You are not logged in.
Pages: 1
I've set up fscrypt following this thread https://wiki.archlinux.org/index.php/Fscrypt including the #Auto-unlocking_directories. Then I encrypted some folder in my home directory. Now my pam.d files are as follows:
/etc/pam.d/system-login
#%PAM-1.0
auth required pam_tally2.so onerr=succeed file=/var/log/tallylog
auth required pam_shells.so
auth requisite pam_nologin.so
auth include system-auth
auth optional pam_fscrypt.so
account required pam_tally2.so
account required pam_access.so
account required pam_nologin.so
account include system-auth
password include system-auth
session optional pam_loginuid.so
session optional pam_keyinit.so force revoke
session include system-auth
session optional pam_motd.so motd=/etc/motd
session optional pam_mail.so dir=/var/spool/mail standard quiet
-session optional pam_systemd.so
session required pam_env.so
session optional pam_fscrypt.so drop_caches lock_policies/etc/pam.d/passwd
#%PAM-1.0
#password required pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3
#password required pam_unix.so sha512 shadow use_authtok
password required pam_unix.so sha512 shadow nullok
password optional pam_fscrypt.soI'm running kernel 5.4 that I heard brought some changes in how fscrypt works. However I'm having the same issues also using linux-its kernel.
$ uname -a
Linux ARCH 5.4.11-arch1-1 #1 SMP PREEMPT Sun, 12 Jan 2020 12:15:27 +0000 x86_64 GNU/LinuxProblem 1:
I've added pam_fscrypt to system-login, not system-local-login, therefore I was expecting to auto-decrypt also when I perform a remote login. I also try tried to run
su $(whoami) -c exitas suggested in https://github.com/google/fscrypt/blob/master/README.md but even that do not unlock the directories. Is there a way to enable auto-decrypt also when I log via SSH?
Problem 2:
Apparently folders do not get re-encrypted until reboot. If I login as root the folders are encrypted as I would expect them to be. However, if I first login with my user account, then logout and finally login with root, folders are decrypted for root as well. Is there a way to fix this behaviour?
Last edited by ExaFusion (2020-01-16 21:36:36)
Offline
(1): I think this is the problem that a fix was just merged for, so please update to the latest version of the fscrypt-git AUR package. However, for now you also have to change your /etc/fscrypt.conf to get the new behavior. See https://github.com/google/fscrypt#cant- … s-unlocked.
(2): pam_fscrypt is *supposed* to lock your login-passphrase protected directories when you log out. But there are two known bugs, one where a systemd bug causes the PAM "close session" hooks to not be fully run, and one where home directories can't be fully locked because some files are still in-use (which is probably not an fscrypt bug either, but I need to figure out what's causing it). For now though, if you really want to lock your directories you can manually run 'fscrypt lock'.
If you have any more questions about fscrypt, please ask at https://github.com/google/fscrypt/issues. I just found this forum thread by chance.
Offline
Pages: 1