Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #179947

Re: system drive encryption question

From Nathanael Schweers <Nathanael.Schweers@outdooractive.com>
Newsgroups linux.debian.user
Subject Re: system drive encryption question
Date 2017-04-10 10:30 +0200
Message-ID <tuCRX-6Gd-9@gated-at.bofh.it> (permalink)
References <tt9yG-52M-21@gated-at.bofh.it> <ttGuB-2vP-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Pascal Hambourg <pascal@plouf.fr.eu.org> writes:

> The version of GRUB included in Jessie at least can handle an encrypted 
> /boot. However the Debian installer does not handle this case correctly. 
> You must add the following line in /etc/default/grub in order for 
> grub-install to install the core image with crypto modules and for 
> update-grub to generate a proper grub.cfg :
>
> GRUB_ENABLE_CRYPTODISK=y
>
> (not =1 or =true as seen on some documentation)
>
> The procedure in the post you point to is flawed in Debian Jessie : if 
> you run update-grub or grub-mkconfig before adding the line in 
> /etc/default/grub, it won't add the required "cryptomount" commands to 
> open encrypted devices. Actually it is grub-mkconfig which is broken : 
> if the line is present, it adds an cryptomount command in every menu 
> entry, even when not needed (and generates boot-time errors). If the 
> line is missing, it adds insmod commands to load crypto modules when 
> needed but not the cryptomount commands.

I never said that it works on debian.  I just wanted to point out that
it is not strictly necessary to have an unencrypted /boot partition.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: system drive encryption question Rick Thomas <rbthomas@pobox.com> - 2017-04-06 12:20 +0200
  Re: system drive encryption question Rick Thomas <rbthomas@pobox.com> - 2017-04-06 12:30 +0200
  Re: system drive encryption question Nathanael Schweers <Nathanael.Schweers@outdooractive.com> - 2017-04-06 13:20 +0200
    Re: system drive encryption question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-04-07 20:10 +0200
      Re: system drive encryption question Nathanael Schweers <Nathanael.Schweers@outdooractive.com> - 2017-04-10 10:30 +0200
        Re: system drive encryption question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-04-10 20:10 +0200
  Re: system drive encryption question Jonathan Dowland <jmtd@debian.org> - 2017-04-12 11:50 +0200

csiph-web