new keys you add to factotum don’t get added to factotum i’m afraid.
there is a script ipso(1) which wraps up the operations you need to manage factotum keys, and it supports secstore, and using an encrypted local file. NB: you might want to chmod -t your lical file to prevent it going into your disc archive (venti/getfs/cwfs etc). though putting a!copy (encrypted) on a thumb drive every so often is a good policy. -Steve > On 2 Oct 2026, at 12:17 am, requiem. via 9fans <[email protected]> wrote: > On Wed, 30 Sep 2026 09:27:10 -0400 > Dan Cross <[email protected]> wrote: > >> An additional resource you didn't mention explicitly, but that may >> help your mental model, is the paper, "Security in Plan 9" by Cox, >> Grosse, and Pike. https://9p.io/sys/doc/auth.html > > Amazing, thank you, I will add this to the reading list! >>> - Without turning the laptop into a cpu/auth server, how do I >>> set up secstored? Where is it best invoked when the system boots, >>> and how do I make sure it is reachable on tcp!127.0.0.1!5356 ? >> >> I think that running `secstored` on your laptop, just to protect your >> WiFi password, is a bit overkill. There is an `aescbc` command that >> can be used for encrypting locally stored files; you could put your >> WiFi password into a text file, encrypt it with some password/phrase >> of your choosing, and decrypt/cat it into factotum when you startup >> your laptop. Of course, you'd have to enter the password manually, and >> the file is potentially vulnerable to offline dictionary attacks, >> depending on the strength of the password you choose, but its probably >> fine against all but state-level actors. I wrote a little program I >> called "micro-secstore" to do just this back in the early 2000s; it >> was just a wrapper around `aescbc` that used a provided a slightly >> more convenient interface. > > Thank you very for the pointer to it. > > I did figure this out meanwhile. > > Although I had little luck with IPV4, I realised that IPV6 comes to the > rescue in this situation. I simply set secstored to listen on the > default IPV6 address for the machine that was available in > /net/ipselftab on boot without any other connections. This way I could > get factotum to work on its own. > > So I added: > secstore=tcp!fe80::a9e:1ff:fe34:c497!5356 > to plan9.ini, > > And then, after the usual secstore setup (creating dirs in /adm, > installing a secstore user, etc) in termrc I added: > auth/secstored -s $secstore > as well as adding 'secstored' to the final 'dontkill' command at the > end. (I am not quite sure I need to do this but looked like a good > idea?) > > I still have to feed keys manually into factotum with `auth/secstore -G > factotum` but I can now automate that at boottime or before rc starts. > > What I don't know tho -- if I subsequently add new keys to factotum with > "echo ... > /mnt/factotum/ctl", how do those make it back into secstore > this way? > >> One could imagine trying to leverage a TPM or something as a secure >> enclave to hold secrets for boot, but as far as I know that >> infrastructure doesn't exist, and again, the simplest route is >> probably just to locally encrypt a text file. > > Thank you -- I think there were suggestions of using cryptsetup > partitions and thumbdrives in the earlier thread; or I suppoes a > yubikey or similar could also be a solution. But this is "good enough" > for me at the moment. > >> ------------------------------------------ >> 9fans: 9fans >> Permalink: >> https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M41c312165ae32e0fb18469ab >> Delivery options: https://9fans.topicbox.com/groups/9fans/subscription ------------------------------------------ 9fans: 9fans Permalink: https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-Maf345b687c5dcb0ff82734b9 Delivery options: https://9fans.topicbox.com/groups/9fans/subscription
