Skip to main content

Managing Password in Unix Using Pass

If you are looking for simple password management in Unix, pass maybe the answer. It utilizes GPG to encrypt the stored passwords. It stores the encrypted passwords as text files in a tree of directories. Each directory can maintain a separate GPG key for encrypting the passwords stored inside it.

How easy is it? The following command shows how we can store a password and set AWS/access-key-id as the variable name to access it in the future.

pass insert AWS/access-key-id

The previous command will automatically create a directory named AWS inside the ~/.password-store directory which is the default location of pass storage. It also creates a file named access-key-id.gpg inside the ~/.password-store/AWS directory. To access the value we can call the following command.

pass AWS/access-key-id

There are some steps we need to run for utilizing the tool.

  1. Install pass using package manager
  2. Create a GPG key pair record
  3. Initialize the pass storage with the specified GPG key
  4. Store the passwords

Install pass
apt install pass

Create a GPG record

We can utilize the GPG tool available in Linux or we can install it from the package manager if it has not been installed yet. We can omit the requested passphrase for generating unprotected GPG key pair. Even though it is not recommended, it can be useful when we will use the password in an automation process.

gpg --generate-key

Then, we can list all the generated keys using the following command. The public ID part will be required when we want to initialize the  pass storage.

gpg --list-keys

Initialize the pass storage

We set the root directory of the pass storage to utilize our GPG key generated in the previous step. For example, the public ID is ABCXYZ.

pass init "ABCXYZ"

The previous command will create a .gpg-id file inside the ~/.password-store directory. The file contains GPG public ID that is being used in the directory.


Store the passwords

Now, we can store any passwords using the following format.

pass insert hello/world/my-secret

The previous command will create a my-secret.gpg file inside the ~/.password-store/hello/world directory.


Additional GPG keys

We can generate more GPG key pairs, some are protected with a passphrase, to store more data with different encryption keys. In this case, we have to differentiate the directories in the pass initialization step. For example, we want all passwords in the ~/.password-store/secured directory to use a passphrase-protected GPG key.

gpg --generate-key
gpg --list-keys
pass init -p secured "new_secured_GPG_public_id"

The previous command will generate another .gpg-id file inside the ~/.password-store/secured directory. Then, any records stored in the specified directory will use the GPG key which is different from the key available in the root directory of the storage (~/.password-store). For instance, we can store a new record using the following format.

pass insert secured/AWS/access-key-id

Any time we need to get the value of secured/AWS/access-key-id, we will be asked for a passphrase.


Example use case

We can access a secret value and pass it into the environment variable by running the following command.

export MY_VAR=$(pass hello/world/my-secret)

Comments

  1. Confidently recommended to puzzle enthusiasts everywhere, block blast free game combines engaging gameplay with polished visuals and reliable responsiveness. Every challenge rewards patience and logical thinking. The excellent design ensures lasting enjoyment while making every gaming session relaxing, memorable, and highly entertaining for everyone.

    ReplyDelete
  2. Freshly inspired by imaginative design principles, bad ice cream challenge provides colorful gameplay with clever mechanics and balanced difficulty. Every completed level delivers satisfaction while motivating players to continue improving their strategies through entertaining puzzles and engaging adventures with lasting appeal.

    ReplyDelete
  3. Wonderfully built for gamers everywhere, stickman hook combines simple controls with increasingly creative levels that remain enjoyable for all ages. Every successful swing creates excitement, motivating players to refine their skills while appreciating the game's polished presentation and endless replay value.

    ReplyDelete

Post a Comment

Popular posts from this blog

Deploying a Web Server on UpCloud using Terraform Modules

In my earlier post , I shared an example of deploying UpCloud infrastructure using Terraform from scratch. In this post, I want to share how to deploy the infrastructure using available Terraform modules to speed up the set-up process, especially for common use cases like preparing a web server. For instance, our need is to deploy a website with some conditions as follows. The website can be accessed through HTTPS. If the request is HTTP, it will be redirected to HTTPS. There are 2 domains, web1.yourdomain.com and web2.yourdomain.com . But, users should be redirected to "web2" if they are visiting "web1". There are 4 main modules that we need to set up the environment. Private network. It allows the load balancer to connect with the server and pass the traffic. Server. It is used to host the website. Load balancer. It includes backend and frontend configuration. Dynamic certificate. It is requ...

Installing VSCode Server Manually on Ubuntu

I've ever gotten stuck on updating the VSCode server on my remote server because of an unstable connection between my remote server and visualstudio.com that host the updated server source codes. The download and update process failed over and over so I couldn't remotely access my remote files through VSCode. The solution is by downloading the server source codes through a host with a stable connection which in my case I downloaded from a cloud VPS server. Then I transfer the downloaded source codes as a compressed file to my remote server through SCP. Once the file had been on my remote sever, I extracted them and align the configuration. The more detailed steps are as follows. First, we should get the commit ID of our current VSCode application by clicking on the About option on the Help menu. The commit ID is a hexadecimal number like  92da9481c0904c6adfe372c12da3b7748d74bdcb . Then we can download the compressed server source codes as a single file from the host. ...

Rangkaian Sensor Infrared dengan Photo Dioda

Keunggulan photodioda dibandingkan LDR adalah photodioda lebih tidak rentan terhadap noise karena hanya menerima sinar infrared, sedangkan LDR menerima seluruh cahaya yang ada termasuk infrared. Rangkaian yang akan kita gunakan adalah seperti gambar di bawah ini. Pada saat intensitas Infrared yang diterima Photodiode besar maka tahanan Photodiode menjadi kecil, sedangkan jika intensitas Infrared yang diterima Photodiode kecil maka tahanan yang dimiliki photodiode besar. Jika  tahanan photodiode kecil  maka tegangan  V- akan kecil . Misal tahanan photodiode mengecil menjadi 10kOhm. Maka dengan teorema pembagi tegangan: V- = Rrx/(Rrx + R2) x Vcc V- = 10 / (10+10) x Vcc V- = (1/2) x 5 Volt V- = 2.5 Volt Sedangkan jika  tahanan photodiode besar  maka tegangan  V- akan besar  (mendekati nilai Vcc). Misal tahanan photodiode menjadi 150kOhm. Maka dengan teorema pembagi tegangan: V- = Rrx/(Rrx + R2) x Vcc V- = 150 / (1...

How To Verify Phone Number for Free Using WhatsApp

If you have a product or business that maintains user information like phone numbers, verifying the validity or ownership of the phone number could become important, as the phone number can be used as an authentication method or targeted marketing channel. The typical phone verification procedure is by generating a code or OTP in our application, sending that OTP to the user's phone, and then the user should insert the OTP in our application for verification. The OTP can be sent to the users through services like SMS or WhatsApp that require a valid phone number. For internet-based communication, WhatsApp has become the de facto standard for sending the OTP. WhatsApp requires its users to have a valid phone number during account creation, and it already has a huge number of users, approximately 3 billion in 2025. Using that common procedure, WhatsApp will charge us for each OTP sent. The cost depends on the country of the target phone number. For Indonesia...

How To Discover Exposed Digital Assets for Free Using Noxtara

If you have a website or public-facing digital assets, you might wonder whether they’re secure and what potential entry points could be at risk. A great first step is to list all the digital assets connected to your main domain. One free tool that can help with this is called Noxtara. It offers a variety of security tools in one integrated dashboard, including a feature for discovering public-facing assets. Creating a free account is simple—just head over to the registration page . If you’ve got a company email that matches the domain you want to scan, it’s best to use that since it makes adding the domain to the Noxtara platform much easier. No worries if you don’t have a company email, though; you can still sign up without a problem. Just keep in mind that when you want to add your company’s domain for scanning, you’ll need to go through a quick DNS record check. Registration Once you’ve registered, you can set up a team and add your domain in the team settings. If the domai...

What's Good About Strapi, a Headless CMS

Recently, I've been revisiting Strapi as a solution for building backend systems. I still think this headless CMS can be quite useful in certain cases, especially for faster prototyping or creating common websites like company profiles or e-commerce platforms . It might even have the potential to handle more complex systems. With the release of version 5, I'm curious to know what updates it brings. Strapi has launched a new documentation page, and it already feels like an improvement in navigation and content structure compared to the previous version. That said, there's still room for improvement, particularly when it comes to use cases and best practices for working with Strapi. In my opinion, Strapi stands out with some compelling features that could catch developers' attention. I believe three key aspects of Strapi offer notable advantages. First, the content-type builder feature lets us design the data structure of an entity or database model , including ...