TPM-backed GNOME keyring unlock
Packages for tpm-keyring-unlock: a PAM module that hands a
TPM-sealed copy of the GNOME keyring password to pam_gnome_keyring at login,
so the login keyring unlocks even when the login itself was by fingerprint -
without blanking the keyring password.
The secret is sealed to the machine's own TPM under a PCR7 (Secure Boot)
policy. Installing a package only places files: run
tpm-keyring-unlock-configure afterwards to seal a password and wire up PAM.
Neither step happens behind the package manager's back.
Source, documentation and issue tracker:
https://github.com/dmitriitimoshenko/tpm-keyring-unlock
Refresh
| Name | Changed |
|---|
Comments 0