Gentoo Archives: gentoo-amd64

From: Neil Bothwick <neil@××××××××××.uk>
To: gentoo-amd64@l.g.o
Subject: Re: [gentoo-amd64] 2nd HDD for var, tmp, usr/portage, swap
Date: Fri, 20 Jul 2007 19:52:19
Message-Id: 20070720204900.0c2e42e7@krikkit.digimed.co.uk
In Reply to: Re: [gentoo-amd64] 2nd HDD for var, tmp, usr/portage, swap by Richard Freeman
1 Hello Richard Freeman,
2
3 > > Use cryptsetup-luks to set up encrypted swap partitions and
4 > > use /etc/conf.d/cryptfs to manage it. If you use a different key for
5 > > swap, there's no risk of it unlocking the wrong partition and
6 > > formatting it.
7
8 > Hmm - not ideal if you store the key in a config file. I just create a
9 > random key on each boot and it doesn't get recorded anywhere. As a
10 > result it isn't possible to tell if a given partition is a swap or
11 > random data upon the next boot. I could write something to the
12 > partition upon shutdown, but it won't help on an unclean boot and I'd
13 > rather not have to manually intervene anytime that happens...
14
15 I keep my keys on an encrypted partition, /etc/conf.d/cryptfs prompts for
16 the key for that partition at boot. Then the keys on that partition are
17 used to set up swap and /home before the partition is unmounted, so the
18 keys are only exposed for 2-3 seconds per boot.
19
20
21 --
22 Neil Bothwick
23
24 Fasten your seatbelt ... I wanna try something.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-amd64] 2nd HDD for var, tmp, usr/portage, swap Richard Freeman <rich@××××××××××××××.net>