Platforms / Linux

KalderaShield on Linux

Linux x64 ships in two shapes: a .deb package for Debian, Ubuntu and their derivatives, and an AppImage that runs on almost any distribution without installation.

What you get

Package manager or single file

The .deb package installs through dpkg or your distribution's software center, lands in the applications menu and can be removed through the normal package tools. The AppImage is one executable file: chmod +x and run, nothing else touched on the system.

Both carry the same application and the same security design: per-record AES-256-GCM encryption, Argon2id key derivation and the air-gap network policy. Vault files and encrypted backups move freely between the two and between Linux machines.

The Linux build uses the GTK3/WebKitGTK windowing stack that Tauri targets. That stack currently carries upstream unmaintained-binding advisories (documented in the dependency advisory register with the acceptance rationale) — they are ecosystem maintenance risks, not known exploitable paths in KalderaShield code.

Getting started on Linux

Download and verify

Fetch the .deb or AppImage from the download page and compare its SHA-256 hash with SHA256SUMS.txt before installing or running it.

Create the vault

Choose the master password and store the 24-word BIP-39 recovery key outside the application. Argon2id parameters are recorded in the vault itself.

Install the browser extension

The Chromium and Firefox extension builds live next to the desktop artifacts. Desktop pairing runs over a loopback-only IPC bridge with a pairing token.

Security Architecture

Linux specifics you should know

Signatures and the GTK3 stack

Linux has no mandatory Authenticode-style signing, so verification is hash-based: always check the SHA-256 checksums published with the release. The updater bundles are minisign-signed regardless. The dependency advisory register lists every accepted advisory with its reason, and accepts none that is reachable from the vault, crypto or IPC trust boundaries.

.deb

Debian-based systems

Installs with dpkg/apt and integrates with the applications menu; removed with the package manager like any other software.

AppImage

Distribution-neutral

A single executable for almost any x64 distribution. No root, no install step, deletable like a document.

WebKitGTK

Windowing stack

The upstream Tauri default on Linux. Its unmaintained GTK3-binding advisories are documented and accepted with rationale, re-evaluated on every Tauri update.

Frequently Asked Questions

Linux questions

AppImage or .deb — which should I use?

Use .deb on Debian, Ubuntu, Mint and derivatives for menu integration and clean removal. Use the AppImage anywhere else, or when you want a zero-footprint install.

Does the Linux version have every desktop feature?

Yes, minus platform-specific conveniences that have no Linux equivalent, such as Windows Hello or Touch ID. Hardware-wrapped unlock is available through PRF-capable FIDO2 security keys instead.

Can I use the same vault on Linux and Windows?

Yes. Encrypted backups are portable across all desktop platforms. Create the backup on one machine and restore it with the master password on the other.

Related pages

Download Installer