如何在macOS High Sierra配置wfsctl WebDAV适配基础认证应用及Password Wallet?
Hey folks, I’ve messed around with macOS High Sierra’s built-in wfsctl WebDAV server a bunch to get it playing nice with apps that need basic authentication—including Password Wallet. Let me walk you through exactly what worked for me:
The default wfsctl setup doesn’t ship with authentication enabled, so we need to tweak its configuration to require a username and password. Here’s the reliable, persistent method I settled on:
First, stop the default service if it’s running (it might start automatically on boot):
sudo launchctl unload /System/Library/LaunchDaemons/com.apple.wfsctl.plistCreate a custom launchd plist to override the default settings. Fire up your favorite text editor (I use nano) and make
/Library/LaunchDaemons/com.apple.wfsctl.custom.plistwith this content:<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Label</key> <string>com.apple.wfsctl.custom</string> <key>ProgramArguments</key> <array> <string>/usr/sbin/wfsctl</string> <string>--server</string> <string>--auth-type=basic</string> <string>--auth-user=your_system_username</string> <string>--auth-pass=your_secure_password</string> <string>--root=/Library/WebDAV</string> <!-- Pick a folder for your WebDAV content --> <string>--port=8080</string> <!-- Use 80 if you want standard HTTP port (needs root) --> </array> <key>RunAtLoad</key> <true/> <key>KeepAlive</key> <true/> <key>StandardOutPath</key> <string>/var/log/wfsctl.log</string> <key>StandardErrorPath</key> <string>/var/log/wfsctl.log</string> </dict> </plist>Replace
your_system_usernameandyour_secure_passwordwith your actual Mac user credentials (or create a dedicated service user if you prefer). The--rootpath is where your WebDAV files will live—make sure this folder exists first!Set the correct permissions for the plist so launchd can read it:
sudo chown root:wheel /Library/LaunchDaemons/com.apple.wfsctl.custom.plist sudo chmod 644 /Library/LaunchDaemons/com.apple.wfsctl.custom.plistLoad the custom service to start the authenticated WebDAV server:
sudo launchctl load /Library/LaunchDaemons/com.apple.wfsctl.custom.plistDouble-check it’s running with:
ps aux | grep wfsctlYou should see the process listed with your custom arguments.
Password Wallet has a few specific quirks when it comes to WebDAV, but once you’ve got basic auth set up, it’s smooth sailing. Here’s what to do:
- Prepare the WebDAV folder: If you used
/Library/WebDAVas your root, create it and set permissions so wfsctl can access it:sudo mkdir /Library/WebDAV sudo chown your_system_username:staff /Library/WebDAV sudo chmod 755 /Library/WebDAV - Configure Password Wallet’s sync:
- Open Password Wallet, head to
Settings > Sync > Add Sync Location > WebDAV. - Enter the server URL:
http://your-macs-local-ip:8080(find your Mac’s IP in System Preferences > Network). - Plug in the username and password you set in the plist.
- Hit
Test Connection—if it passes, you’re good to go! If not, check the log at/var/log/wfsctl.logfor errors (permission issues are the most common culprit).
- Open Password Wallet, head to
- Pro tip: If you run into sync failures, make sure Password Wallet has permission to access your network (check System Preferences > Security & Privacy > Privacy > Full Disk Access, though usually just network access is enough).
After testing this setup for months, here are the key things I’ve learned to keep it stable and secure:
- Persistent service: Using a launchd plist ensures the server starts on boot and restarts if it crashes—way better than running it manually in the terminal.
- Security heads-up: Storing your password in plaintext in the plist isn’t the most secure, but for home use (especially if your Mac is locked down), it’s acceptable. If you want to harden it, you can use a shell script to pull the password from the macOS Keychain and update the plist to run that script instead—just know it adds a bit of complexity.
- Firewall settings: If you’re using a non-standard port like 8080, make sure to allow incoming connections on that port in macOS Firewall (System Preferences > Security & Privacy > Firewall > Firewall Options).
- External access: If you want to access the server from outside your home network, set up port forwarding on your router to point to your Mac’s IP and the wfsctl port. Only do this if you’re using a strong, unique password—basic auth isn’t encrypted, so consider using HTTPS if you’re accessing over the internet (though wfsctl doesn’t support HTTPS natively, you can use a reverse proxy like nginx if needed).
- OS updates: macOS updates might overwrite the default wfsctl plist, but your custom plist in
/Library/LaunchDaemonswill stay intact. Just double-check the server is running after any major update.
内容的提问来源于stack exchange,提问作者marc-medley

