Gentoo Archives: gentoo-user

From: Neil Bothwick <neil@××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Full system encryption on Gentoo
Date: Sat, 02 Jan 2016 12:47:55
Message-Id: 43A739BB-546A-4D7D-B5E6-EC64F2FACA60@digimed.co.uk
In Reply to: Re: [gentoo-user] Full system encryption on Gentoo by Frank Steinmetzger
1 On 2 January 2016 12:01:08 GMT+00:00, Frank Steinmetzger <Warp_7@×××.de> wrote:
2 > On Wed, Dec 30, 2015 at 08:22:22PM -0500, Alex Corkwell wrote:
3 > > On Wed, Dec 30, 2015 at 07:34:52AM +1000, Hans wrote:
4 > > > Hi,
5 > > >
6 > > > Is it possible to fully encrypt a Gentoo system as can be done
7 > with
8 > > > Fedora, Suse, Arch Linux, Debian and Ubunto without using a
9 > unencrypted
10 > > > USB boot stick or unencrypted /boot partition?
11 > > >
12 > > > If yes, where can I find instructions that really work on a BIOS
13 > only
14 > > > box without UEFI, EFI, systemd using EXT4 file system?
15 > > >
16 > > > Hans
17 > >
18 > > I can confirm that it's entirely possible, as I've managed to do it
19 > with
20 > > my laptop.
21 > > I don't remember exactly how I did everything, but here are the main
22 > > points of my setup.
23 > > […]
24 >
25 > Thank you very much for this documentation. I was about to start a
26 > thread
27 > with this topic myself because I’m in the market for a new laptop
28 > before too
29 > soon. But Hans beat me to it.
30 > Since I will install an after-market SSD in it, I want to encrypt
31 > everything. With a little luck, your information is all I need. I will
32 > practice it in a VM.
33 >
34 > @Neil:
35 > you seem to know your way around booting with EFI. I don’t suppose you
36 > could
37 > add your mustard (as we say here-abouts) regarding booting an
38 > encrypted
39 > system with an EFI bootloader. I was hoping to quicken my boot
40 > procedure
41 > because Grub seems slow to load and I find its UI to be not very
42 > responsive.
43 >
44 > Cheers
45 > --
46 > Gruß | Greetings | Qapla’
47 > Please do not share anything from, with or about me on any social
48 > network.
49 >
50 > You can’t fire me, slaves must be sold.
51
52 I use systemd's version of gummiboot with /boot on the ESP. Everything else is on a single btrfs filesystem, on a luks-encrypted partition and dracut takes care of everything. I don't have my laptop with me, but I'll post the dracut options I use later.
53 --
54 Sent from my Android phone with K-9 Mail. Please excuse my brevity.

Replies

Subject Author
Re: [gentoo-user] Full system encryption on Gentoo Neil Bothwick <neil@××××××××××.uk>