You are not logged in.

#1 2020-01-16 12:13:16

ExaFusion
Member
Registered: 2020-01-16
Posts: 1

fscrypt decryption on ssh login using PAM

I've set up fscrypt following this thread https://wiki.archlinux.org/index.php/Fscrypt including the #Auto-unlocking_directories. Then I encrypted some folder in my home directory. Now my pam.d files are as follows:

/etc/pam.d/system-login

#%PAM-1.0

auth       required   pam_tally2.so        onerr=succeed file=/var/log/tallylog
auth       required   pam_shells.so
auth       requisite  pam_nologin.so
auth       include    system-auth
auth       optional   pam_fscrypt.so

account    required   pam_tally2.so
account    required   pam_access.so
account    required   pam_nologin.so
account    include    system-auth

password   include    system-auth

session    optional   pam_loginuid.so
session    optional   pam_keyinit.so       force revoke
session    include    system-auth
session    optional   pam_motd.so          motd=/etc/motd
session    optional   pam_mail.so          dir=/var/spool/mail standard quiet
-session   optional   pam_systemd.so
session    required   pam_env.so
session    optional   pam_fscrypt.so       drop_caches lock_policies

/etc/pam.d/passwd

#%PAM-1.0
#password	required	pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3
#password	required	pam_unix.so sha512 shadow use_authtok
password	required	pam_unix.so sha512 shadow nullok
password        optional        pam_fscrypt.so

I'm running kernel 5.4 that I heard brought some changes in how fscrypt works. However I'm having the same issues also using linux-its kernel.

$ uname -a
Linux ARCH 5.4.11-arch1-1 #1 SMP PREEMPT Sun, 12 Jan 2020 12:15:27 +0000 x86_64 GNU/Linux

Problem 1:
I've added pam_fscrypt to system-login, not system-local-login, therefore I was expecting to auto-decrypt also when I perform a remote login. I also try tried to run

su $(whoami) -c exit

as suggested in https://github.com/google/fscrypt/blob/master/README.md but even that do not unlock the directories. Is there a way to enable auto-decrypt also when I log via SSH?


Problem 2:
Apparently folders do not get re-encrypted until reboot. If I login as root the folders are encrypted as I would expect them to be. However, if I first login with my user account, then logout and finally login with root, folders are decrypted for root as well. Is there a way to fix this behaviour?

Last edited by ExaFusion (2020-01-16 21:36:36)

Offline

#2 2020-01-23 04:39:47

Synchronicity
Member
Registered: 2020-01-23
Posts: 3

Re: fscrypt decryption on ssh login using PAM

(1): I think this is the problem that a fix was just merged for, so please update to the latest version of the fscrypt-git AUR package.  However, for now you also have to change your /etc/fscrypt.conf to get the new behavior.  See https://github.com/google/fscrypt#cant- … s-unlocked.

(2): pam_fscrypt is *supposed* to lock your login-passphrase protected directories when you log out.  But there are two known bugs, one where a systemd bug causes the PAM "close session" hooks to not be fully run, and one where home directories can't be fully locked because some files are still in-use (which is probably not an fscrypt bug either, but I need to figure out what's causing it).  For now though, if you really want to lock your directories you can manually run  'fscrypt lock'.

If you have any more questions about fscrypt, please ask at https://github.com/google/fscrypt/issues.  I just found this forum thread by chance.

Offline

Board footer

Powered by FluxBB