1 |
On Sun, 30 Mar 2008 18:50:59 +0200, Dirk Heinrichs wrote: |
2 |
|
3 |
> > I use a variant of this, where keys are stored on a dedicated |
4 |
> > partition. The pre_mount and post_mount (which unmounts the |
5 |
> > filesystem) ensure that the keys are only visible for as long as it |
6 |
> > takes to mount the other filesystems. |
7 |
> |
8 |
> I protect the root fs with a passphrase and all other volumes with a |
9 |
> keyfile stored in this fs. No need to mount anything (however, I _do_ |
10 |
> need an initramfs because of this). |
11 |
|
12 |
That still means your keys are readable all the time, whereas mine |
13 |
disappear long before the network comes up. |
14 |
|
15 |
|
16 |
-- |
17 |
Neil Bothwick |
18 |
|
19 |
Remember, it takes 47 muscles to frown |
20 |
And only 4 to pull the trigger of a sniper rifle.... |