5 ms·
Yeah big nope on this. Needs to be separate, if it’s useful at all, not systemd “separate”. I don’t run systemd at all, to be safe.
by strawhatguy 1y ago
Yeah big nope on this. Needs to be separate, if it’s useful at all, not systemd “separate”.
I don’t run systemd at all, to be safe.
- aryonoco 1y agoStay safe! Meanwhile, I want to be able to mount my home directory on an external drive, and have it shared between systems without UID/GID hell. And, Have an encrypted home directory and boot the system and be able to enter my password with my keyboard which is connected to a thunderbolt dock during boot. Something which has been possible on Mac and windows for a decade or two. Systemd-homed is the ONLY way to achieve these (and many others) in Linux. Criticisms of systemd just because “it doesn’t smell like Unix” is all nice and fine, but ignores real quality of life and security features it provides. If you don’t have these usecases, you’re welcome to continue to ignore systemd, but some of us actually want these feature.
- msgodel 1y agoYou're comfortable sharing secret keys between systems?
- bombcar 1y agoThe keys would definitely be secreted hehehe
- yjftsjthsd-h 1y ago> Systemd-homed is the ONLY way to achieve these (and many others) in Linux. It absolutely is not. [Full] disk encryption has been fine for... at least 15 years, probably more. Sharing a home directory requires consistent UID/GID, but that's not hard even fully manually (which is fine if you're just one person).
- aryonoco 1y agoMaybe I wasn’t clear. Yes Linux has had FDE on for a long time, but with traditional FDE using LUKS etc, you cannot use accessories such as a thunderbolt keyboard during the boot process to enter the password to unlock the disk. Which is a problem if you’re like me and want to just connect your Linux laptop to a thunderbolt dock and use the keyboard attached to it. A problem which systemd-homed solves.
- yjftsjthsd-h 1y agoYou could have been a little clearer, but the main communication problem is that I didn't know that was a problem that could exist so it was easy to not follow. After a few minutes of confused web searching, I found https://fedoramagazine.org/thunderbolt-how-to-use-keyboard-during-boot-time/ https://fedoramagazine.org/thunderbolt-how-to-use-keyboard-d... which appears to describe the problem and some solutions (that don't involve homed, not least because this article predates it). AIUI, the problem is that you have to log in so you can approve the keyboard; that might be a pain point with an encrypted root (albeit it looks solvable), but if it works with homed I struggle to believe that it wouldn't work with any other encrypted home setup. Mostly because that part of homed is mostly a thin wrapper of code and convention over existing stuff.