From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?utf-8?Q?Ludovic_Court=C3=A8s?= Subject: Re: Unencrypted boot with encrypted root Date: Tue, 07 Apr 2020 11:46:27 +0200 Message-ID: <87d08jbpcc.fsf@gnu.org> References: <87ftdmi7pp.fsf@ambrevar.xyz> <17c316adc8485d1f09f70d291cfaad50258c6c1f.camel@wine-logistix.de> <20200403194423.m3pvz654qslug7g3@pelzflorian.localdomain> <20200404101832.cmegsybfyrseazjq@pelzflorian.localdomain> <4610a9147fa041ebb47f184a2d3f7878a8a2539c.camel@wine-logistix.de> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:470:142:3::10]:36402) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jLkoS-0000Uy-Dc for guix-devel@gnu.org; Tue, 07 Apr 2020 05:46:33 -0400 In-Reply-To: <4610a9147fa041ebb47f184a2d3f7878a8a2539c.camel@wine-logistix.de> (Ellen Papsch's message of "Mon, 06 Apr 2020 14:00:04 +0200") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane-mx.org@gnu.org Sender: "Guix-devel" To: Ellen Papsch Cc: guix-devel@gnu.org Hi, Ellen Papsch skribis: > Am Samstag, den 04.04.2020, 12:18 +0200 schrieb pelzflorian (Florian > Pelz): >> Could key files help in passing the passphrase on to the >> Linux kernel? The Arch Wiki says this: [...] >>=20 > > The key file would be another means of decrypting the master key, if I > understand LUKS correctly. It would be independent of the passphrase. > (In LUKS terminology, two slots are used). > > It would definitely help usability not having to enter a passphrase > twice. The GUI/TUI installer should take care generating the file and > ensuring strict permissions, so user processes cannot read it. There is > still some risk, because root processes could read it. If the installer > would support an external medium for the file, that would be best > (IMHO). The difficulty is that any file traveling through the store is world-readable. It=E2=80=99s hard to avoid. Ludo=E2=80=99.