wip: docs(issues): design for unifying local auth (kanidm, FIDO2 PAM, Vaultwarden) #831
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "local-auth-unification"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Captures the design discussion as an issue in
issues/open/. Docs-only — no config changes.Position: unify the unlock (one hardware authenticator feeding kanidm, PAM/sudo and LUKS), not the storage. Machine secrets stay on sops-nix.
Records four concrete findings from surveying the repo and upstream:
mkForce falsefleet-wide over a uid-2001-vs-1000 collision — that's the real blocker.pam_u2f+systemd-cryptenroll.Follow-up work is sequenced as three independent PRs in the issue.
docs(issues): design for unifying local auth (kanidm, FIDO2 PAM, Vaultwarden)to wip: docs(issues): design for unifying local auth (kanidm, FIDO2 PAM, Vaultwarden)View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.