From: Pablo Castellano <pablo@anche.no>
To: ecryptfs@vger.kernel.org
Subject: Re: Way to decrypt an encrypted /home
Date: Tue, 21 Apr 2015 10:57:54 +0000 (UTC) [thread overview]
Message-ID: <loom.20150421T114722-828@post.gmane.org> (raw)
In-Reply-To: CAHTahaZ262EtzX+sZ013rfR0JvwK+zmzJCy+yusEYjR+nKehhw@mail.gmail.com
Marc de Verdelhan <mdeverdelhan <at> gmail.com> writes:
> [...]
> What I'm wondering is: What if a user (for instance: me) has a v2
> wrapped-passphrase file but try to mount its encrypted directory with
> a version of ecryptfs-utils inferior to v104? Did you consider this
> case?
> After this adventure I can say that returning "ERROR: Your passphrase
> is incorrect" when you run a "ecryptfs-mount-private" in that kind of
> configuration may get some users to think they really have an
> incorrect password and to give up, loosing their data.
> At [the very] least you should put a very big warning on
> http://ecryptfs.org/ to inform all the users in that situation (which
> may occur again since Debian Stable has the version 99-1 of
> ecryptfs-utils (https://packages.debian.org/stable/misc/ecryptfs-utils)
> and is still maintained).
>
I have experienced this same issue today.
I had ubuntu 14.04 with ecryptfs-utils 104-0ubuntu1.14.04.3.
I reinstalled Linux Mint 17 in / and kept /home.
As the installation ships with ecryptfs-utils 104-0ubuntu1 and my home
actually had the rewrapped version using a random salt, it was saying my
passphrase was incorrect and made me very nervous.
Fortunately I upgraded all the packages and after reboot everything was fine
again.
prev parent reply other threads:[~2015-04-21 11:15 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-04-01 7:52 Way to decrypt an encrypted /home Marc de Verdelhan
2015-04-01 14:42 ` Tyler Hicks
2015-04-03 12:48 ` Marc de Verdelhan
2015-04-21 10:57 ` Pablo Castellano [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=loom.20150421T114722-828@post.gmane.org \
--to=pablo@anche.no \
--cc=ecryptfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox