Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #179947
| From | Nathanael Schweers <Nathanael.Schweers@outdooractive.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: system drive encryption question |
| Date | 2017-04-10 10:30 +0200 |
| Message-ID | <tuCRX-6Gd-9@gated-at.bofh.it> (permalink) |
| References | <tt9yG-52M-21@gated-at.bofh.it> <ttGuB-2vP-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Pascal Hambourg <pascal@plouf.fr.eu.org> writes: > The version of GRUB included in Jessie at least can handle an encrypted > /boot. However the Debian installer does not handle this case correctly. > You must add the following line in /etc/default/grub in order for > grub-install to install the core image with crypto modules and for > update-grub to generate a proper grub.cfg : > > GRUB_ENABLE_CRYPTODISK=y > > (not =1 or =true as seen on some documentation) > > The procedure in the post you point to is flawed in Debian Jessie : if > you run update-grub or grub-mkconfig before adding the line in > /etc/default/grub, it won't add the required "cryptomount" commands to > open encrypted devices. Actually it is grub-mkconfig which is broken : > if the line is present, it adds an cryptomount command in every menu > entry, even when not needed (and generates boot-time errors). If the > line is missing, it adds insmod commands to load crypto modules when > needed but not the cryptomount commands. I never said that it works on debian. I just wanted to point out that it is not strictly necessary to have an unencrypted /boot partition.
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: system drive encryption question Rick Thomas <rbthomas@pobox.com> - 2017-04-06 12:20 +0200
Re: system drive encryption question Rick Thomas <rbthomas@pobox.com> - 2017-04-06 12:30 +0200
Re: system drive encryption question Nathanael Schweers <Nathanael.Schweers@outdooractive.com> - 2017-04-06 13:20 +0200
Re: system drive encryption question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-04-07 20:10 +0200
Re: system drive encryption question Nathanael Schweers <Nathanael.Schweers@outdooractive.com> - 2017-04-10 10:30 +0200
Re: system drive encryption question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-04-10 20:10 +0200
Re: system drive encryption question Jonathan Dowland <jmtd@debian.org> - 2017-04-12 11:50 +0200
csiph-web