From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b_Rwb9oSkMm7 for ; Tue, 23 Aug 2011 14:58:01 +0200 (CEST) Received: from v4.tansi.org (ns.km33513-03.keymachine.de [87.118.94.3]) by mail.saout.de (Postfix) with ESMTP for ; Tue, 23 Aug 2011 14:58:00 +0200 (CEST) Received: from gatewagner.dyndns.org (84-74-162-232.dclient.hispeed.ch [84.74.162.232]) by v4.tansi.org (Postfix) with ESMTPA id 90B741404001 for ; Tue, 23 Aug 2011 14:58:00 +0200 (CEST) Date: Tue, 23 Aug 2011 14:57:59 +0200 From: Arno Wagner Message-ID: <20110823125759.GA21623@tansi.org> References: <4E4BFE0C.3040703@mousecar.com> <4E526C56.7080202@mousecar.com> <1314030003.2065.9.camel@scapa> <4E52D93A.10802@mousecar.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4E52D93A.10802@mousecar.com> Subject: Re: [dm-crypt] recovering forgotten passwords for 2 LVs List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On Mon, Aug 22, 2011 at 06:33:30PM -0400, ken wrote: [...] > Yves, thanks for replying. > > This setup worked fine for years without changing anything on it. I'm > fairly certain that there are two logical volumes on /dev/sda5, both > encrypted. As said, when I booted the system up, I was prompted for two > passphrases (one for each filesystem). > > > Does this tell us anything? > > # cryptsetup luksDump /dev/sda5 > LUKS header information for /dev/sda5 > > Version: 1 > Cipher name: aes [...] It does. /dev/sda5 has a LUKS container at the start with one passphrase active. For password breaking attempts, it does not matter that there are some LVM mappings. I advise to just ignore any LVM stuff for the moment and to run your password guessing attempts against /dev/sda5. You will possibly not get you data, but the password checking will be good, unless that thing was created using decrypt_derived or the like. I doubt that, as then you should have been asked only for one password. Once you have the password recovered, you should be able to do a normal boot. Arno -- Arno Wagner, Dr. sc. techn., Dipl. Inform., CISSP -- Email: arno@wagner.name GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F ---- Cuddly UI's are the manifestation of wishful thinking. -- Dylan Evans If it's in the news, don't worry about it. The very definition of "news" is "something that hardly ever happens." -- Bruce Schneier