Skip to content

Commit

Permalink
add notice about root-owned secrets
Browse files Browse the repository at this point in the history
  • Loading branch information
ryantm committed Dec 18, 2020
1 parent 0650e51 commit fbd9e29
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,10 @@ All files in the Nix store are readable by any system user, so it is not a suita
* Very little code, so it should be easy for you to audit
* Encrypted secrets are stored in the Nix store, so a separate distribution mechanism is not necessary

## Notices

* If you want to manage user's hashed passwords, you must use a version of NixOS with [commit e6b8587](https://github.com/NixOS/nixpkgs/commit/e6b8587b25a19528695c5c270e6ff1c209705c31), so the root-owned secrets can be decrypted before the user activation script runs. Currently only available on `unstable`.

## Installation

Choose one of the following methods:
Expand Down

0 comments on commit fbd9e29

Please sign in to comment.