From: Tommaso <elisapippo@tiscali.it>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] Help: after crypttab modify > begin: waiting for root file system
Date: Wed, 02 Sep 2009 12:43:25 +0200 [thread overview]
Message-ID: <4A9E4C4D.3020701@tiscali.it> (raw)
In-Reply-To: <20090901093425.GD6333@resivo.wgnet.de>
Jonas Meurer wrote:
> yes, that's exactly what passdev is meant for.
Problem solved indeed, passdev works :)
> that really sounds weird. if the unlocked device _is_ the same for both
> passphrases, then it will behave similar. thus i don't see how issues
> with network should be related to the used keyslot.
Ok, maybe I got it, but maybe you won't like the answer.
The error I was getting with the new passphrase was:
ADDRCONF(NETDEV_UP): eth1: link is not ready
I found many topics about, and I discovered that this is an issue of a
bad renaming of the network interfaces, see i.e.
http://marc.info/?l=debian-user&m=114369893509924&w=2
In fact I have two NICs on the server, one of which (eth0) is not used
(hasn't got even a cable). So it seems that, due to the dynamic
remapping of the interfaces at boot, if I insert the old passphrase the
interface names are right, but if I change the passphrase, probably
because of some kind of variation in the entropy pattern of the system,
the names are swapped. I solved this issue installing ifrename and
managing the interfaces name according to their MAC.
HOWEVER: if this is the case (that is, if the cause of the name swapping
is due to the passphrase inserted for cryptsetup), I believe it's not a
good thing. It would indicate some kind of fixed entropy pattern
variation according to a given passphrase, probably not a desiderable
behaviour in regard to the security of encrypted filesystems.
I also addressed this issue on
http://forums.debian.net/viewtopic.php?f=10&t=44690
Thank you :)
prev parent reply other threads:[~2009-09-02 10:43 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-08-30 22:49 [dm-crypt] Help: after crypttab modify > begin: waiting for root file system Tommaso
2009-09-01 1:13 ` Jonas Meurer
2009-09-01 9:17 ` Tommaso
2009-09-01 9:34 ` Jonas Meurer
2009-09-02 10:43 ` Tommaso [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4A9E4C4D.3020701@tiscali.it \
--to=elisapippo@tiscali.it \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.