Re: dracut 008 luks key in external device - still broken

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



2011/3/20 Amadeusz ÅoÅnowski <aidecoe@xxxxxxxxxxxx>:
> Excerpts from jaivuk's message of Sun Mar 20 00:14:56 +0100 2011:
>> > It re queues cryptroot-ask for after udev queue is settled if key is
>> > not available initially. If device is still not available at this
>> > point, I am not sure what can be done sensibly.
>>
>> I think it should ask for password. And if it does so it would be good
>> if I could still connect the key during the password prompt as I
>> explained...
>
> First of all I haven't taken into consideration fact, that one can want
> to use dracut for mounting something more than root.

Remembering recent discussion about separate /usr, it seems quite possible :)

> That's why there's
> only key or only password. But it probably would be possible to
> optionally ask for password, too. I will have to think of cases with
> multiple devices to be decrypted and improve the module.
>

 I think this can be combined with below. If keydev was not found
after udevsettle, fall through to password request, combined with
request to insert key if respective kernel option was present.

>> So in case an attempt to open another luks partition failes, then yes
>> in my view it would be best if user can either enter key manually or
>> insert the USB stick with the key (in case rd.luks.key was specified).
>
> Hm, might be good idea.

Yep. Currently if user forgot to plug in stick before booting it is
"Oops, I forgot to attach my key" and reboot. Stop there (after udev
settle) and give user chance to still plug in device,
--
To unsubscribe from this list: send the line "unsubscribe initramfs" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Kernel]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite News]     [Linux SCSI]

  Powered by Linux