Skip to main content

Using KeePassXC as the Secret Service

KeePassXC_Project keepassxreboot/keepassxc

Installation

sudo apt install keepassxc

Create a D-Bus Service That Implements the Secret Service API

mkdir -p "$HOME/.local/share/dbus-1/services"
tee "$HOME/.local/share/dbus-1/services/org.freedesktop.secrets.service" >/dev/null <<'EOF'
[D-BUS Service]
Name=org.freedesktop.secrets
Exec=/usr/bin/keepassxc
EOF

Disable the GNOME Keyring Daemon Service

systemctl --user mask gnome-keyring-daemon.socket
systemctl --user mask gnome-keyring-daemon.service 
sudo systemctl mask gnome-keyring-daemon.socket
sudo systemctl mask gnome-keyring-daemon.service
mkdir -p "$HOME/.config/autostart/"
cp "/etc/xdg/autostart/gnome-keyring-pkcs11.desktop" "$HOME/.config/autostart/"
cp "/etc/xdg/autostart/gnome-keyring-secrets.desktop" "$HOME/.config/autostart/"
cp "/etc/xdg/autostart/gnome-keyring-ssh.desktop" "$HOME/.config/autostart/"
echo "Hidden=true" >> "$HOME/.config/autostart/gnome-keyring-pkcs11.desktop"
echo "Hidden=true" >> "$HOME/.config/autostart/gnome-keyring-secrets.desktop"
echo "Hidden=true" >> "$HOME/.config/autostart/gnome-keyring-ssh.desktop"

Until an appropriate solution is found, resort to removing "executable" permission from gnome-keyring-daemon.

sudo chmod -x /usr/bin/gnome-keyring-daemon
sudo tee "/etc/apt/apt.conf.d/99-disable-gnome-keyring-daemon" >/dev/null <<'EOF'
DPkg::Post-Invoke {
    "if [ -e /usr/bin/gnome-keyring-daemon ]; then chmod -x /usr/bin/gnome-keyring-daemon; fi";
};
EOF

Unset GNOME Keyring as the Chromium Password Store

sudo tee --append "/etc/chromium.d/default-flags" >/dev/null <<'EOF'

# Disable GNOME keyring as password store (using keepassxc)
export CHROMIUM_FLAGS="$CHROMIUM_FLAGS --password-store=basic"
EOF

Configuration

  • General
    • Basic Settings
      • Startup
        • Start only a single instance of KeePassXC
        • Automatically launch KeePassXC at system startup
        • Minimize window at application startup
        • Minimize window after unlocking database
        • Remember previously used databases
          • Load previously open databases on startup
          • Remember database key files and security dongles

Unlocking the Keyring Automatically

Create a KeePassXC Database Protected by Keyfile

mkdir -p --mode=700 "$HOME/.secrets/databases"
mkdir -p --mode=700 "$HOME/.secrets/private"
keepassxc-cli db-create --decryption-time 1000 --set-key-file "$HOME/.secrets/private/SecretService.keyx" "$HOME/.secrets/databases/SecretService.kdbx"
Encrypt the Keyfile Using the TPM2-Sealed Key
sudo systemd-creds encrypt --name=KeePassXC-SecretService --with-key=tpm2 "$HOME/.secrets/SecretService.keyx" "$HOME/.secrets/SecretService.creds"
sudo chown $USER:$USER "$HOME/.secrets/SecretService.creds"
sudo chmod 0400 "$HOME/.secrets/SecretService.creds"

Ensure you have a backup copy of the keyfile stored securely before shredding it — there is no recovery option if the TPM-sealed key becomes unusable (e.g. due to a firmware update).

shred "$HOME/.secrets/SecretService.keyx"

Authorize Credentials Decryption Using the TPM2-Sealed Key

sudo tee "/etc/polkit-1/rules.d/49-systemd-creds.rules" >/dev/null <<'EOF'
polkit.addRule(function(action, subject) {
    if (action.id == "io.systemd.credentials.decrypt" &&
        subject.local == true && subject.active == true &&
        subject.isInGroup ("tss")) {
            return polkit.Result.YES;
    }
});
EOF
sudo gpasswd --add <username> tss

Set Up Automatic Unlock on Login

sudo wget --quiet -O "/usr/local/libexec/keepassxc-watch.sh" "https://kb.havlas.me/attachments/16"
sudo chown root:root "/usr/local/libexec/keepassxc-watch.sh"
sudo chmod 0755 "/usr/local/libexec/keepassxc-watch.sh"
sudo tee "/etc/systemd/user/keepassxc-watch@.service" >/dev/null <<'EOF'
[Unit]
Description=Auto-unlock KeePassXC database '%i' via TPM2-sealed key
After=graphical-session.target
ConditionPathExists=%h/.secrets/%i.kdbx
ConditionPathExists=%h/.secrets/%i.creds

[Service]
ExecStart=/usr/local/libexec/keepassxc-watch.sh %i
Restart=on-failure
RestartSec=2

[Install]
WantedBy=graphical-session.target
EOF
sudo chown root:root "/etc/systemd/user/keepassxc-watch@.service"
sudo chmod 0644 "/etc/systemd/user/keepassxc-watch@.service"
sudo systemctl daemon-reload
systemctl --user enable --now keepassxc-watch@SecretService.service
SSH Keys
sudo apt install seahorse
sudo mkdir -p /usr/libexec/ssh
sudo ln -s seahorse/ssh-askpass /usr/libexec/ssh/ssh-askpass