4 ms·
There's a not-widely-publicized feature of Linux that allows programs to store secrets directly in the kernel: https://www.kernel.org/doc/Documentation/security
by phunge 12y ago
There's a not-widely-publicized feature of Linux that allows programs to store secrets directly in the kernel: https://www.kernel.org/doc/Documentation/security/keys.txt https://www.kernel.org/doc/Documentation/security/keys.txt That has some advantages, including the guarantee that it can't be swapped to disk. Kerberos can use it for secret storage, I haven't seen it used elsewhere though.
It looks like process-private storage is one of its features.
- jjmason 12y agoI haven't looked to hard at the docs yet, but this seems kind of awesome. Is it something that you have to build your own kernel for, or is it configurable in a prebuilt kernel?
- jbert 12y agoStock ubuntu here has a /proc/keys file, so I think it's generally available.
- falcolas 12y agoIt seems like the security for that keyring is based on uid, which can cause problems in the world of containers. https://news.ycombinator.com/item?id=8321210 https://news.ycombinator.com/item?id=8321210
- olefoo 12y agoThe main drawback of this ( and it's a minor drawback in the larger scheme of things ) is that this isn't a portable interface and isn't available on other POSIX-ish OS's. It looks like there are key agents available for Freebsd, OS X and Illumos though. Thanks for pointing this out.