Gentoo Archives: gentoo-user

From: Hans <linux@××××××××××××××.au>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: Full system encryption on Gentoo
Date: Wed, 30 Dec 2015 21:45:50
Message-Id: n61j9q$9ot$1@ger.gmane.org
In Reply to: [gentoo-user] Re: Full system encryption on Gentoo by Roman Dobosz
1 I can't follow Sakaki's_EFI_Install_Guide. The system will run in
2 VirtualBox and only have BIOS. No UEFI, EFI, USB stick as boot or key disk.
3
4 OpenSuse 42.1 boots from a encrypted single LVM volume on a MSDOS drive,
5 single partition, using grub2 as boot manager, and systemd.
6
7 I just have to find a way to get the same result using Gentoo with
8 OpenRC and if possible without LVM. Entering the pass phrase several
9 times is no problem.
10
11 Hans
12
13
14 On 31/12/15 03:53, Roman Dobosz wrote:
15 > On Wed, 30 Dec 2015 07:34:52 +1000
16 > Hans <linux@××××××××××××××.au> wrote:
17 >
18 >> Is it possible to fully encrypt a Gentoo system as can be done with
19 >> Fedora, Suse, Arch Linux, Debian and Ubunto without using a unencrypted
20 >> USB boot stick or unencrypted /boot partition?
21 >>
22 >> If yes, where can I find instructions that really work on a BIOS only
23 >> box without UEFI, EFI, systemd using EXT4 file system?
24 >
25 > It's definitely possible - for both usb stick or ordinary boot
26 > partition, although it's not quite the same as in distros you've
27 > mentioned, since it require either custom made initramfs or some
28 > utility which would made one for you (like dracut, genkernel etc).
29 >
30 > There is several guides which might be useful, just google for one.
31 > It doesn't have to be gentoo specific, since the install procedure is
32 > almost the same, the only difference is the choice of medium for
33 > booting up the encrypted system, bootloader and fstab configuration,
34 > partition layout (with/without lvm) and so on. One of teh most
35 > comprehensive guide about the topic is the Sakaki's EFI Install
36 > Guide [1]. Yeah, I know there is "EFI" word, but it doesn't matter -
37 > you can just skip the part with efi partition and make your own
38 > pendrive (using syslinux) or create unencrypted boot partition :)
39 >
40 > [1] https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide
41 >

Replies

Subject Author
[gentoo-user] Re: Full system encryption on Gentoo Jeremi Piotrowski <jeremi.piotrowski@×××××.com>