5 ms·
> With the advent of systemd-homed it might be desirable to convert an existing, traditional user account to a systemd-homed managed one. As someone unfamiliar
by WCSTombs 1y ago
> With the advent of systemd-homed it might be desirable to convert an existing, traditional user account to a systemd-homed managed one.
As someone unfamiliar with systemd-homed, I have a very basic question: why would someone want (or not want) to do this?
- ocdtrekkie 1y agoBased on... a web search: https://wiki.archlinux.org/title/Systemd-homed https://wiki.archlinux.org/title/Systemd-homed The big thing appears to be moving the user metadata into the home directory itself rather than it being around the system, and enabling home folder encryption, which has been like... a single button press feature on Windows since like Windows XP. Sounds like a step forward.
- yjftsjthsd-h 1y agoI'm slightly confused. I understand the appeal to putting user configuration inside the home directory, and I definitely approve of encrypting each home directory individually, but doesn't doing both of them together mean that you can't read the user data until it's been decrypted?
- 0xCMP 1y agoThe encrypted volume has an encrypted copy of the `~/.identity` file in it's metadata fields. The same key which encrypts the volume decrypts the metadata, but they use different IVs. You could assume that most systems the key would be secured with the TPM so this won't be much of a big deal to the user, but otherwise when they try to login it would prompt for this password first.
- throw0101d 1y ago> * I understand the appeal to putting user configuration inside the home directory* […] I'm not sure I understand the appeal. What does "putting user configuration inside the home directory" mean in this context? Is there a file with the UID, GIDs (primary, secondaries), GECOS, etc? What is put inside the homedir?
- bluGill 1y agoYou home dir including password is on a usb drive and so can move from machine to machine with all your files.
- JdeBP 1y agoA lot of JSON in a big file. * https://systemd.io/USER_RECORD/ https://systemd.io/USER_RECORD/ You'll enjoy the bit about the umask. Yes, this is short on details of where all of the privileged and secret stuff lives.