apt install libengine-pkcs11-openssl gnutls-bin opensc-pkcs11 scdaemon opensc libpam-p11 libpam-u2f pamu2fcfg ssh
install the packages
kwallet password set to empty string
setup libpam-p11 and/or fido2
configure luks2 unlock with tpm/smartcard
install tarsnap for backups
A note about kwallet. I don't want it. I don't use it and it won't go away. In the past--with varying degrees of success--I have:
disabled in system settings
deleted files from random locations based on web searches
set specific commands in files
set a blank password after every password reset
Here are some specifics
rm ~/.local/share/kwalletd/kdewallet.kwl
It should be trivial to connect the tpm to the current encrypted looks root volume but it depends greatly on what boot process your distro is using.
Kubuntu 26.04 is not using systemd in boot which is fine because i have my own utility to add support for tpm2 to initramfs-tools. After I install the deb I built I enroll the tpm for my luks2 volume. Then I rebuild the initrd. Since I have my own utility installed the initrd rebuild adds the tpm2 support.
sudo apt install luks-root-smartcard-tools
dev=/dev/nvmen1p7
sudo systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=7 $dev
sudo update-initramfs -u -k "$(uname -r)"
Unfortunately, the initrd is NOT protected by 99% of the Linux distros out there. The only systems that tackle this issue are PureOS and the heads project--both of which require specific hardware. This leaves the rest of us unprotected.
some of my systems have an older tpm and systemd wont use it. this method gives me the same
I have a ppa with packages for this
https://launchpad.net/~jtmoree/+archive/ubuntu/security-tools
My custom unlock processes leverages luks2, gpg, smartcards, systemd tokens, and initramfs to unlock during boot without requring systemd in the boot process.
gpg keyfile and luks2 gpg token
tpm systemd token
systemd-pkcs11
systemd-fido2
I hope to get ubuntu to accept my packages since debian is moving to dracut and ubuntu is not ready for that.
I could not get dracut to work with this. That may have to be done later.
PAM handles most of the work for sudo.
deb
I have had success using libpam-poldi and libpam-p11 with the smart card. libpam-p11 works better but is a little more technical to setup. I have not been able to get everything working with poldi.
rpm
different packages are required on fedora.
sudo dnf install sssd opensc pcsc-lite pcsc-lite-ccid
When gnome and KDE need to elevate privileges they prompt the user for a password. This seems to be running a sudo based or equivalent process. This should detect that a smartcard is available and prompt for the PIN instead of the password.
This did not work in pureos 9 (whereas most other stuff did) but does work for most of the modern setups I try.
This can be configured similar to the p11/poldi sudo setup. Once pam is using the smartcard for common auth the console inherits the prompts.
pam can enable multi factor authentication for login. In this case you are forced to enter the password and have the smartcard and PIN.
Generally works with sddm after setting up common auth with smartcard. Hopefully PLM inherits the functionality.
Though it is useful to protect the private key with the smartcard I'm already using encrypted partitions for storing keys. Using the smartcard with SSH does not bring much value to me. It would add an extra layer of protection in the case of a system compromise but not much. maybe I'll do it at some point.
apt install openssh
dnf install openssh-server
Some of the smart cards have password manager features. I have not been able to get this to work with mine and so I use a password vault with the data stored in a LUKS volume.
Documented Challenges with setting numlock ON by default.