Re: [systemd-devel] Why are journal files stored in machine-specific directories?

2022-05-26 Thread Mantas Mikulėnas
On Thu, May 26, 2022, 16:27 Jakub Piecuch wrote: > Hello, > > I'm wondering why journald stores journal files under > /var/log/journal/$MACHINE_ID instead of just /var/log/journal. > It allows logs from remote systems to be collected using ordinary rsync or NFS or other file-based tools.

[systemd-devel] Why are journal files stored in machine-specific directories?

2022-05-26 Thread Jakub Piecuch
Hello, I'm wondering why journald stores journal files under /var/log/journal/$MACHINE_ID instead of just /var/log/journal. I found the commit that introduces this change, but it contains no justification: https://github.com/systemd/systemd/commit/ed49ef3f349bcd4f0483ba8254a2537fe8e9cd17 I also

[systemd-devel] v251 cryptsetup & FIDO2

2022-05-26 Thread Riccardo Paolo Bestetti
Hi, I just switched from using a custom glue script to systemd for FIDO2 local drive unlocking. From my own experimenting in v251, it seems to me that the following usability issues are present in my setup (Arch Linux, no PIN, user presence required): - When key is not inserted at boot time,

Re: [systemd-devel] certificate and trust store feature for systemd

2022-05-26 Thread Petr Menšík
Don't we have ansible on modern systems to be managed like that? I doubt we want API to manage keys for specific applications. Sure, we may have simplify creation of self-signed certificates with key pair. We may standardize generation of certificate request with a key, but I doubt we want

Re: [systemd-devel] certificate and trust store feature for systemd

2022-05-26 Thread Thomas Haller
On Thu, 2022-05-26 at 12:42 +0300, Mantas Mikulėnas wrote: > On Wed, May 25, 2022 at 4:28 PM SCOTT FIELDS > wrote: > > I apologize for the very general inquiry. > >   > > Are there any plans to have system natively support its own trust > > store for items like CAs, x509 certs, passwords &

Re: [systemd-devel] certificate and trust store feature for systemd

2022-05-26 Thread Mantas Mikulėnas
On Wed, May 25, 2022 at 4:28 PM SCOTT FIELDS wrote: > I apologize for the very general inquiry. > > > > Are there any plans to have system natively support its own trust store > for items like CAs, x509 certs, passwords & truststores akin to the > keychain in Windows and OS X? > > > > I still