From 374f96399e7dba169c49c0507a7fa84e2125fbb7 Mon Sep 17 00:00:00 2001 From: Gitead Date: Mon, 17 Aug 2026 23:45:06 -0400 Subject: [PATCH] docs: add fallback keyring-disable steps for when apt purge isn't enough D-Bus service activation can respawn gnome-keyring-daemon even after the package is removed and PAM/autostart hooks are disabled. Co-Authored-By: Claude Sonnet 5 --- README.md | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/README.md b/README.md index 3e81bece..8efb1a51 100644 --- a/README.md +++ b/README.md @@ -81,6 +81,43 @@ Reboot to confirm the popup no longer appears. > Trade-off: Chrome saved passwords/cookie encryption falls back to its weaker "Basic" store, and NetworkManager Wi-Fi passwords may need to be re-entered once. If a future setup needs the keyring kept, unlock it silently instead by opening **Passwords and Keys** (`seahorse`) → right-click **Login** → **Change Password** → set both new-password fields blank. +#### If the popup (or a "choose a new password for keyring" prompt) still appears after a reboot + +The `apt purge` above removes the package, but if something reinstalls `gnome-keyring`/`libpam-gnome-keyring` as a dependency later (e.g. installing another desktop app), it comes back. Deleting just the keyring files under `~/.local/share/keyrings/` doesn't fix it either — a new keyring gets created on the next login/app request and prompts for a password again. + +Do this instead, which disables it at every level (PAM login hook, session autostart, and D-Bus on-demand activation) without needing to uninstall the package: + +```sh +# 1. Disable PAM hooks (login + password-sync) +sudo sed -i \ + -e 's/^-auth optional pam_gnome_keyring.so/#-auth optional pam_gnome_keyring.so/' \ + -e 's/^-session optional pam_gnome_keyring.so auto_start/#-session optional pam_gnome_keyring.so auto_start/' \ + /etc/pam.d/sddm +sudo sed -i 's/^password\toptional\tpam_gnome_keyring.so/#&/' /etc/pam.d/common-password + +# 2. Stop the keyring daemon components from autostarting in the session +mkdir -p ~/.config/autostart +for f in gnome-keyring-pkcs11 gnome-keyring-secrets gnome-keyring-ssh; do + cp /etc/xdg/autostart/$f.desktop ~/.config/autostart/$f.desktop 2>/dev/null + echo "Hidden=true" >> ~/.config/autostart/$f.desktop +done + +# 3. Mask D-Bus service activation (the part that keeps bringing it back — +# any app calling the Secret Service API, e.g. Chrome, spawns the daemon +# on demand even with PAM and autostart disabled) +sudo mkdir -p /usr/share/dbus-1/services-disabled +sudo mv /usr/share/dbus-1/services/org.freedesktop.secrets.service \ + /usr/share/dbus-1/services/org.gnome.keyring.service \ + /usr/share/dbus-1/services/org.freedesktop.impl.portal.Secret.service \ + /usr/share/dbus-1/services-disabled/ 2>/dev/null + +# 4. Kill the running daemon and clear existing keyring files +pkill -f gnome-keyring-daemon +rm -f ~/.local/share/keyrings/* +``` + +Reboot to confirm. Same trade-off as above: Chrome falls back to storing saved passwords unencrypted rather than via the Secret Service. + ### Step 2 — Install Git ```sh