Skip to main content

Using KeePassXC as the Secret Service

KeePassXC_Project keepassxreboot/keepassxc

Installation

sudo apt install keepassxc

Create a D-Bus Service That Implements the Secret Service API

mkdir -p "$HOME/.local/share/dbus-1/services"
tee "$HOME/.local/share/dbus-1/services/org.freedesktop.secrets.service" >/dev/null <<'EOF'
[D-BUS Service]
Name=org.freedesktop.secrets
Exec=/usr/bin/keepassxc
EOF

Disable the GNOME Keyring Daemon Service

systemctl --user mask gnome-keyring-daemon.socket
systemctl --user mask gnome-keyring-daemon.service 
sudo systemctl mask gnome-keyring-daemon.socket
sudo systemctl mask gnome-keyring-daemon.service
mkdir -p "$HOME/.config/autostart/"
cp "/etc/xdg/autostart/gnome-keyring-pkcs11.desktop" "$HOME/.config/autostart/"
cp "/etc/xdg/autostart/gnome-keyring-secrets.desktop" "$HOME/.config/autostart/"
cp "/etc/xdg/autostart/gnome-keyring-ssh.desktop" "$HOME/.config/autostart/"
echo "Hidden=true" >> "$HOME/.config/autostart/gnome-keyring-pkcs11.desktop"
echo "Hidden=true" >> "$HOME/.config/autostart/gnome-keyring-secrets.desktop"
echo "Hidden=true" >> "$HOME/.config/autostart/gnome-keyring-ssh.desktop"

Until an appropriate solution is found, resort to removing "executable" permission from gnome-keyring-daemon.

sudo chmod -x /usr/bin/gnome-keyring-daemon
sudo tee "/etc/apt/apt.conf.d/99-disable-gnome-keyring-daemon" >/dev/null <<'EOF'
DPkg::Post-Invoke {
    "if [ -e /usr/bin/gnome-keyring-daemon ]; then chmod -x /usr/bin/gnome-keyring-daemon; fi";
};
EOF

Unset GNOME Keyring as the Chromium Password Store

sudo tee --append "/etc/chromium.d/default-flags" >/dev/null <<'EOF'

# Disable GNOME keyring as password store (using keepassxc)
export CHROMIUM_FLAGS="$CHROMIUM_FLAGS --password-store=basic"
EOF

Configuration

    General
      Basic Settings
        Startup
           Start only a single instance of KeePassXC  Automatically launch KeePassXC at system startup  Minimize window at application startup  Minimize window after unlocking database  Remember previously used databases
             Load previously open databases on startup  Remember database key files and security dongles

            Unlocking the Keyring Automatically

            Create a KeePassXC Database Protected by Keyfile

            mkdir -p --mode=700 "$HOME/.secrets/databases"
            mkdir -p --mode=700 "$HOME/.secrets/private"
            keepassxc-cli db-create --decryption-time 1000 --set-key-file "$HOME/.secrets/private/SecretService.keyx" "$HOME/.secrets/databases/SecretService.kdbx"
            
            Encrypt the Keyfile Using the TPM2-Sealed Key
            sudo systemd-creds encrypt --name=KeePassXC-SecretService --with-key=tpm2 "$HOME/.secrets/SecretService.keyx" "$HOME/.secrets/SecretService.creds"
            sudo chown $USER:$USER "$HOME/.secrets/SecretService.creds"
            sudo chmod 0400 "$HOME/.secrets/SecretService.creds"
            

            Ensure you have a backup copy of the keyfile stored securely before shredding it — there is no recovery option if the TPM-sealed key becomes unusable (e.g. due to a firmware update).

            shred "$HOME/.secrets/SecretService.keyx"
            

            Authorize Credentials Decryption Using the TPM2-Sealed Key

            sudo tee "/etc/polkit-1/rules.d/49-systemd-creds.rules" >/dev/null <<'EOF'
            polkit.addRule(function(action, subject) {
                if (action.id == "io.systemd.credentials.decrypt" &&
                    subject.local == true && subject.active == true &&
                    subject.isInGroup ("tss")) {
                        return polkit.Result.YES;
                }
            });
            EOF
            
            sudo gpasswd --add <username> tss
            

            Set Up Automatic Unlock on Login

            sudo wget --quiet -O "/usr/local/libexec/keepassxc-watch.sh" "https://kb.havlas.me/attachments/16"
            sudo chown root:root "/usr/local/libexec/keepassxc-watch.sh"
            sudo chmod 0755 "/usr/local/libexec/keepassxc-watch.sh"
            
            sudo tee "/etc/systemd/user/keepassxc-watch@.service" >/dev/null <<'EOF'
            [Unit]
            Description=Auto-unlock KeePassXC database '%i' via TPM2-sealed key
            After=graphical-session.target
            ConditionPathExists=%h/.secrets/%i.kdbx
            ConditionPathExists=%h/.secrets/%i.creds
            
            [Service]
            ExecStart=/usr/local/libexec/keepassxc-watch.sh %i
            Restart=on-failure
            RestartSec=2
            
            [Install]
            WantedBy=graphical-session.target
            EOF
            
            sudo chown root:root "/etc/systemd/user/keepassxc-watch@.service"
            sudo chmod 0644 "/etc/systemd/user/keepassxc-watch@.service"
            sudo systemctl daemon-reload
            
            systemctl --user enable --now keepassxc-watch@SecretService.service