Re: dracut-sshd in fedora - ssh access to early cryptsetup/dracut shell

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, 27 Jan 2019 15:23:08 +0100
Georg Sauthoff <mail@xxxxxxxx> wrote:

> Hello,
> 
> so I wrote dracut-sshd - a dracut module that adds sshd to the
> initramfs such that one is able to remotely access early
> userspace for e.g. unlocking an encrypted root filesystem or
> dealing with the dracut emergency shell:

The biggest problem in dealing with crypto early in boot is that the
system is starved for entropy. I'm wondering if this runs before or
after systemd loads the saved entropy seed into the kernel?

-Steve

> https://github.com/gsauthof/dracut-sshd
> 
> I would like to add it to Fedora because it adds important
> functionality that is currently missing.
> 
> There are basically two routes:
> 
> 1) Integrate it into upstream dracut (and package it as new
>    package in Fedora)
> 2) Package it independently and submit a review request to the
>    Fedora bugzilla (I could maintain that package)
> 
> In May, 2018 I posted to the dracut mailing list
> (https://www.spinics.net/lists/linux-initramfs/msg04617.html), but I
> didn't receive any reply on that list.
> 
> Thus, I lean towards following route 2) now.
> 
> Any comments/suggestions?
> 
> See also:
> 
> - dracut-sshd copr repository for f28/f29/c7
>   https://copr.fedorainfracloud.org/coprs/gsauthof/dracut-sshd/
> - Travis-CI continuous integration (tests run on f29/c7)
>   https://travis-ci.org/gsauthof/dracut-sshd
> - >9 year old open Fedora Bug about this feature  
>   Dracut + encrypted root + networking
>   https://bugzilla.redhat.com/show_bug.cgi?id=524727
>   My comment there:
>   https://bugzilla.redhat.com/show_bug.cgi?id=524727#c28
> 
> Best regards
> Georg
> 
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Users]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]

  Powered by Linux