new keys you add to factotum don’t get added to factotum i’m afraid.

there is a script ipso(1) which wraps up the operations you need to manage 
factotum keys, and it supports secstore, and using an encrypted local file.

NB: you might want to chmod -t your lical file to prevent it going into your 
disc archive (venti/getfs/cwfs etc). though putting a!copy (encrypted) on a 
thumb drive every so often is a good policy.

-Steve

> On 2 Oct 2026, at 12:17 am, requiem. via 9fans <[email protected]> wrote:
> On Wed, 30 Sep 2026 09:27:10 -0400
> Dan Cross <[email protected]> wrote:
> 
>> An additional resource you didn't mention explicitly, but that may
>> help your mental model, is the paper, "Security in Plan 9" by Cox,
>> Grosse, and Pike. https://9p.io/sys/doc/auth.html
> 
> Amazing, thank you, I will add this to the reading list!
>>> - Without turning the laptop into a cpu/auth server, how do I
>>>  set up secstored? Where is it best invoked when the system boots,
>>> and how do I make sure it is reachable on tcp!127.0.0.1!5356 ?  
>> 
>> I think that running `secstored` on your laptop, just to protect your
>> WiFi password, is a bit overkill.  There is an `aescbc` command that
>> can be used for encrypting locally stored files; you could put your
>> WiFi password into a text file, encrypt it with some password/phrase
>> of your choosing, and decrypt/cat it into factotum when you startup
>> your laptop. Of course, you'd have to enter the password manually, and
>> the file is potentially vulnerable to offline dictionary attacks,
>> depending on the strength of the password you choose, but its probably
>> fine against all but state-level actors. I wrote a little program I
>> called "micro-secstore" to do just this back in the early 2000s; it
>> was just a wrapper around `aescbc` that used a provided a slightly
>> more convenient interface.
> 
> Thank you very for the pointer to it.
> 
> I did figure this out meanwhile.
> 
> Although I had little luck with IPV4, I realised that IPV6 comes to the
> rescue in this situation. I simply set secstored to listen on the
> default IPV6 address for the machine that was available in
> /net/ipselftab on boot without any other connections. This way I could
> get factotum to work on its own.
> 
> So I added:
>        secstore=tcp!fe80::a9e:1ff:fe34:c497!5356
> to plan9.ini,
> 
> And then, after the usual secstore setup (creating dirs in /adm,
> installing a secstore user, etc) in termrc I added:
>        auth/secstored -s $secstore
> as well as adding 'secstored' to the final 'dontkill' command at the
> end. (I am not quite sure I need to do this but looked like a good
> idea?)
> 
> I still have to feed keys manually into factotum with `auth/secstore -G
> factotum` but I can now automate that at boottime or before rc starts.
> 
> What I don't know tho -- if I subsequently add new keys to factotum with
> "echo ... > /mnt/factotum/ctl", how do those make it back into secstore
> this way?
> 
>> One could imagine trying to leverage a TPM or something as a secure
>> enclave to hold secrets for boot, but as far as I know that
>> infrastructure doesn't exist, and again, the simplest route is
>> probably just to locally encrypt a text file.
> 
> Thank you -- I think there were suggestions of using cryptsetup
> partitions and thumbdrives in the earlier thread; or I suppoes a
> yubikey or similar could also be a solution. But this is "good enough"
> for me at the moment.
> 
>> ------------------------------------------
>> 9fans: 9fans
>> Permalink:
>> https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M41c312165ae32e0fb18469ab
>> Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

------------------------------------------
9fans: 9fans
Permalink: 
https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-Maf345b687c5dcb0ff82734b9
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

Reply via email to