fix(security): sync gnome login keyring password on passwd

Enable gnomeKeyring for the passwd PAM service so pam_gnome_keyring
updates the login keyring password when the login password changes.
Fixes 'Unlock Login Keyring' prompt desync after changing the password
via passwd (greetd session unlock alone does not update the keyring).
This commit is contained in:
Ryan Yin
2026-08-31 15:28:00 +08:00
parent 01622bf6d6
commit d0cd00069d
+14
View File
@@ -14,12 +14,26 @@
gcr-ssh-agent.enable = false; gcr-ssh-agent.enable = false;
}; };
# seahorse is a GUI App for GNOME Keyring. # seahorse is a GUI App for GNOME Keyring.
# Pitfall: never use seahorse's "New -> Default keyring". pam_gnome_keyring
# hardcodes the keyring name "login" (unlocks/syncs only login.keyring),
# while Secret Service apps (gh, browsers) use the keyring named in
# ~/.local/share/keyrings/default. Creating a separate "Default keyring"
# forks secrets into a second container whose password never syncs with the
# login password, causing "Unlock Login Keyring" prompt desyncs.
# Keep everything in "login" and leave the `default` pointer unset (or
# pointing at "login").
programs.seahorse.enable = true; programs.seahorse.enable = true;
# The OpenSSH agent remembers private keys for you # The OpenSSH agent remembers private keys for you
# so that you dont have to type in passphrases every time you make an SSH connection. # so that you dont have to type in passphrases every time you make an SSH connection.
# Use `ssh-add` to add a key to the agent. # Use `ssh-add` to add a key to the agent.
programs.ssh.startAgent = true; programs.ssh.startAgent = true;
security.pam.services.greetd.enableGnomeKeyring = true; security.pam.services.greetd.enableGnomeKeyring = true;
# Keep the login keyring password in sync with the login password when it is
# changed via `passwd`. Without this, pam_gnome_keyring only unlocks the
# keyring at login and a `passwd` change desyncs the two, causing
# "Unlock Login Keyring" prompt loops (and gh asking for a separate
# "keyring password").
security.pam.services.passwd.enableGnomeKeyring = true;
# gpg agent with pinentry # gpg agent with pinentry
programs.gnupg.agent = { programs.gnupg.agent = {