From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1noeM9-0004Hw-3w for mharc-grub-devel@gnu.org; Wed, 11 May 2022 00:53:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:36782) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1noeM2-0004Ci-TU for grub-devel@gnu.org; Wed, 11 May 2022 00:53:43 -0400 Received: from mail-ua1-x934.google.com ([2607:f8b0:4864:20::934]:45777) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1noeM1-0005oB-Bu for grub-devel@gnu.org; Wed, 11 May 2022 00:53:42 -0400 Received: by mail-ua1-x934.google.com with SMTP id g22so334005uam.12 for ; Tue, 10 May 2022 21:53:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=efficientek-com.20210112.gappssmtp.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=+Z4pGsSJYs6A+UMUAgRaKfV0RQSpFUfxdGH+nGSlJWA=; b=vwXh66mz+jKK31I+ct6gdOUmk+OLZHTeCbMAx4T5Vicb6NsX7ocHla3f0oT+Tqw5vI Qd7kLdEWqjb9GUGyt0TYnAh06VVH3SBLbxgQcWccOKM6QipP4ZcKQMc0ngGxzLIJEdaR NNF7Yw6rLxgFbz7/Pi7VgItEGtoI35lDowCzAosKaqE6ni+hLD349XpzAMnf4vfLOSW2 e04AtnZAryYNkT/6y7/yNwRgkuO1x6zSrY6lCkjd0L1HBe+j1cqyBGykrEuPtq9d2MZi bHRByWcCJwEvIAU9yx20NC5LDkQPscZ+yb0AZbQTf2QtO8gSlOxgJwmbDnIAWHNCARyi V+WA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=+Z4pGsSJYs6A+UMUAgRaKfV0RQSpFUfxdGH+nGSlJWA=; b=T1uf4jF4A5vv66zWY4YlAZLFK1BO3ixptxkP/t/mkcjqn99W1+D0nYFtIkj8KU0Ndc r7FPLZTYmy0vmkdOLrNrvGLh+jFo2d8EwUyJqjMrKqNifN8Bq6BP3epwJX+7yewShroD rK+MVh2k8OZ6vSApbsNHU7HfhK3ccoJM0iPNwu4+GjNmfxTF0TR1O6VGVGW/tNeBDREK UPmjgINNVvgZaCIBw+rhuMIcBY3U3muWeYcHmpbNQj03czyVP9tcLvF2os+ODYvrnIC1 jGFryFULvAil6MJ+I2iTusMNvsqs6SXWJCYqDNmBd2ym81nBVNR+EvEnkr7NDlJlHUz2 zQNg== X-Gm-Message-State: AOAM5335tax9KYaknd5VwFQVzagA+sacKwU7vC7FGi0Tqw0H8lNnlrKL 3PM+SnFo4+qQGLuIRnlFnp7z6mGs/VrBfC0T X-Google-Smtp-Source: ABdhPJxbWPrWhxduSBTlhoQzo7GG4pVCt46aUrfGNpTORHZdzsdWEZYn5OnCmV8sgo9lWTRiL6EtYQ== X-Received: by 2002:a9f:3084:0:b0:360:1fa1:6aca with SMTP id j4-20020a9f3084000000b003601fa16acamr12833041uab.57.1652244820008; Tue, 10 May 2022 21:53:40 -0700 (PDT) Received: from localhost.localdomain ([37.218.244.249]) by smtp.gmail.com with ESMTPSA id o75-20020a9f3551000000b0036510b0d45csm169239uao.10.2022.05.10.21.53.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 10 May 2022 21:53:39 -0700 (PDT) From: Glenn Washburn To: grub-devel@gnu.org, Daniel Kiper Cc: Denis 'GNUtoo' Carikli , Patrick Steinhardt , John Lane , Glenn Washburn Subject: [PATCH 3/3] docs: Add documentation on detached header option to cryptomount Date: Tue, 10 May 2022 23:53:09 -0500 Message-Id: <393b087d89cd5534a72ecdb4164e78e95bc0a214.1652242759.git.development@efficientek.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=2607:f8b0:4864:20::934; envelope-from=development@efficientek.com; helo=mail-ua1-x934.google.com X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 May 2022 04:53:43 -0000 Signed-off-by: Glenn Washburn --- docs/grub.texi | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/docs/grub.texi b/docs/grub.texi index 8d1536c4d..9437b46a5 100644 --- a/docs/grub.texi +++ b/docs/grub.texi @@ -4356,19 +4356,26 @@ Alias for @code{hashsum --hash crc32 arg @dots{}}. See command @command{hashsum} @node cryptomount @subsection cryptomount -@deffn Command cryptomount [ [@option{-p} password] | [@option{-k} keyfile [@option{-O} keyoffset] [@option{-S} keysize] ] ] device|@option{-u} uuid|@option{-a}|@option{-b} +@deffn Command cryptomount [ [@option{-p} password] | [@option{-k} keyfile [@option{-O} keyoffset] [@option{-S} keysize] ] ] [@option{-H} file] device|@option{-u} uuid|@option{-a}|@option{-b} Setup access to encrypted device. A passphrase will be requested interactively, if neither the @option{-p} nor @option{-k} options are given. The option @option{-p} can be used to supply a passphrase (useful for scripts). Alternatively the @option{-k} option can be used to supply a keyfile with options @option{-O} and @option{-S} optionally supplying the offset and size, -respectively, of the key data in the given key file. - +respectively, of the key data in the given key file. The @option{-H} options can +be used to supply cryptomount backends with an alternative header file (aka +detached header). Not all backends have headers nor support alternative header +files (currently only LUKS1 and LUKS2 support them). Argument @var{device} configures specific grub device (@pxref{Naming convention}); option @option{-u} @var{uuid} configures device with specified @var{uuid}; option @option{-a} configures all detected encrypted devices; option @option{-b} configures all geli containers that have boot flag set. +Devices are not allowed to be given as key files nor as detached header files. +However, this limitation can be worked around by using blocklist syntax. So +for instance, @code{(hd1,gpt2)} can not be used, but @code{(hd1,gpt2)0+} will +achieve the desired result. + GRUB suports devices encrypted using LUKS, LUKS2 and geli. Note that necessary modules (@var{luks}, @var{luks2} and @var{geli}) have to be loaded manually before this command can be used. For LUKS2 only the PBKDF2 key derivation -- 2.34.1