Hm, interesting, #fedora seems to be moving to full-disk-encryption using #btrfs and #fscrypt by default, along with signing unified kernel images (UKIs) and using the #TPM. No measuring/attestation AFAICT yet, but a very good move forward!
They also want to separately encrypt homes, and even mention #systemd #homed in the Pagure:
https://pagure.io/fedora-workstation/blob/master/f/notes/encryption.md
However they write:
> *It cannot be universal for all Fedora systems - some things like NFS home directories are out of scope for systemd-homed. Logging in remotely via ssh is not supported. (???)*
I'm pretty sure ssh is supported and even documented, and #NFS should be of no business to homed? But NFS+automount should work perfectly fine with #homed, or did I misunderstand something?
Maybe someone with more knowledge than me should chip in, otherwise they will re-invent the wheel (and doing separately encrypted homes is hard to do correctly!)
#fedora #btrfs #fscrypt #tpm #systemd #homed #nfs
Looking for fellow #earlyyears educator, people interested in #play and #PlayBased #authentic learning. Looking for those in #NurseryEducation and people working with #under5s and #families. Also #homeeducation and #neuro #neurodiversity as I’m a mum of two #homed kids who are both #neurodiverse! Full time head with children #homeeducated passionate about education that is #purposeful, #authentic and meaningful! Let’s connect!
#earlyyears #play #playbased #authentic #nurseryeducation #under5s #families #homeeducation #neuro #neurodiversity #homed #neurodiverse #homeeducated #purposeful
So today with #systemd-homed I got a "state dirty" with Input output error, after a system crash.
I dont know if #homed runs fsck from time to time on the container.
Thanks to https://bbs.archlinux.org/viewtopic.php?pid=1920540#p1920540
I could set it up and run fsck manually.
`homectl fsck` would be a welcome cmd
Oh my focking god ! La pile de merde #systemd n'a décidément pas de fond, voici le petit dernier, j'ai nommé #HomeD 😡
https://www.techrepublic.com/article/linux-home-directory-management-is-about-to-undergo-major-change/
Le truc est déjà en statut RC2, et on note : "You can be sure that Poettering will come up with a solution that takes SSH into consideration. "
Autrement dit ça marche pas à ce jour.
Mais Ouate. De. Phoque.
FOSDEM: Systemd und die Neuerfindung der Home-Verzeichnisse | heise online
https://www.heise.de/newsticker/meldung/FOSDEM-Systemd-und-die-Neuerfindung-der-Home-Verzeichnisse-4651663.html
#systemd #homed #verschlüsselung #linux #experimental
#systemd #homed #verschlüsselung #linux #experimental