Headless mac Mini M1 on Big Sur
So, I just rack mounted a M1 macMini, right next to a 2012 macMini.
There are a number of issues with the M1 mac that I don't have with the Intel Mac, these are most likely due to the different in OS.
The M1 will not respond to Remote Management unless it's logged in. So, you have to figure out how to authenticate to it constantly, which is a significant challenge on a headless installation.
The only solution I've found is to:
- Disable FileVault
- Set my user account to auto-login
- Disable require password at screen saver (so disable the auto-screen lock
- Disable authentication with Apple Watch
The result is a useable, headless, macMini M1
The security risks are minimal, because you'd have to break into my house, find my server rack, disassemble the rack with the minis in it (assuming you knew what you were looking for), and then take the macMini.
At that point, sure, an attacker would have access to all of the files on the mini. Again, that risk is minimal.
The real breaking issue here is FileVault. The login password is the same as the FileVault authorization key and as such, you cannot have auto-login with FileVault enabled. I'm okay with that.
What I'm not okay with is that ARD doesn't work at all until you've logged into the system. That's just silly and renders a whole series of valid and useful security options inoperable.
Why can't the ARD daemon run in the background at boot and then allow me to access the system and authenticate normally like every other system on the planet? Seems odd.
Mac mini, macOS 11.4