From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id 4H5oJDjz5WBoFwAAgWs5BA (envelope-from ) for ; Wed, 07 Jul 2021 20:32:24 +0200 Received: from aspmx1.migadu.com ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id IAciIDjz5WBrGgAA1q6Kng (envelope-from ) for ; Wed, 07 Jul 2021 18:32:24 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id BCF151ABDA for ; Wed, 7 Jul 2021 20:32:23 +0200 (CEST) Received: from localhost ([::1]:39194 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1m1CLO-0006DC-Em for larch@yhetil.org; Wed, 07 Jul 2021 14:32:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:60064) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1m1CJc-0004Qm-VN for help-guix@gnu.org; Wed, 07 Jul 2021 14:30:33 -0400 Received: from freeshell.de ([2a01:4f8:231:482b::2]:35716) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1m1CJa-0006lW-7y for help-guix@gnu.org; Wed, 07 Jul 2021 14:30:32 -0400 Received: from localhost (cst-prg-10-140.cust.vodafone.cz [46.135.10.140]) (Authenticated sender: wz) by freeshell.de (Postfix) with ESMTPSA id 04576B2C1C78; Wed, 7 Jul 2021 20:30:21 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freeshell.de; s=mail; t=1625682622; bh=sZB0Oh/7E0/n6lg5HcWJ0sqbJtiIoWlSEPAFIS5gao4=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=acO3KFVmF6xxIb6ff+SApt89/vbQ4BsxpfDjwg5+TvOnTu1kh6TpwjqN0G8n4F3Y1 D9PCC1w+ZmA2nbmobC1RUYAZGOPO0uclYk3TLfAwhhbSPO/86MYkbfD37IIxW8p2sy ib57m70ohL8mQRMUW3hXvrw1Ds2vNyIphA2uV86M= Date: Wed, 7 Jul 2021 20:30:19 +0200 From: Wiktor =?utf-8?Q?=C5=BBelazny?= To: help-guix@gnu.org Subject: Re: Typing LUKS passphrase only once and a possible solution Message-ID: <20210707183019.tafzyasnrtstptr2@wzguix> Mail-Followup-To: help-guix@gnu.org, Joshua Branson X-PGP-Key: https://freeshell.de/~wz/pubkey.asc X-PGP-Fingerprint: BDC9 74CD D9C9 BA7D 761A 573D C735 A8C6 AB60 79D5 References: <87k0m2gld3.fsf@gmail.com> <878s2i0z91.fsf@dismail.de> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="yjeg4dhfv5dufrvh" Content-Disposition: inline In-Reply-To: <878s2i0z91.fsf@dismail.de> Received-SPF: pass client-ip=2a01:4f8:231:482b::2; envelope-from=wz@freeshell.de; helo=freeshell.de X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: help-guix@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Joshua Branson Errors-To: help-guix-bounces+larch=yhetil.org@gnu.org Sender: "Help-Guix" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1625682744; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:dkim-signature; bh=sZB0Oh/7E0/n6lg5HcWJ0sqbJtiIoWlSEPAFIS5gao4=; b=lKy/sq3ipaD0Ic6xR60dVIxc342SdovnBagwmH/bEgUiIMG04udW/t76itQ3NZiQ7zvrhW E+d2rpvtl3PW+ADVlE9GyCS326TsR6QkJ0hLlQoiebrG4e4uhwZa/J0Abg+lBIM8H19mfy Nt4eLbP1ktASY3cRiVtFq+25BcyKcIRpWGPbSCMIaQMfFUPqUG3Rh6ueW+zkDXcjW7sq6t zf5Mnp0YlPMNi/nFR23NLOSVdfMt5zNIoc6trKR8exqm0s8wAcDhGcMDfRuEZ+L/Ul/XFn nchRpms+AhC5OkVeQjpmmHs37CSAZQPASu3Nd1PwBig8hbyAPZrrnkKoOgRuiA== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1625682744; a=rsa-sha256; cv=none; b=u8GqqSL+aevGziD4uJ3HUzd6rVhBBoCLgS5TtkGDevPfNr2XMjvpk6gI4gelcK1tI6ITjE V/+PxzE10cnc6RyDVHrHtwDUKLX+CTc4SMlHXswWIL0UTBA5tPJh4CZ946W2LBC5pvdOww Y2IHgMvEAypF21u7ZJifKvaafujjutAF4PDCBYK2teBOF7OsJ4Avz0O8IvM/UN9GorO9On StM/4kLXNos2YmqJGNNvqFVEnxDd9x7o1+CaLsN8aYbFOg7qu+0wBPexbBDCg4QI45adYV cTa6gfjJlfc4XKrUhGCDVTnZzslCczZcEBT9/RizK3sH5m7Tw+NfdHiAfa+0Eg== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=freeshell.de header.s=mail header.b=acO3KFVm; spf=pass (aspmx1.migadu.com: domain of help-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=help-guix-bounces@gnu.org X-Migadu-Spam-Score: -4.71 Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=freeshell.de header.s=mail header.b=acO3KFVm; dmarc=pass (policy=none) header.from=freeshell.de; spf=pass (aspmx1.migadu.com: domain of help-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=help-guix-bounces@gnu.org X-Migadu-Queue-Id: BCF151ABDA X-Spam-Score: -4.71 X-Migadu-Scanner: scn0.migadu.com X-TUID: yPUzSqgZ1T8j --yjeg4dhfv5dufrvh Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Jul 07, 2021 at 02:12:26PM -0400, Joshua Branson wrote: > I haven't figured out how to set up an encrypted /. Did you encrypt > your /boot as well!? I've got a osboot-ed T400. Hi, For full encryption, you might be interested in taking a look at the Guix System and Libreboot guide by Raghav "RG" Gururajan [1]. I=E2=80=99m n= ot sure if the solution is going to work without libreboot, though. W=C5=BB [1]: https://flossmanuals.net/pub/guix-system-and-libreboot.pdf --yjeg4dhfv5dufrvh Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEvcl0zdnJun12Glc9xzWoxqtgedUFAmDl8rpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEJE Qzk3NENERDlDOUJBN0Q3NjFBNTczREM3MzVBOEM2QUI2MDc5RDUACgkQxzWoxqtg edXGAxAArl15gcFI+J6UfT0Ag07a+0mqvZ+DNiZRc4JDN6hVQAQm9rwy3we/b2Z4 vblOc9n3rQ9d++sojEqrI9sKjSJ8zwnA8/meR5un5yaeRzR9sGzLWBBskMjI243K wzRVxM6kwi/3To613Az2uD0QvAOTS+hP9AKdRREaDmIYQwUTklkdwgVQVivDhKp2 uTL+3mSBcAdrDAcurc/S7fPS9esMzUQNUwezWU/RKxIpdnQxornDE6cV9h2kwKbc 3pwReFDE8KpBV1nN9M3ylnMCe53GVbg9H7Rc3Jp7Ax+vfVq8PvrgRw1RiexRuBlL 23T5z2xMxUZkn3QKo3LIT9BHyGyHmfUt/Ek7pJOeJoDo3ZhAYj7B0RNil6otYa5E IcOFMr+wALu/W1p6DBcCBkU+ENfOrWGNXKjAoSvnNDc8u7T2tlfqKQo98WPaCMJq MA2BRUdVlc2P/90j56QX6OKQiwxDv3ZdsgdXrPdPYzC+1WyPgPoMBiTNhPoObasz WoAOL10TwKn8Eougo2MwklvsgdcoRi8GA20j/9bU7p9Pv16bj05ZnHUbuO9Uxnkp XeZGbQSDqILKsV1Bvv9g7z/aqVHF3aZ1fYlkYayAkqZdCXCGLstSWfjTLCwiJ6Kp 2TJoAR5KAWVCc4uiR2spoT+KxLb7IQ0KSRRmvKtuPr3+rX5b2AM= =PQg2 -----END PGP SIGNATURE----- --yjeg4dhfv5dufrvh--