Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241822 > unrolled thread

mount.ecryptfs_private in .xsession with autologin

Started byLucio Crusca <lucio@sulweb.org>
First post2021-11-01 11:20 +0100
Last post2021-11-02 15:00 +0100
Articles 4 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  mount.ecryptfs_private in .xsession with autologin Lucio Crusca <lucio@sulweb.org> - 2021-11-01 11:20 +0100
    Re: mount.ecryptfs_private in .xsession with autologin Lucio Crusca <lucio@sulweb.org> - 2021-11-02 00:10 +0100
      Re: mount.ecryptfs_private in .xsession with autologin [SOLVED] Lucio Crusca <lucio@sulweb.org> - 2021-11-02 15:00 +0100
      Re: mount.ecryptfs_private in .xsession with autologin Curt <curty@free.fr> - 2021-11-02 15:00 +0100

#241822 — mount.ecryptfs_private in .xsession with autologin

FromLucio Crusca <lucio@sulweb.org>
Date2021-11-01 11:20 +0100
Subjectmount.ecryptfs_private in .xsession with autologin
Message-ID<DeCA1-3NX-1@gated-at.bofh.it>
Hello all,

this is a cross-post from serverfault.com, where I got no asnwers nor 
comments, so if you are interested in the bounty I set there you can 
answer there (too): https://serverfault.com/q/1082119/264847

I'm trying to decrypt the `Private` directory inside a user `$HOME` 
automatically at system startup. The system is a Debian GNU/Linux 10 
(actually a Raspbian, but I assume it's no different to this end) that 
uses NoDM [1] to start Xorg. It automatically logs the unprivileged user 
in and it runs the `$HOME/.xsession` startup script.

I have the following script, that is being called by .xsession:

     #!/bin/bash -x
     # Original by Michael Halcrow, IBM
     # Extracted to a stand-alone script by Dustin Kirkland
     # Edited on 2021-10-28 by Lucio Crusca

     export 
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
     PD="Private"
     WPF="$HOME/.ecryptfs/wrapped-passphrase"
     MPSF="$HOME/.ecryptfs/$PD.sig"

     if /sbin/mount.ecryptfs_private ; then
     	exit 0
     fi

     if [ -f "$WPF" -a -f "$MPSF" ]; then
     		if [ $(wc -l < "$MPSF") = "1" ]; then
     			if printf "%s\0" "$LP" | ecryptfs-unwrap-passphrase "$WPF" - | 
ecryptfs-add-passphrase -; then
     				echo Ok
     			else
     				echo incorrect LP
                     exit 1
     			fi
     		else
     			if printf "%s\0" "$LP" | 
ecryptfs-insert-wrapped-passphrase-into-keyring "$WPF" - ; then
     				echo Ok
     			else
     				echo incorrect LP
                     exit 1
     			fi
     		fi
     	/sbin/mount.ecryptfs_private
     else
     	echo Setup error
     	exit 1
     fi
     exit 0

It is a stripped down version of `/usr/bin/ecryptfs-mount-private`. It 
executes just the same commands, but it expects the LP environment 
variable to contain the passphrase instead of asking for the passphrase 
interactively.

I saved this script as `$HOME/el-mount.sh`. When my system boots and 
NoDM starts, it executes .xsession that in turn calls my script, 
redirecting `stdout` and `stderr` to a logfile for debug. The thing does 
not work, in that it outputs this:

     ...
     + /sbin/mount.ecryptfs_private
     mount: No such file or directory

However if I connect to the system via `ssh` and run the same 
`el-mount.sh` script, logged in as the same user configured in Nodm, the 
script flawlessy works. Just in case you wonder, the LP variable is 
correctly set in both cases (already checked in the logfile).

I've already tried switching from Nodm to lightdm-autologin-greeter [2], 
but I get just the same outcome.

How do I make `mount.ecryptfs_private` work when called during autologin?

   [1]: https://github.com/spanezz/nodm
   [2]: https://github.com/spanezz/lightdm-autologin-greeter

[toc] | [next] | [standalone]


#241831

FromLucio Crusca <lucio@sulweb.org>
Date2021-11-02 00:10 +0100
Message-ID<DeOBb-2Qf-7@gated-at.bofh.it>
In reply to#241822
On Nov 1, 2021 I wrote:
> (actually a Raspbian, but I assume it's no different 

I've now tried installing a clean Debian 11 with Nodm in a virtual 
machine and I face exactly the same problem, so we can safely exclude 
any Raspbian-specific problems.

[toc] | [prev] | [next] | [standalone]


#241839 — Re: mount.ecryptfs_private in .xsession with autologin [SOLVED]

FromLucio Crusca <lucio@sulweb.org>
Date2021-11-02 15:00 +0100
SubjectRe: mount.ecryptfs_private in .xsession with autologin [SOLVED]
Message-ID<Df2uu-2OV-1@gated-at.bofh.it>
In reply to#241831
I've finally sorted it out. The problem is Debian bug 870126.
Work around it by manually adding:

  session    optional   pam_keyinit.so force revoke

to /etc/pam.d/nodm

[toc] | [prev] | [next] | [standalone]


#241840

FromCurt <curty@free.fr>
Date2021-11-02 15:00 +0100
Message-ID<Df2uu-2OV-5@gated-at.bofh.it>
In reply to#241831
On 2021-11-01, Lucio Crusca <lucio@sulweb.org> wrote:
> On Nov 1, 2021 I wrote:
>> (actually a Raspbian, but I assume it's no different 
>
> I've now tried installing a clean Debian 11 with Nodm in a virtual 
> machine and I face exactly the same problem, so we can safely exclude 
> any Raspbian-specific problems.
>
>
>

Looks like you solved it in the end (and at the end):

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870126

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web