2 ms·
Interesting. I'm surprised I haven't read more about the Linux kernel keyring infrastructure. Are you sure that portable openssh ssh-agent doesn't implement acc
by drvdevd 10y ago
Interesting. I'm surprised I haven't read more about the Linux kernel keyring infrastructure. Are you sure that portable openssh ssh-agent doesn't implement access to it?
- sandGorgon 10y agoin a few distros, they hack it together using "ssh agent" . You can read about it here - https://wiki.gnome.org/Projects/GnomeKeyring/Ssh https://wiki.gnome.org/Projects/GnomeKeyring/Ssh AFAIK - its the same story on OSX. I dont begrudge openssh - I'm not sure how it would work with multiple systems, but I dont know if it was ever a priority. But in this day and age of a "reloaded" Lavabit... these are infrastructure decisions that must be solved ! Interestingly, for all the hate that Lennart gets, he refused to implement "systemd-keyring" and suggested people should use the kernel level keyring service that already exists [1]. You can test it out using "keyctl". Remember however, that IMHO kernel keys do not persist across powercycles.. There is some kind of funky interplay between ecryptfs, kernel keyring and gnome-keyring that I dont completely understand (and is the basis of encrypted home directory in Linux) [1] https://lists.freedesktop.org/archives/systemd-devel/2014-June/020638.html https://lists.freedesktop.org/archives/systemd-devel/2014-Ju...