From: Konstantin Svist <fry.kun@gmail.com>
To: dm-crypt@saout.de
Subject: [dm-crypt] Encrypting swap
Date: Thu, 10 May 2012 12:50:30 -0700 [thread overview]
Message-ID: <4FAC1C06.5090109@gmail.com> (raw)
Hi,
I'm setting up Fedora 16 i686 with [luks] encrypted root on a laptop.
Problem is, I can't seem to find a way to encrypt the swap so that it
would be usable for hibernation.
* Simple setup for encrypting swap uses a random key generated on each
boot, so resuming doesn't work.
* Using the same key for swap & root is not recommended because some
tool caches the password, making the whole thing meaningless [1]
* Using a swap file doesn't work because btrfs is Copy-On-Write, so the
filesystem may get messed up by hibernate/resume process.
I'm not sure if the "same key" problem exists in Fedora 16, I've tried
setting it up this way and I'm able to boot but not resume.
Any help appreciated!
[1]
https://wiki.archlinux.org/index.php/Talk:System_Encryption_with_LUKS_for_dm-crypt#Suspend_to_disk_instructions_are_insecure
next reply other threads:[~2012-05-10 19:50 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-05-10 19:50 Konstantin Svist [this message]
2012-05-10 20:30 ` [dm-crypt] Encrypting swap Milan Broz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4FAC1C06.5090109@gmail.com \
--to=fry.kun@gmail.com \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox