docs: add fallback keyring-disable steps for when apt purge isn't enough
D-Bus service activation can respawn gnome-keyring-daemon even after the package is removed and PAM/autostart hooks are disabled. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -81,6 +81,43 @@ Reboot to confirm the popup no longer appears.
|
|||||||
|
|
||||||
> Trade-off: Chrome saved passwords/cookie encryption falls back to its weaker "Basic" store, and NetworkManager Wi-Fi passwords may need to be re-entered once. If a future setup needs the keyring kept, unlock it silently instead by opening **Passwords and Keys** (`seahorse`) → right-click **Login** → **Change Password** → set both new-password fields blank.
|
> Trade-off: Chrome saved passwords/cookie encryption falls back to its weaker "Basic" store, and NetworkManager Wi-Fi passwords may need to be re-entered once. If a future setup needs the keyring kept, unlock it silently instead by opening **Passwords and Keys** (`seahorse`) → right-click **Login** → **Change Password** → set both new-password fields blank.
|
||||||
|
|
||||||
|
#### If the popup (or a "choose a new password for keyring" prompt) still appears after a reboot
|
||||||
|
|
||||||
|
The `apt purge` above removes the package, but if something reinstalls `gnome-keyring`/`libpam-gnome-keyring` as a dependency later (e.g. installing another desktop app), it comes back. Deleting just the keyring files under `~/.local/share/keyrings/` doesn't fix it either — a new keyring gets created on the next login/app request and prompts for a password again.
|
||||||
|
|
||||||
|
Do this instead, which disables it at every level (PAM login hook, session autostart, and D-Bus on-demand activation) without needing to uninstall the package:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
# 1. Disable PAM hooks (login + password-sync)
|
||||||
|
sudo sed -i \
|
||||||
|
-e 's/^-auth optional pam_gnome_keyring.so/#-auth optional pam_gnome_keyring.so/' \
|
||||||
|
-e 's/^-session optional pam_gnome_keyring.so auto_start/#-session optional pam_gnome_keyring.so auto_start/' \
|
||||||
|
/etc/pam.d/sddm
|
||||||
|
sudo sed -i 's/^password\toptional\tpam_gnome_keyring.so/#&/' /etc/pam.d/common-password
|
||||||
|
|
||||||
|
# 2. Stop the keyring daemon components from autostarting in the session
|
||||||
|
mkdir -p ~/.config/autostart
|
||||||
|
for f in gnome-keyring-pkcs11 gnome-keyring-secrets gnome-keyring-ssh; do
|
||||||
|
cp /etc/xdg/autostart/$f.desktop ~/.config/autostart/$f.desktop 2>/dev/null
|
||||||
|
echo "Hidden=true" >> ~/.config/autostart/$f.desktop
|
||||||
|
done
|
||||||
|
|
||||||
|
# 3. Mask D-Bus service activation (the part that keeps bringing it back —
|
||||||
|
# any app calling the Secret Service API, e.g. Chrome, spawns the daemon
|
||||||
|
# on demand even with PAM and autostart disabled)
|
||||||
|
sudo mkdir -p /usr/share/dbus-1/services-disabled
|
||||||
|
sudo mv /usr/share/dbus-1/services/org.freedesktop.secrets.service \
|
||||||
|
/usr/share/dbus-1/services/org.gnome.keyring.service \
|
||||||
|
/usr/share/dbus-1/services/org.freedesktop.impl.portal.Secret.service \
|
||||||
|
/usr/share/dbus-1/services-disabled/ 2>/dev/null
|
||||||
|
|
||||||
|
# 4. Kill the running daemon and clear existing keyring files
|
||||||
|
pkill -f gnome-keyring-daemon
|
||||||
|
rm -f ~/.local/share/keyrings/*
|
||||||
|
```
|
||||||
|
|
||||||
|
Reboot to confirm. Same trade-off as above: Chrome falls back to storing saved passwords unencrypted rather than via the Secret Service.
|
||||||
|
|
||||||
### Step 2 — Install Git
|
### Step 2 — Install Git
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
|
|||||||
Reference in New Issue
Block a user