Forum Discussion
s3rj1k
2 years agoNew Contributor
Feature request: Integrate better with Systemd Credentials
As per https://systemd.io/CREDENTIALS/ the only way of using systemd credentials is via it's built in store, that is essentially a on-demand encrypted folder where each file in it has secret value.
...
s3rj1k
2 years agoNew Contributor
Eldan I use similar approach, still don't like it.
Even systemd-creds have issues, decrypted passwords files are accessible from current user.
Not sure even how to solve this one without native TPM decryption support from op
(op + TPM, in this case op could directly use local TPM provider to decrypt passwords from ENV)