Re: /home on luks-encrypted usb-stick

Markus Mandalka <[email protected]> Sun, 06 Jan 2008 09:38:10 +0100
Newsgroups gmane.linux.morphix.devel
Message-ID <[email protected]>
Hello,

Thanks for your fast answer.

The skripts now are working in my morphix-based distri and will be
testet by others in the next days.

When the scripts are supporting not only english but german too and i
have worked on some optical stuff i'll upload them to a webserver and
will send a announcement to this list.

While developing i found some little problems or have still some questions:

1.) luks is working if the kernel supports cryptsetup/luks
(devicemappers, aes256 and so on...).

This works great with the kernel of basemod-2.6.17-2007-10-24_0014.iso.

But my favorite (more and newer drivers)
basemod-2.6.23-2008-01-03_0018.iso is not able to do a cryptsetup (tool
from in the package cryptsetup which contains commandline-tools and
initskripts for encryption-things) luksFormat or luksOpen.

I don't know if this kernel doesn't contain support for aes256 or
devicemappers or the modules are not loaded or if the kernel is not
compatible.

If you do not know without looking for that what is going on and you
should need more info, please write and i will do some additional checks.

This things are not only usefull for encrypted homes for morphix but for
rescue cd's too, because with debian etch and now with the new ubuntu
users are able to encrypt their systems with luks without enhanced
knowledge.

2.) Because of using luks for my not important: I had no time to check
much more or to check if the problem was in front of my computer and not
in the morphixkernel, but i think in both basemods the support for
loop-aes is broken, which would be neccecary to let the
standard-morphix-persistant-home-image working, if it is aes-encrypted
(for example knoppix asks if you want to encrypt an image while you
create one).

3.) Is it a bug, a feature or well thought special stuff avoiding
problems because beeing a livesystem, that the init-system of the
morphix-live-cd-system is not starting all this runlevels and
initscripts like a "normal debian" does?

So is it the right way to start all needed services like for example
dbus with an "/etc/init.d/dbus start" in an own startskript in
/morphix/rc.m/S0xYZ or is my developmentplattform broken or did i forgot
to switch into the right runlevel and all services from the used debian
packages should start themselves using the standard init-system while
booting the cd?

4.) If using the package morphix-init-light (xfce4 as gui) and not
"logging out" but exiting xfce with "reboot" or "halt" the system is not
running the skripts
/morphix/rc.m/S90X11-shutdown and S99exitshell because it seems directly
switch to runlevel 0 or 6.

So i am starting the stop-skript for my luks-encrypted-home at
/etc/rc0.d and /etc/rc6.d and not as /morhix/rc.m/S90crypthome_stop,
because so it is called on every scenario how to halt or reboot.

Is this the right way or is there a better "standardway" in morphix?

Greetings,
Markus

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/