From: Milan Broz <gmazyland@gmail.com>
To: hgabreu@gmail.com, dm-crypt@saout.de
Subject: Re: [dm-crypt] luks header on initramfs img
Date: Fri, 08 Aug 2014 15:22:33 +0200 [thread overview]
Message-ID: <53E4CF19.1090904@gmail.com> (raw)
In-Reply-To: <53E2FDAD.8080603@gmail.com>
On 08/07/2014 06:16 AM, Milan Broz wrote:
> On 08/07/2014 03:09 AM, Henrique Abreu wrote:
>> I use to have a setup with luks header on a separate file, as describe here:
>> https://wiki.archlinux.org/index.php/Dm-crypt/Specialties#Encrypted_system_using_a_remote_LUKS_header
>>
>> But since update from 1.6.4 to 1.6.5 it doesn't work anymore. It just keeps asking for the passphrase on and on without any error messages.
>>
>> I noticed that, if I mount a usb drive and move the header from memory to the drive, then attempt to open again with the exact same command (below) it works:
>> # cryptsetup open --header header.img --type luks /dev/sda4 lvm
>>
>> So, the difference is just where the header.img file is placed. For now, I have downgraded back to 1.6.4 to keep my boot setup simpler.
>> I rather use the header image inside initramfs if possible instead of having to mount a usb at boot just to read the header.
>>
>> Does anyone know if that's intended for not working anymore or if it's a bug?
>
> There is no reason this should not work.
> (It could be bug elsewhere as well, 1.6.5 already uncovered 2 kernel bugs...)
Should be fixed in devel git (and in 1.6.6 which will be released in a few days).
(Basically I forgot to use wrapper for device open which avoids using O_DIRECT
if not supported, like in tmpfs.)
Thanks for report!
Milan
next prev parent reply other threads:[~2014-08-08 13:22 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-08-07 1:09 [dm-crypt] luks header on initramfs img Henrique Abreu
2014-08-07 4:16 ` Milan Broz
2014-08-08 13:22 ` Milan Broz [this message]
2014-08-08 18:16 ` Henrique Abreu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=53E4CF19.1090904@gmail.com \
--to=gmazyland@gmail.com \
--cc=dm-crypt@saout.de \
--cc=hgabreu@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.