Gentoo Archives: gentoo-user

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: tmp on tmpfs
Date: Thu, 25 May 2017 06:34:24
Message-Id: 3294A185-6D02-49E3-B477-68FA53555898@antarean.org
In Reply to: Re: [gentoo-user] Re: tmp on tmpfs by Rich Freeman
1 It is possible. I have it set up like that on my laptop.
2 Apart from a small /boot partition. The whole drive is encrypted.
3 Decryption keys are stored encrypted in the initramfs, which is embedded in the kernel.
4
5 --
6 Joost
7
8 On May 25, 2017 12:40:12 AM GMT+02:00, Rich Freeman <rich0@g.o> wrote:
9 >On Wed, May 24, 2017 at 2:16 PM, Andrew Savchenko <bircoph@g.o>
10 >wrote:
11 >>
12 >> Apparently it is pointless to encrypt swap if unencrypted
13 >> hibernation image is used, because all memory is accessible through
14 >> that image (and even if it is deleted later, it can be restored
15 >> from hdd and in some cases from ssd).
16 >>
17 >
18 >Yeah, that was my main concern with an approach like that. I imagine
19 >you could use a non-random key and enter it on each boot and restore
20 >from the encrypted swap, though I haven't actually used hibernation on
21 >linux so I'd have to look into how to make that work. I imagine with
22 >an initramfs it should be possible.
23 >
24 >--
25 >Rich
26
27 --
28 Sent from my Android device with K-9 Mail. Please excuse my brevity.

Replies

Subject Author
[gentoo-user] Re: tmp on tmpfs Kai Krakow <hurikhan77@×××××.com>