Re: FAQ 2.2 Scenario (1) - clarification concerning "encrypted root"

[email protected]
Newsgroups gmane.linux.kernel.device-mapper.dm-crypt
Message-ID <[email protected]>
Thanks a lot for the clarification!

On 20.06.20 08:10, Arno Wagner wrote:
> I have a scenario: Put the initrd on USB-stick, remove it after
> boot and secure the USB-stick physically (safe) when not in use.
> I actually did that set-up for somebody. This is not perfect either, 
> but makes attacks that rely on manipulating the disk directly a lot 
> harder.
You mean because the initrd is somewhat safe from manipulation in this
scenario? Wouldn't you have to do the same for the kernel then?

> But what do you use to unlock it? Something needs to run 
> cryptsetup for that unlocking action.

The Arch way seems to be to do this via the initrd which in a "default"
setup resides on a dedicated /boot. I figure that might be good enough
for me then.

Best Wishes


_______________________________________________
dm-crypt mailing list
[email protected]
https://www.saout.de/mailman/listinfo/dm-crypt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.