Re: Are the keys of mounted encrypted disks secured during reboot?

John Smith <[email protected]>
Newsgroups dev.linux.lists.cryptsetup
Message-ID <CA+5JoNp5PF+43AqbYHnjern792b=LYJtAEheFynEU8mRmw0Vxw@mail.gmail.com>
I'm asking about when a regular shutdown/reboot/suspend-to-disk is
issued. In most cases the rootfs volume is not unmounted because that
would require a pivot_root to a special initrd/ramdisk-rootfs just for
powering off.
So that would mean the device isn't deactivated via cryptsetup -
because that would fail.
In that case, when the kernel is preparing to reboot/poweroff, will it
wipe the keys or just leave them there vulnerable to cold boot or
forensics?

On Mon, Dec 26, 2022 at 7:42 PM Milan Broz <[email protected]> wrote:
>
> On 12/26/22 20:13, John Smith wrote:
> > During the course of proper shutdown/reboot/suspend-to-disk, does the
> > kernel securely erase (or at least free memory of - as it pertains to
> > init_on_free=1) encryption keys of all dmcrypt/luks systems which
> > remained mounted?
>
> If the device is properly deactivated, then keys are always wiped.
>
> (Actually, with LUKS2, dm-crypt no longer keeps own copy of the key, it
> is stored in kernel keyring only for activation and then, obviously, in kernel
> crypto where is is directly used for encryption. So if it is not
> deactivated, it is responsibility of these subsystems to wipe it on reboot.)
>
> For suspend to ram, it is more complicated - there is a way how to wipe key
> and freeze device temporarily (see luksSuspend), but I do no think many systems
> actually use it. Debian has cryptsetup-suspend that can do this AFAIK.
>
> For suspend to disk, the memory should be written to encrypted device.
> (And RAM contents disappears after some short time with no power anyway.)
>
> Milan
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.