mirror of
https://github.com/anotherhadi/nixy.git
synced 2026-08-22 19:15:48 +02:00
Autologin, unlock the keyring with the luks password
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
This commit is contained in:
@@ -9,6 +9,7 @@
|
|||||||
../../nixos/nix.nix
|
../../nixos/nix.nix
|
||||||
../../nixos/systemd-boot.nix
|
../../nixos/systemd-boot.nix
|
||||||
../../nixos/tuigreet.nix
|
../../nixos/tuigreet.nix
|
||||||
|
../../nixos/autologin.nix # Skip first TUIGreet login, use LUKS password to unlock the keyring
|
||||||
../../nixos/users.nix
|
../../nixos/users.nix
|
||||||
../../nixos/utils.nix
|
../../nixos/utils.nix
|
||||||
../../nixos/hyprland.nix
|
../../nixos/hyprland.nix
|
||||||
|
|||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# Autologin at boot: greetd starts your session directly on the first VT
|
||||||
|
{
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
...
|
||||||
|
}: {
|
||||||
|
services.greetd.settings.initial_session = {
|
||||||
|
command = "${pkgs.uwsm}/bin/uwsm start -e -D Hyprland hyprland.desktop";
|
||||||
|
user = config.var.username;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Needed so the LUKS passphrase entered at boot is cached in the kernel
|
||||||
|
# keyring, where pam_fde_boot_pw can retrieve it (see below).
|
||||||
|
boot.initrd.systemd.enable = true;
|
||||||
|
|
||||||
|
security.pam.services.greetd.rules.session.fde_boot_pw = {
|
||||||
|
order = 12550; # kwallet=12500, gnome_keyring=12600: must run in between
|
||||||
|
control = "optional";
|
||||||
|
modulePath = "${pkgs.pam_fde_boot_pw}/lib/security/pam_fde_boot_pw.so";
|
||||||
|
args = ["inject_for=gkr"];
|
||||||
|
};
|
||||||
|
|
||||||
|
security.pam.services.login.enableGnomeKeyring = true;
|
||||||
|
|
||||||
|
systemd.services.greetd.serviceConfig.KeyringMode = lib.mkForce "shared";
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user