    Bruce Buckland Bruce Buckland Aug 8, 2014 2:57 PM in response to HorsewareIT
    Level 1 (4 points)
    Aug 8, 2014 2:57 PM in response to HorsewareIT

    The problem the OP has I have too.  But I would describe it differently.

     

    I have passwords stored for the active directory domain.  Those passwords are stored in "internet passwords" in the System Preferences pane, associated with Exchange.  The result is that when the password policy requires a user to CHANGE his password, then the user does that (for instance on an office computer, running windows), the result is that the first time the user boot's his mac at home, and starts mail a very bad thing happens.

     

    Mail tries multiple times to log in using the old password and then gives up (the multiple bad attempts actually disable the user account in Active Directory in my case).

     

    Then the user can't log in at home or at work, and has to call support.

     

    What is needed is a way to NOT remember the Exchange password and prompt for it each time it is needed by the mac app.  These apps would include Mail, Calendar, Notes, Reminders and Contacts.

  • by Herbie021,

    Herbie021 Herbie021 Dec 16, 2014 6:21 PM in response to WildinPunk
    Level 1 (0 points)
    Dec 16, 2014 6:21 PM in response to WildinPunk

    Thanks WildinPunk, it work for me also.

  • by Man-of-Kent,

    Man-of-Kent Man-of-Kent Jan 23, 2015 1:22 PM in response to baltwo
    Level 1 (0 points)
    Jan 23, 2015 1:22 PM in response to baltwo

    In answer to Baltwo, use Last Pass (for Mac) for all your passwords. Far more compreehensive than keychain. I hope I have disabled it according to ComputerGeek147.

  • by baltwo,

    baltwo baltwo Jan 23, 2015 3:44 PM in response to Man-of-Kent
    Level 9 (62,256 points)
    Jan 23, 2015 3:44 PM in response to Man-of-Kent

    Why? I have no issues with using the built-in keychain mechanism.

  • by mya homet,

    mya homet mya homet May 21, 2015 9:46 PM in response to HACKINT0SH
    Level 1 (0 points)
    May 21, 2015 9:46 PM in response to HACKINT0SH

    Dear Hackintosh,

    I'd bet you are a level one by your response to the very reasonable question posed by several Mac users (such as HorseWareIT): "How do I disable Keychain?" 

    Any level-minded Mac user could never have replied so daftly. Keep quiet unless you have experienced what they are telling you. They go on this forum for good reason, and one is certainly NOT to get glib and flat-line answers.  The keychain issue is madness for a multitude of reasons. HorseWareIT explained only one possible, maddening scenario.

  • by mya homet,

    mya homet mya homet May 21, 2015 9:49 PM in response to paperstars55
    Level 1 (0 points)
    May 21, 2015 9:49 PM in response to paperstars55

    Hey, PaperStars -- that didn't work at all. What Mac product do you have?

  • by Seven Pictures Hollywood,

    Seven Pictures Hollywood Seven Pictures Hollywood Aug 29, 2015 11:08 AM in response to ComputerGeek147
    Level 1 (0 points)
    Aug 29, 2015 11:08 AM in response to ComputerGeek147

    Great thank you very much - perfect solution!!

    Best,

    AC

  • by nasppilot,

    nasppilot nasppilot Oct 10, 2015 6:01 PM in response to terry999
    Level 1 (0 points)
    Oct 10, 2015 6:01 PM in response to terry999

    THANK YOU!!!  This worked exactly as you said.  I guess i have to research more about keychains....it was quite stressful~   you saved the day

  • by Steve Seny,

    Steve Seny Steve Seny Feb 11, 2016 12:06 PM in response to WildinPunk
    Level 1 (5 points)
    Feb 11, 2016 12:06 PM in response to WildinPunk

    WOW Thank you.  This absolutely fixed the constant annoying Keychain prompts.  But I have a feeling that this has only 4 thanks because people don't know that you can't just open finder to find Keychains. 
    Use spotlight to find Terminal.

    In Terminal type this command  cd /Users/admin/Library/Keychains/   Note that Capital letters count so /users is not the same as /Users.  Replace admin with your username.

    From here delete the files with this command.  *WARNIG MAKE SURE YOU ARE REALLY IN THE CORRECT DIRECTORY*

    Type  pwd   It should respond with /Users/admin/Library/Keychains/ 

    then delete everything with this command.   rm -f *   <<<  That's  r m    -f  * <<<Added spaces so r and m are legible.

    log out and log back in and enjoy No More keychain spams.

  • by djscorpio74,

    djscorpio74 djscorpio74 May 23, 2016 6:33 AM in response to WildinPunk
    Level 1 (4 points)
    May 23, 2016 6:33 AM in response to WildinPunk

    I was reading through this forum 'cause keychain drives me mad every time I restart my Mac. Today flavor of madness was my Lync client connected to my corporate O365 account was giving me the obstinately recurring keychain popups.

     

    following your advise, I just trashed the Oc_Container... file in the library\keychains\ folder and Lync reset to the current active O365 password.

     

    Now, I';m going to go trash all the other keychains and start from scratch.

     

    Thanks WildinPunk

Previous Page 2