On Thu, Oct 1, 2026 at 7:18 PM requiem. via 9fans <[email protected]> wrote:
> On Wed, 30 Sep 2026 09:27:10 -0400
> Dan Cross <[email protected]> wrote:
>> [snip]
>
> I did figure this out meanwhile.
>
> Although I had little luck with IPV4, I realised that IPV6 comes to the
> rescue in this situation. I simply set secstored to listen on the
> default IPV6 address for the machine that was available in
> /net/ipselftab on boot without any other connections. This way I could
> get factotum to work on its own.
>
> So I added:
> secstore=tcp!fe80::a9e:1ff:fe34:c497!5356
> to plan9.ini,
So I'd be very careful with that. That is not an IPv6 loopback
address (the IPv6 loopback address is ::1), that is an IPv6 link-local
address, which is not routed, but _is_ visible on your local network.
It's probably not a big deal, but if you're running `secstored` on
that address, then anyone who's on the local network segment can try
and access your secstore.
> And then, after the usual secstore setup (creating dirs in /adm,
> installing a secstore user, etc) in termrc I added:
> auth/secstored -s $secstore
> as well as adding 'secstored' to the final 'dontkill' command at the
> end. (I am not quite sure I need to do this but looked like a good
> idea?)
Dunno. Can't hurt, I suppose.
> I still have to feed keys manually into factotum with `auth/secstore -G
> factotum` but I can now automate that at boottime or before rc starts.
>
> What I don't know tho -- if I subsequently add new keys to factotum with
> "echo ... > /mnt/factotum/ctl", how do those make it back into secstore
> this way?
You have to manually push them back to secstore. Steve mentioned this;
`ipso` is the way to go.
> > One could imagine trying to leverage a TPM or something as a secure
> > enclave to hold secrets for boot, but as far as I know that
> > infrastructure doesn't exist, and again, the simplest route is
> > probably just to locally encrypt a text file.
>
> Thank you -- I think there were suggestions of using cryptsetup
> partitions and thumbdrives in the earlier thread; or I suppoes a
> yubikey or similar could also be a solution. But this is "good enough"
> for me at the moment.
Yup; happy to help.
- Dan C.
------------------------------------------
9fans: 9fans
Permalink:
https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-Mec7927373217b39a9939f41c
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription