Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #185163

Re: Unusual LUKS setup

From Darac Marjal <mailinglist@darac.org.uk>
Newsgroups linux.debian.user
Subject Re: Unusual LUKS setup
Date 2017-08-14 12:20 +0200
Message-ID <uekDw-2U0-11@gated-at.bofh.it> (permalink)
References <uekav-2tS-27@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, Aug 14, 2017 at 11:27:00AM +0200, Nicolas George wrote:
>Hi.
>
>I have been using LUKS to encrypt part of my system, with a rather
>unusual setup, and I would like to ask for advice on making it more
>standard without sacrificing my requirements.
>
>My requirements are:
>
>- Protect me from casual invasions of my privacy in case the computer
>  were stolen.
>
>- Being able to unlock the system remotely through SSH.
>
>- Minimize the duration of the second-longest interval between required
>  manual operation during boot.
>
>  Which translate in practice by: minimize the time between the first
>  interaction I must have with Linux and the moment I have an usable
>  session.
>
>- Minimize the number of keystrokes required during boot.
>
>The second point requires an explanation. Like many people, in the
>morning I switch on this computer with the following sequence: start the
>boot, go take care of physiological needs, finish the boot. During the
>longest part of the boot, I am somewhere else, hence my focus on the
>second longest part. Since the duration of the POST is incompressible,
>the longest part of the boot is usually the time between pressing the
>power button and the first interaction required by Linux.

It sounds to me, then, that you'd like the system to be unencrypted, but 
your home to be encrypted. You want to look into PAM, which I'm sure can 
do this. With PAM, the system would come up and all the system daemons 
would start. Towards the end of that (or perhaps earlier, depending on 
the dependencies), login methods (getty / x-display-manager / sshd / 
etc) would become available. You'd log in on one of those and PAM would 
ensure that your home is decrypted as part of the session start-up. 

A quick google suggests that pam_mount is your friend here. I *think* 
that pam_mount should be able to mount other directories (as well as 
home), so if you have a media partition that you'd like mounted, that 
can be done.


-- 
For more information, please reread.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 11:50 +0200
  Re: Unusual LUKS setup Darac Marjal <mailinglist@darac.org.uk> - 2017-08-14 12:20 +0200
    Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 16:40 +0200
      Re: Unusual LUKS setup Bastien Durel <bastien@durel.org> - 2017-08-14 17:10 +0200
        Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 18:00 +0200
          Re: Unusual LUKS setup Bastien Durel <bastien@durel.org> - 2017-08-16 10:10 +0200
            Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 15:40 +0200
  Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-14 12:30 +0200
    Re: Unusual LUKS setup tomas@tuxteam.de - 2017-08-14 16:40 +0200
      Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 18:10 +0200
        Re: Unusual LUKS setup tomas@tuxteam.de - 2017-08-14 21:30 +0200
      Re: Unusual LUKS setup Curt <curty@free.fr> - 2017-08-15 14:20 +0200
        Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-15 17:30 +0200
          Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 21:10 +0200
            Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 04:50 +0200
              Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-16 09:40 +0200
                Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 15:30 +0200
        Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 21:00 +0200
          Re: Unusual LUKS setup Brian <ad44@cityscape.co.uk> - 2017-08-15 21:40 +0200
            Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 22:20 +0200
    Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 16:50 +0200

csiph-web