all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
* Detached LUKS header
@ 2019-11-09  3:27 elaexuotee
  2019-11-12  4:44 ` Chris Marusich
       [not found] ` <86h83dqb88.fsf@dismail.de>
  0 siblings, 2 replies; 4+ messages in thread
From: elaexuotee @ 2019-11-09  3:27 UTC (permalink / raw)
  To: help-guix

Installing GuixSD for the first time. On a ThinkPad T400s, to boot!

Anyway, is there a straightforward way to configure a mapping device for LUKS
with a detached header? Otherwise, what's the best way to go about passing
command line options to the initrd cryptsetup call?

For a little context, I like my drive to look just like random data to a third
party; however, the precence of a LUKS header pretty much defeats plausible
deniability of hosting encrypted data. Thus, detached headers.

To that end, with my current non-guix setup, I have /boot and grub sitting on
an external drive, with dracut shoving the LUKS header in the initrd. Then
crypttab references said header, so the initrd cryptsetup call Just Works TM.

If there is a better way to go about setting up a "random noise" drive, I
certainly am open to hearing suggestions! At the end of the day, I am just
looking for a way to have such a drive under GuixSD.

I haven't found anything in the manual, but if I am just missing something
obvious, then forgive the spam.

Cheers!

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2019-11-12 20:27 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-11-09  3:27 Detached LUKS header elaexuotee
2019-11-12  4:44 ` Chris Marusich
2019-11-12 20:27   ` elaexuotee
     [not found] ` <86h83dqb88.fsf@dismail.de>
2019-11-12 20:08   ` elaexuotee

Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.