Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #204790 > unrolled thread

trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

Started byAlbretch Mueller <lbrtchx@gmail.com>
First post2019-01-29 13:50 +0100
Last post2019-01-30 20:10 +0100
Articles 20 — 8 participants

Back to article view | Back to linux.debian.user


Contents

  trying to install Debian encrypted in an existed partition, keeping  the rest as it is ... Albretch Mueller <lbrtchx@gmail.com> - 2019-01-29 13:50 +0100
    Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Nitebirdz <nitebirdz@sacredchaos.com> - 2019-01-29 14:50 +0100
      Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Albretch Mueller <lbrtchx@gmail.com> - 2019-01-30 00:20 +0100
        Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Wright <deblis@lionunicorn.co.uk> - 2019-01-30 01:30 +0100
          Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Albretch Mueller <lbrtchx@gmail.com> - 2019-01-30 05:40 +0100
            Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Albretch Mueller <lbrtchx@gmail.com> - 2019-01-30 06:40 +0100
              Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Christensen <dpchrist@holgerdanske.com> - 2019-01-30 15:50 +0100
                Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Brian <ad44@cityscape.co.uk> - 2019-01-30 16:10 +0100
                  Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-01-30 20:00 +0100
                    Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Brian <ad44@cityscape.co.uk> - 2019-01-30 20:10 +0100
                      Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Christensen <dpchrist@holgerdanske.com> - 2019-01-31 02:30 +0100
                Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Thomas D Dial <tdial@acm.org> - 2019-01-30 20:30 +0100
                  Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Christensen <dpchrist@holgerdanske.com> - 2019-01-31 02:30 +0100
              Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Wright <deblis@lionunicorn.co.uk> - 2019-02-01 04:40 +0100
                Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Albretch Mueller <lbrtchx@gmail.com> - 2019-02-05 10:50 +0100
                  Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Wright <deblis@lionunicorn.co.uk> - 2019-02-05 17:40 +0100
            Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... David Wright <deblis@lionunicorn.co.uk> - 2019-01-31 22:40 +0100
        Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Nitebirdz <nitebirdz@sacredchaos.com> - 2019-01-30 15:50 +0100
    Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Jonathan Dowland <jmtd@debian.org> - 2019-01-30 11:10 +0100
    Re: trying to install Debian encrypted in an existed partition,  keeping the rest as it is ... Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-01-30 20:10 +0100

#204790 — trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2019-01-29 13:50 +0100
Subjecttrying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlAZX-2v6-1@gated-at.bofh.it>
 I got one of those office computers I would like to recycle. It has a
fat16 (as /dev/sda1) partition with some manufacturer’s selftests
which I would like to keep. So, I wiped the rest of the other two
partitions to install Debian encrypted, however I can’t make sense of
the questions I am being asked and I can’t go passed that installation
step.

 I could imagine I am not the only one who has tried to do something
like that before. It seems the Debian encrypted installation gets a
bit "temperamental" about partitions. Why would that be? Could you
point me to a link explaining the installation procedures step by step
when you need to keep a previous partition?

 I will post here how did I work myself out of that situation. Once I
manage to do so.

 lbrtchx

[toc] | [next] | [standalone]


#204796 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromNitebirdz <nitebirdz@sacredchaos.com>
Date2019-01-29 14:50 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlBW1-357-13@gated-at.bofh.it>
In reply to#204790
On Tue, Jan 29, 2019 at 07:45:40AM -0500, Albretch Mueller wrote:
>  I got one of those office computers I would like to recycle. It has a
> fat16 (as /dev/sda1) partition with some manufacturer’s selftests
> which I would like to keep. So, I wiped the rest of the other two
> partitions to install Debian encrypted, however I can’t make sense of
> the questions I am being asked and I can’t go passed that installation
> step.
> 
>  I could imagine I am not the only one who has tried to do something
> like that before. It seems the Debian encrypted installation gets a
> bit "temperamental" about partitions. Why would that be? Could you
> point me to a link explaining the installation procedures step by step
> when you need to keep a previous partition?
> 
>  I will post here how did I work myself out of that situation. Once I
> manage to do so.
> 
>  lbrtchx
> 

I used the following two documents sometime ago to perform a similar
install. Hopefully, they will be of some help to you too. 

https://xo.tc/setting-up-full-disk-encryption-on-debian-9-stretch.html

https://gist.github.com/ppmathis/ccfbfce86484dc61834c1f17568d7b80


-- 
Nitebirdz

[toc] | [prev] | [next] | [standalone]


#204813 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2019-01-30 00:20 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlKPD-cs-1@gated-at.bofh.it>
In reply to#204796
On 1/29/19, Nitebirdz <nitebirdz@sacredchaos.com> wrote:
> I used the following two documents sometime ago to perform a similar
> install. Hopefully, they will be of some help to you too.
>
> https://xo.tc/setting-up-full-disk-encryption-on-debian-9-stretch.html
>
> https://gist.github.com/ppmathis/ccfbfce86484dc61834c1f17568d7b80

 As you could see, they both describe a Debian stretch -Full Disk
Encryption- type of installation. I will try to think it through again
when I find some time

 I still don't get why would Debian become so temperamental about
partitions when you try to install it encrypted

 thanks
 lbrtchx

[toc] | [prev] | [next] | [standalone]


#204814 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-01-30 01:30 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlLVn-OB-5@gated-at.bofh.it>
In reply to#204813
On Tue 29 Jan 2019 at 18:15:23 (-0500), Albretch Mueller wrote:
> On 1/29/19, Nitebirdz <nitebirdz@sacredchaos.com> wrote:
> > I used the following two documents sometime ago to perform a similar
> > install. Hopefully, they will be of some help to you too.
> >
> > https://xo.tc/setting-up-full-disk-encryption-on-debian-9-stretch.html
> >
> > https://gist.github.com/ppmathis/ccfbfce86484dc61834c1f17568d7b80
> 
>  As you could see, they both describe a Debian stretch -Full Disk
> Encryption- type of installation. I will try to think it through again
> when I find some time

I can see that with the first version, because it chose to use
"Guided - use entire disk"; though I don't know why the installer
doesn't offer the combination of the first option "Guided - use the
largest continuous free space" and the later one with "… set up
encrypted LVM".

However, the second method uses manual partitioning of the disks with
gdisk, so I don't see why sda should not contain a(nother) FAT
partition which is ignored. If the sda partition numbers are all
increased by one, which command is it that would prevent the
method from working?

>  I still don't get why would Debian become so temperamental about
> partitions when you try to install it encrypted

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#204817 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2019-01-30 05:40 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlPPk-3cv-3@gated-at.bofh.it>
In reply to#204814
On 1/29/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> However, the second method uses manual partitioning of the disks with
> gdisk, so I don't see why sda should not contain a(nother) FAT
> partition which is ignored.

 I don't see why either. Also, given the fact that so many, entirely
fine computers (with 4+ Gibs RAM!) are being discarded/discontinued on
a yearly basis (mostly for software related issues or just because
they are "old"), why shouldn't people keep the a very small (less than
64Mbs) diagnostic partition from the manufacturer on sda1 and use the
rest of the space for the installation?

 Is it because the unencrypted root partition wants to sit on sda1?

 At the very least the Debian installer should explicitly tell you:
"no, you can't install and encrypted volume on just a partition
(hopefully: 'because . . .')"

> If the sda partition numbers are all
> increased by one

 How do you do that? and, can you revert the partition numbers back if
the need arises? I think most probably that won't be the solution
and/or may create other problems.

>  which command is it that would prevent the
> method from working?

 How could you find out about it?

 lbrtchx

[toc] | [prev] | [next] | [standalone]


#204818 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2019-01-30 06:40 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlQLn-3O0-1@gated-at.bofh.it>
In reply to#204817
 use case:

 Say, you have a computer preinstalled with Windows, on which you
would like to install a Debian Linux base. You would:

 1) resize the larger, Windows proper (/dev/sda3) partition
 2) install Linux encrypted in the created space, with
 3) what you need to start it up (the /root partition) on a pen drive

 So, other people may be able to use that box just fine under Windows
and you would do your thing.

 If for whatever reason you disown that computer, you would just
delete that partition. Your own data you will keep on a USB pen or
microdrive.

 Any step by step procedures?

 lbrtchx

[toc] | [prev] | [next] | [standalone]


#204821 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2019-01-30 15:50 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlZlE-uO-5@gated-at.bofh.it>
In reply to#204818
On 1/29/19 9:30 PM, Albretch Mueller wrote:
>   use case:
> 
>   Say, you have a computer preinstalled with Windows, on which you
> would like to install a Debian Linux base. You would:
> 
>   1) resize the larger, Windows proper (/dev/sda3) partition
>   2) install Linux encrypted in the created space, with
>   3) what you need to start it up (the /root partition) on a pen drive
> 
>   So, other people may be able to use that box just fine under Windows
> and you would do your thing.
> 
>   If for whatever reason you disown that computer, you would just
> delete that partition. Your own data you will keep on a USB pen or
> microdrive.

If you want a portable Debian installation, install Debian on a USB 
flash drive.  To avoid confusion, install (and update/upgrade) on a 
computer with no other drives connected (so that GRUB does not create 
boot menu entries for other operating systems).  Use the motherboard 
firmware (BIOS/UEFI) boot device hot key and/or setup program to boot 
Debian.


>   Any step by step procedures?

See the Debian stretch -- Installation Guide:

https://www.debian.org/releases/stable/installmanual


Use a camera or phone to take photographs of the screen as needed.  Use 
a second computer to take detailed notes.  Put everything into your 
favorite version control system.


David

[toc] | [prev] | [next] | [standalone]


#204823 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromBrian <ad44@cityscape.co.uk>
Date2019-01-30 16:10 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlZEZ-QG-1@gated-at.bofh.it>
In reply to#204821
On Wed 30 Jan 2019 at 06:42:30 -0800, David Christensen wrote:

> On 1/29/19 9:30 PM, Albretch Mueller wrote:
> >   use case:
> > 
> >   Say, you have a computer preinstalled with Windows, on which you
> > would like to install a Debian Linux base. You would:
> > 
> >   1) resize the larger, Windows proper (/dev/sda3) partition
> >   2) install Linux encrypted in the created space, with
> >   3) what you need to start it up (the /root partition) on a pen drive
> > 
> >   So, other people may be able to use that box just fine under Windows
> > and you would do your thing.
> > 
> >   If for whatever reason you disown that computer, you would just
> > delete that partition. Your own data you will keep on a USB pen or
> > microdrive.
> 
> If you want a portable Debian installation, install Debian on a USB flash
> drive.  To avoid confusion, install (and update/upgrade) on a computer with
> no other drives connected (so that GRUB does not create boot menu entries
> for other operating systems).  Use the motherboard firmware (BIOS/UEFI) boot
> device hot key and/or setup program to boot Debian.

Wouldn't removing os-prober save having to hunt down a driveless
machine?

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#204832 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2019-01-30 20:00 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xm3fz-2O9-1@gated-at.bofh.it>
In reply to#204823
Le 30/01/2019 à 16:01, Brian a écrit :
> On Wed 30 Jan 2019 at 06:42:30 -0800, David Christensen wrote:
>>
>> To avoid confusion, install (and update/upgrade) on a computer with
>> no other drives connected (so that GRUB does not create boot menu entries
>> for other operating systems).
(...)
> Wouldn't removing os-prober save having to hunt down a driveless
> machine?

Yes. Or just add this line to /etc/default/grub :

GRUB_DISABLE_OS_PROBER=true

[toc] | [prev] | [next] | [standalone]


#204834 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromBrian <ad44@cityscape.co.uk>
Date2019-01-30 20:10 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xm3pg-36G-7@gated-at.bofh.it>
In reply to#204832
On Wed 30 Jan 2019 at 19:51:06 +0100, Pascal Hambourg wrote:

> Le 30/01/2019 à 16:01, Brian a écrit :
> > On Wed 30 Jan 2019 at 06:42:30 -0800, David Christensen wrote:
> > > 
> > > To avoid confusion, install (and update/upgrade) on a computer with
> > > no other drives connected (so that GRUB does not create boot menu entries
> > > for other operating systems).
> (...)
> > Wouldn't removing os-prober save having to hunt down a driveless
> > machine?
> 
> Yes. Or just add this line to /etc/default/grub :
> 
> GRUB_DISABLE_OS_PROBER=true

A much more satisfactory and flexible technique than using brute force.

-- 
Brian. 

[toc] | [prev] | [next] | [standalone]


#204848 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2019-01-31 02:30 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xm9l0-6GD-5@gated-at.bofh.it>
In reply to#204834
On 1/30/19 11:05 AM, Brian wrote:
> On Wed 30 Jan 2019 at 19:51:06 +0100, Pascal Hambourg wrote:
> 
>> Le 30/01/2019 à 16:01, Brian a écrit :
>>> On Wed 30 Jan 2019 at 06:42:30 -0800, David Christensen wrote:
>>>>
>>>> To avoid confusion, install (and update/upgrade) on a computer with
>>>> no other drives connected (so that GRUB does not create boot menu entries
>>>> for other operating systems).
>> (...)
>>> Wouldn't removing os-prober save having to hunt down a driveless
>>> machine?
>>
>> Yes. Or just add this line to /etc/default/grub :
>>
>> GRUB_DISABLE_OS_PROBER=true
> 
> A much more satisfactory and flexible technique than using brute force.

+1


I will need to look that up the next time I reach for my Debian-on-USB 
flash drives.


David

[toc] | [prev] | [next] | [standalone]


#204836 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromThomas D Dial <tdial@acm.org>
Date2019-01-30 20:30 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xm3IC-3dq-17@gated-at.bofh.it>
In reply to#204821
On Wed, 2019-01-30 at 06:42 -0800, David Christensen wrote:
> On 1/29/19 9:30 PM, Albretch Mueller wrote:
> >   use case:
> > 
> >   Say, you have a computer preinstalled with Windows, on which you
> > would like to install a Debian Linux base. You would:
> > 
> >   1) resize the larger, Windows proper (/dev/sda3) partition
> >   2) install Linux encrypted in the created space, with
> >   3) what you need to start it up (the /root partition) on a pen
> > drive
> > 
> >   So, other people may be able to use that box just fine under
> > Windows
> > and you would do your thing.
> > 
> >   If for whatever reason you disown that computer, you would just
> > delete that partition. Your own data you will keep on a USB pen or
> > microdrive.
> 
> If you want a portable Debian installation, install Debian on a USB 
> flash drive.  To avoid confusion, install (and update/upgrade) on a 
> computer with no other drives connected (so that GRUB does not create 
> boot menu entries for other operating systems).  Use the motherboard 
> firmware (BIOS/UEFI) boot device hot key and/or setup program to boot 
> Debian.
> 
I see no reason to take the original drive out for the install. If you
don't, grub will find the OS(s) on it and generally provide correctly
for booting them if you wish to do so. If the machine is booted without
the USB key, it still will boot normally for the old OS(s). I have found
this arrangement quite convenient.

Tom Dial 
> 
> >   Any step by step procedures?
> 
> See the Debian stretch -- Installation Guide:
> 
> https://www.debian.org/releases/stable/installmanual
> 
> 
> Use a camera or phone to take photographs of the screen as
> needed.  Use 
> a second computer to take detailed notes.  Put everything into your 
> favorite version control system.
> 
> 
> David

[toc] | [prev] | [next] | [standalone]


#204847 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2019-01-31 02:30 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xm9l0-6GD-3@gated-at.bofh.it>
In reply to#204836
On 1/30/19 11:03 AM, Thomas D Dial wrote:
> On Wed, 2019-01-30 at 06:42 -0800, David Christensen wrote:
>> If you want a portable Debian installation, install Debian on a USB
>> flash drive.  To avoid confusion, install (and update/upgrade) on a
>> computer with no other drives connected (so that GRUB does not create
>> boot menu entries for other operating systems). ... >>
> I see no reason to take the original drive out for the install. 

Note the word "connected" -- when installing Debian, I disconnect any 
drives that I don't want the Debian installer to see.  I


> If you don't, grub will find the OS(s) on it and generally provide correctly for booting them if you wish to do so. 

I have one USB flash drive with Debian amd64 and another with Debian 
i386.  I use them for maintenance/ troubleshooting on many computers 
(one at a time).  I don't want or need GRUB adding extraneous boot menu 
entries.


> If the machine is booted without the USB key, it still will boot normally for the old OS(s). I have found this arrangement quite convenient.

Same for my arrangement, but without the cruft.


David

[toc] | [prev] | [next] | [standalone]


#204879 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-02-01 04:40 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xmxQl-4SB-3@gated-at.bofh.it>
In reply to#204818
On Wed 30 Jan 2019 at 00:30:40 (-0500), Albretch Mueller wrote:
>  use case:
> 
>  Say, you have a computer preinstalled with Windows, on which you
> would like to install a Debian Linux base. You would:
> 
>  1) resize the larger, Windows proper (/dev/sda3) partition

Yes, the largest partition (/dev/sda5 here) was the one containing all
the user data. I shrank it in stages:
a) free up space by removing redundant files, emptying the trash etc.
b) defrag and optimise the disk.
c) shrink the volume.
d) create a partition in the freed space.
e) copy files onto the new partition.
f) remove said files.
g) try again.
h) set No Protection, then delete Checkpoints.
i) copy said files back.
j) shrink more.
k) remove partition created at (d).
l) create 5 partitions as required, filling free space.
m) set size, assign no drive letter, exFAT or FAT as offered.
n) label them for unambiguous identification.
o) boot linux and run gdisk to reestablish the 5 partitions' properties.

I create 5 partitions for /, backup / (I always carry a spare),
/home, BIOS boot, and Swap. NB: BIOS boot is not /boot; it's empty.

>  2) install Linux encrypted in the created space,

One reason I'm not more help is that I install linux unencrypted in /,
create an encrypted partition for future /home, copy the directories
from current /home to future /home (basically the /etc/skel files)
and make the necessary adjustments to /etc/fstab and crypttab to
mount future /home over current /home when rebooted.

> with
>  3) what you need to start it up (the /root partition) on a pen drive

I've used the option of selecting the OS to run by using Legacy BIOS
booting for linux and the preinstalled EFI booting for Windows.
So, apart from the creation of the 5 "untouchable" partitions,
and being told that the RTC is running on UTC, Windows knows nothing
about the linux system's presence.

>  So, other people may be able to use that box just fine under Windows
> and you would do your thing.

Yes, in my case they just have to know to press the small button on
the side instead of the power button, and then select the top item
from this menu (as I leave BIOS as the default):

Normal Startup     ← Windows
BIOS Setup         ← linux
Boot Menu
System recovery

>  If for whatever reason you disown that computer, you would just
> delete that partition. Your own data you will keep on a USB pen or
> microdrive.

Something like that. I'd run badblocks over the unencrypted partitions.

>  Any step by step procedures?

Modify anything above to taste.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#205002 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2019-02-05 10:50 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xo5wB-5cs-1@gated-at.bofh.it>
In reply to#204879
On 1/31/19, David Wright <deblis@lionunicorn.co.uk> wrote:
>>  If for whatever reason you disown that computer, you would just
>> delete that partition. Your own data you will keep on a USB pen or
>> microdrive.
>
> Something like that. I'd run badblocks over the unencrypted partitions.
>

 Why? Do you mean the low level formatting on an encrypted drive
physically messes with it?

If you start the Debian installation Live DVD and remove that
partition using parted. Would the BIOS, file system utilities under
Windows not see and handle the deleted partition just as extra space?

 This is of crucial importance because you don’t own those computers
at work. Your supervisors, "tech support" would not mind you bending
the rules a bit as long as you safely reset them back to their initial
state when you disown them.

 lbrtchx

On 1/31/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> On Wed 30 Jan 2019 at 00:30:40 (-0500), Albretch Mueller wrote:
>>  use case:
>>
>>  Say, you have a computer preinstalled with Windows, on which you
>> would like to install a Debian Linux base. You would:
>>
>>  1) resize the larger, Windows proper (/dev/sda3) partition
>
> Yes, the largest partition (/dev/sda5 here) was the one containing all
> the user data. I shrank it in stages:
> a) free up space by removing redundant files, emptying the trash etc.
> b) defrag and optimise the disk.
> c) shrink the volume.
> d) create a partition in the freed space.
> e) copy files onto the new partition.
> f) remove said files.
> g) try again.
> h) set No Protection, then delete Checkpoints.
> i) copy said files back.
> j) shrink more.
> k) remove partition created at (d).
> l) create 5 partitions as required, filling free space.
> m) set size, assign no drive letter, exFAT or FAT as offered.
> n) label them for unambiguous identification.
> o) boot linux and run gdisk to reestablish the 5 partitions' properties.
>
> I create 5 partitions for /, backup / (I always carry a spare),
> /home, BIOS boot, and Swap. NB: BIOS boot is not /boot; it's empty.
>
>>  2) install Linux encrypted in the created space,
>
> One reason I'm not more help is that I install linux unencrypted in /,
> create an encrypted partition for future /home, copy the directories
> from current /home to future /home (basically the /etc/skel files)
> and make the necessary adjustments to /etc/fstab and crypttab to
> mount future /home over current /home when rebooted.
>
>> with
>>  3) what you need to start it up (the /root partition) on a pen drive
>
> I've used the option of selecting the OS to run by using Legacy BIOS
> booting for linux and the preinstalled EFI booting for Windows.
> So, apart from the creation of the 5 "untouchable" partitions,
> and being told that the RTC is running on UTC, Windows knows nothing
> about the linux system's presence.
>
>>  So, other people may be able to use that box just fine under Windows
>> and you would do your thing.
>
> Yes, in my case they just have to know to press the small button on
> the side instead of the power button, and then select the top item
> from this menu (as I leave BIOS as the default):
>
> Normal Startup     ← Windows
> BIOS Setup         ← linux
> Boot Menu
> System recovery
>
>>  If for whatever reason you disown that computer, you would just
>> delete that partition. Your own data you will keep on a USB pen or
>> microdrive.
>
> Something like that. I'd run badblocks over the unencrypted partitions.
>
>>  Any step by step procedures?
>
> Modify anything above to taste.
>
> Cheers,
> David.

[toc] | [prev] | [next] | [standalone]


#205027 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-02-05 17:40 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xobVn-P5-5@gated-at.bofh.it>
In reply to#205002
On Tue 05 Feb 2019 at 04:42:02 (-0500), Albretch Mueller wrote:
> On 1/31/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> >>  If for whatever reason you disown that computer, you would just
> >> delete that partition. Your own data you will keep on a USB pen or
> >> microdrive.
> >
> > Something like that. I'd run badblocks over the unencrypted partitions.
> >
> 
>  Why? Do you mean the low level formatting on an encrypted drive
> physically messes with it?

If by "low level formatting" you mean what manufacturers do, certainly not.

No, I'm just shredding any unencrypted partitions that are in the
"created space" (your item 2). Sorry if that wasn't clear.

> If you start the Debian installation Live DVD and remove that
> partition using parted. Would the BIOS, file system utilities under
> Windows not see and handle the deleted partition just as extra space?

I assume so. I've not done it, but I would think that you could regrow
the filesystem that you shrank at the start.

>  This is of crucial importance because you don’t own those computers
> at work. Your supervisors, "tech support" would not mind you bending
> the rules a bit as long as you safely reset them back to their initial
> state when you disown them.

In my own circumstances, there are two scenarios, and the recipe
I posted was for the first. Here, the Debian installation is
permanent, but the preinstalled Windows must continue to function
without any interruption in availability. Being a laptop, the
options are a bit more limited.

The other scenario is for conventional PCs, and there are many
options depending on the loan. Sometimes the safest option would
to remove the drive and use your own for the duration. In my case,
the only reason the equipment hasn't been disposed of is the
stunning bureaucracy involved. Running the installed OS on a network
would be irresponsible, so there's no point in preserving it.

(BTW disposal would involve either three passes of badblocks
or total destruction of the drive.)

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#204875 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-01-31 22:40 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xmsdY-1o9-13@gated-at.bofh.it>
In reply to#204817
On Tue 29 Jan 2019 at 23:36:27 (-0500), Albretch Mueller wrote:
> On 1/29/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> > However, the second method uses manual partitioning of the disks with
> > gdisk, so I don't see why sda should not contain a(nother) FAT
> > partition which is ignored.
> 
>  I don't see why either. Also, given the fact that so many, entirely
> fine computers (with 4+ Gibs RAM!) are being discarded/discontinued on
> a yearly basis (mostly for software related issues or just because
> they are "old"), why shouldn't people keep the a very small (less than
> 64Mbs) diagnostic partition from the manufacturer on sda1 and use the
> rest of the space for the installation?

No reason, but when people post a recipe that they actually use, it
will likely contain choices that they made for their own reasons.
So, for example, I've never used non-expert mode install, guided
partitioning, or EFI installation, and recipes that assume any of
these might be of limited use to me.

>  Is it because the unencrypted root partition wants to sit on sda1?

s/root/boot/
I can't think why that would matter.

>  At the very least the Debian installer should explicitly tell you:
> "no, you can't install and encrypted volume on just a partition
> (hopefully: 'because . . .')"
> 
> > If the sda partition numbers are all
> > increased by one
> 
>  How do you do that? and, can you revert the partition numbers back if
> the need arises? I think most probably that won't be the solution
> and/or may create other problems.

I just meant that you would read instructions like these:

$ mdadm --create /dev/md/boot --level=1 --raid-devices=2 /dev/sda2 /dev/sdb2
$ mdadm --create /dev/md/lvm --level=1 --raid-devices=2 /dev/sda3 /dev/sdb3
$ mkfs.vfat -F32 /dev/sda1
$ mkfs.vfat -F32 /dev/sdb1

as:

$ mdadm --create /dev/md/boot --level=1 --raid-devices=2 /dev/sda3 /dev/sdb2
$ mdadm --create /dev/md/lvm --level=1 --raid-devices=2 /dev/sda4 /dev/sdb3
$ mkfs.vfat -F32 /dev/sda2
$ mkfs.vfat -F32 /dev/sdb1

> >  which command is it that would prevent the
> > method from working?
> 
>  How could you find out about it?

By trying it out, I guess. I fall at the first hurdle on
requirements 1 (EFI) and 3 (2 disks).

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#204820 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromNitebirdz <nitebirdz@sacredchaos.com>
Date2019-01-30 15:50 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlZlD-uO-1@gated-at.bofh.it>
In reply to#204813
On Tue, Jan 29, 2019 at 06:15:23PM -0500, Albretch Mueller wrote:
> On 1/29/19, Nitebirdz <nitebirdz@sacredchaos.com> wrote:
> > I used the following two documents sometime ago to perform a similar
> > install. Hopefully, they will be of some help to you too.
> >
> > https://xo.tc/setting-up-full-disk-encryption-on-debian-9-stretch.html
> >
> > https://gist.github.com/ppmathis/ccfbfce86484dc61834c1f17568d7b80
> 
>  As you could see, they both describe a Debian stretch -Full Disk
> Encryption- type of installation. I will try to think it through again
> when I find some time
> 
>  I still don't get why would Debian become so temperamental about
> partitions when you try to install it encrypted
> 

Albretch,


Perhaps the following document could be of some help. I had to use it to
install Debian Stretch on a different laptop with EFI. So, in my case, one
of the partitions is not encrypted. In that sense, the situation is
somehow similar to your fat16 (/dev/sda1) partition. The document refers
to Jessie, but I used it to install Stretch no problem. 

https://xo.tc/setting-up-full-disk-encryption-on-debian-jessie.html


-- 
Nitebirdz

[toc] | [prev] | [next] | [standalone]


#204819 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromJonathan Dowland <jmtd@debian.org>
Date2019-01-30 11:10 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xlUYG-6st-19@gated-at.bofh.it>
In reply to#204790
On Tue, Jan 29, 2019 at 07:45:40AM -0500, Albretch Mueller wrote:
> I got one of those office computers I would like to recycle. It has a
>fat16 (as /dev/sda1) partition with some manufacturer’s selftests
>which I would like to keep. So, I wiped the rest of the other two
>partitions to install Debian encrypted, however I can’t make sense of
>the questions I am being asked and I can’t go passed that installation
>step.

Can you share exactly what you tried, what questions you were asked, and
any other messages you were presented with?

This is something that is (or should be) perfectly possible.

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#204833 — Re: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2019-01-30 20:10 +0100
SubjectRe: trying to install Debian encrypted in an existed partition, keeping the rest as it is ...
Message-ID<xm3pf-36G-1@gated-at.bofh.it>
In reply to#204790
Le 29/01/2019 à 13:45, Albretch Mueller a écrit :
>   I got one of those office computers I would like to recycle. It has a
> fat16 (as /dev/sda1) partition with some manufacturer’s selftests
> which I would like to keep. So, I wiped the rest of the other two
> partitions to install Debian encrypted, however I can’t make sense of
> the questions I am being asked and I can’t go passed that installation
> step.

You need to understand hows the installer works.

Select manual partitioning.

Create a partition for the unencrypted part (/ or /boot). Use it as ext4 
filesystem and mount it on / or /boot.

Create a partition for the encrypted part. Use it as physical volume for 
encryption.

Enter the encrypted volume management.
Create an encrypted volume using the second partition.
Exit the encrypted volume management.

Select the encrypted volume and use it a physical volume for LVM.

Enter the LVM management.
Create a volume group using the encrypted volume. Give it an informative 
name, not "vg0".
Create logical volumes for /, /home, swap... as you like. Give them 
informative names, not "lv1"...
Exit the LVM management.

Select each logical volume, use and mount it as appropriate like you 
would do with partitions.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web