PAM lines written into login and passwd as blocks, so login unlocks the keyring on both workstations; no daemon of its own; gcr's ssh agent named for the session until the environment can say a runtime-directory path. Go tools unlocked, lock, collections and ssh-keys, never reading a secret.
77 lines
2.2 KiB
JSON
77 lines
2.2 KiB
JSON
{
|
|
"module": "gnome-keyring",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"package-manager"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-secret-service",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"tools": [
|
|
"gnome_keyring_unlocked",
|
|
"gnome_keyring_lock",
|
|
"gnome_keyring_collections",
|
|
"gnome_keyring_ssh_keys"
|
|
],
|
|
"shell": [
|
|
{
|
|
"for": "xinitrc",
|
|
"slot": "first",
|
|
"code": "# The ssh agent (module gnome-keyring, novox/hq ADR 0208): gcr's, which the account's service manager\n# starts on first use from its socket. Named here, for the session and every terminal it starts, until\n# the account's environment can say a path under the runtime directory (see the module's README).\nSSH_AUTH_SOCK=\"${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/gcr/ssh\"\nexport SSH_AUTH_SOCK\n"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "gnome-keyring"
|
|
},
|
|
{
|
|
"id": "library",
|
|
"type": "package",
|
|
"package": "libsecret"
|
|
},
|
|
{
|
|
"id": "manager",
|
|
"type": "package",
|
|
"package": "seahorse"
|
|
},
|
|
{
|
|
"id": "pam-login",
|
|
"type": "file",
|
|
"path": "/etc/pam.d/login",
|
|
"mode": "0644",
|
|
"into": "block",
|
|
"at": "end",
|
|
"content": "# The login keyring (module gnome-keyring, novox/hq ADR 0208, ADR 0102): the password typed at the\n# login screen unlocks the keyring, and the login session starts the keyring daemon with it.\nauth optional pam_gnome_keyring.so\nsession optional pam_gnome_keyring.so auto_start\n"
|
|
},
|
|
{
|
|
"id": "pam-passwd",
|
|
"type": "file",
|
|
"path": "/etc/pam.d/passwd",
|
|
"mode": "0644",
|
|
"into": "block",
|
|
"at": "end",
|
|
"content": "# The login keyring (module gnome-keyring, novox/hq ADR 0208, ADR 0102): changing the account's\n# password changes the login keyring's with it, so the next login still unlocks it.\npassword optional pam_gnome_keyring.so\n"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/gnome-keyring-tools",
|
|
"binary": "gnome-keyring-tools",
|
|
"loads": [
|
|
"gnome-keyring-tools"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|