Jari Ruusu wrote: > You can decrypt your root partition using exactly same command syntax as you > used to encrypt it, except add -d option to aespipe for 'decryption'. Then > you can re-run the 'encrypt' command pipe again with correct encryption > options. I forgot to ask: What version of loop-AES are you using? build-initrd.sh script from loop-AES versions older than v2.0e will not work properly with recent gentoo glibc. In loop-AES-v2.0e you have to set USEDIETLIBC=1. In loop-AES-v2.0f that is the default. vsyscall enabled glibc incompatility with build-initrd.sh was one of the reasons why v2.0f was released so quickly after v2.0e. Also, are you sure that your mount and losetup programs are from loop-AES-v2.0b or later? If they are older, multi-key mode will fail. -- Jari Ruusu 1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9 DB - Linux-crypto: cryptography in and on the Linux system Archive: http://mail.nl.linux.org/linux-crypto/