I have some things working
done
encrypted root
personal vault
todo
fix numlock light
librem key
yubikey
smartcard encryrypted root or tpm
smartcard gdm/sddm
smartcard pam
tpm unlock luks2 root
secure boot it turned on which boots signed fedora kernels. tpm is used to unlock the root partition. since my uefi setup is password protected and the tpm shouldn't allow anyone access to the private key used for unlocking i am reasonably safe from attack but not completely.
fedora and ubuntu (debian etc) linux uses a ram filesystem with the krnel (initrd) to boot. the initrd is customized for the local system and cannot be signed with factory shipped (microsoft) keys for secure boot. an attacker could replace the initrd on my machine if they get physical access.
sudo systemd-cryptenroll --tpm2-device=auto /dev/sdXn
sudo dracut --force /boot/initramfs-$(uname -r).img $(uname -r)
ls -lh /boot/initramfs-*.img
sudo grubby --info=$(grubby --default-kernel) | grep -q "rd.luks.options=tpm2-device=auto" || sudo grubby --update-kernel=$(grubby --default-kernel) --args="rd.luks.options=tpm2-device=auto"
lsinitrd /boot/initramfs-$(uname -r).img | grep -i tpm
pin login
I'd like to use the tpm to login to reduce dependence on the smartkey but it's experimental. ai found this
Method 1: The Modern Way (pinpam & pinutil)An open-source PAM framework called pinpam
For now Im in a hurry so I'll keep doing it with sssd
sssd setup for librem smartcart
install packages
sudo dnf install sssd-tools pcsc-lite pcsc-lite-ccid opensc pcsc-tools p11-kit
next create sssd config
sudo tee /etc/sssd/sssd.conf <<EOF
[sssd]
services = nss, pam
domains = local
[pam]
pam_cert_auth = True
[domain/local]
id_provider = proxy
proxy_lib_name = files
auth_provider = proxy
proxy_pam_target = sssd-shadowutils
access_provider = permit
EOF
# Set required strict permissions
sudo chmod 600 /etc/sssd/sssd.conf
sudo chown root:root /etc/sssd/sssd.conf
sudo restorecon -v /etc/sssd/sssd.conf
# Restart the service to apply changes
sudo systemctl restart sssd
sudo chown -R sssd:sssd /var/log/sssd/
sudo chmod 750 /var/log/sssd/
sudo systemctl enable --now pcscd
pkcs11-tool --list-slots
pkcs11-tool --list-objects --login
pkcs11-tool --login --read-object --type cert --id 03 -o librem_auth.der
#that is not working. try generating a cert but none of it works. It all comes down to not being able to extract th public key from the smartcard. will get that and keep going later
yubikey
sudo dnf install pam-u2f pamu2fcfg yubikey-manager
i want a pin prompt
ykman fido access change-pin
mkdir -p ~/.config/Yubico
pamu2fcfg --pin-verification > ~/.config/Yubico/u2f_keys
the yubi key i have is a fido2 device but missing features I want for other places.