Sample Header Ad - 728x90

Manually Decrypt Partially Cloned APFS Volume

4 votes
1 answer
798 views
I recently attempted to clone a failing external drive to a new external drive. The clone failed part-way into the process. The original drive hardware has now fully failed, so I'm trying to recover as much as I can from the clone. When I plug in the clone, macOS gives me an error reading "The disk 'Volume_Name' can't be unlocked. A problem was detected with the disk that prevents it from being unlocked." Disk Utility shows 1.6 TB used. I tried unlocking it from the command line and the Terminal output was Passphrase incorrect or user does not exist. I am certain I'm entering the passphrase correctly. A scan in Data Rescue shows a recognizable list of files and folders. I can copy a file from the clone, but I can't open it. I am guessing that the files are encrypted individually while the folder structure is not. From my research, macOS creates a separate cryptouser on an encrypted disk (separate from a Mac account/user) so that one password can open the disk on any Mac. When I used diskutil apfs listcryptousers /dev/Volume_Name in Terminal, the output is No cryptographic users for Volume_Name when it *should* output something like this: Terminal output I believe I've recovered the clone volume's cryptouser string from Keychain Access on two separate Macs (they match), so I have both the user and the passphrase. Is there a way to enter these manually and decrypt the drive? Either via the Terminal or a third-party piece of software? For reference, I got a lot of information from this page even though it outlines boot drives instead of external ones. Thank you in advance!
Asked by jay-z (41 rep)
May 8, 2022, 08:38 PM
Last activity: May 30, 2025, 06:10 PM