unofficial mirror of help-guix@gnu.org 
 help / color / mirror / Atom feed
* Detached LUKS header
@ 2019-11-09  3:27 elaexuotee
  2019-11-12  4:44 ` Chris Marusich
       [not found] ` <86h83dqb88.fsf@dismail.de>
  0 siblings, 2 replies; 4+ messages in thread
From: elaexuotee @ 2019-11-09  3:27 UTC (permalink / raw)
  To: help-guix

Installing GuixSD for the first time. On a ThinkPad T400s, to boot!

Anyway, is there a straightforward way to configure a mapping device for LUKS
with a detached header? Otherwise, what's the best way to go about passing
command line options to the initrd cryptsetup call?

For a little context, I like my drive to look just like random data to a third
party; however, the precence of a LUKS header pretty much defeats plausible
deniability of hosting encrypted data. Thus, detached headers.

To that end, with my current non-guix setup, I have /boot and grub sitting on
an external drive, with dracut shoving the LUKS header in the initrd. Then
crypttab references said header, so the initrd cryptsetup call Just Works TM.

If there is a better way to go about setting up a "random noise" drive, I
certainly am open to hearing suggestions! At the end of the day, I am just
looking for a way to have such a drive under GuixSD.

I haven't found anything in the manual, but if I am just missing something
obvious, then forgive the spam.

Cheers!

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2019-11-12 20:27 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-11-09  3:27 Detached LUKS header elaexuotee
2019-11-12  4:44 ` Chris Marusich
2019-11-12 20:27   ` elaexuotee
     [not found] ` <86h83dqb88.fsf@dismail.de>
2019-11-12 20:08   ` elaexuotee

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).