From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.71) id 1Vjh0M-0006gP-02 for mharc-grub-devel@gnu.org; Thu, 21 Nov 2013 22:02:02 -0500 Received: from eggs.gnu.org ([2001:4830:134:3::10]:60569) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Vjh0B-0006eQ-RW for grub-devel@gnu.org; Thu, 21 Nov 2013 22:02:00 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Vjh03-0007FS-DH for grub-devel@gnu.org; Thu, 21 Nov 2013 22:01:51 -0500 Received: from mail-ee0-x235.google.com ([2a00:1450:4013:c00::235]:63726) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Vjh03-0007FM-5f for grub-devel@gnu.org; Thu, 21 Nov 2013 22:01:43 -0500 Received: by mail-ee0-f53.google.com with SMTP id b57so263177eek.40 for ; Thu, 21 Nov 2013 19:01:42 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=zX3TPb6exZKx4xTJ5wzRMBVq6Trc/2Rpsz+TADAiUvY=; b=j7aBzCrXv4jmNM9wypeH+1lyr16z9fLWdS5eiVPd+SChxhGoI0SQRKTIuUGFAW0ew9 urZXsciXZ3xzlD3TRtrqrgwLVQLqtQ4CS7v1kydrA9vtWLW7y2iuMgvHlbUAhUSaF9p6 dxvzNsgskOr3I/4qDJA3va3n/2KTobf8PyVj/eESyXisIZ7QYa3ZaaurrI2NjuKw54qF sfNFqjvMjoru8m7HdA1tW6AwkKkqBov8+3Eq7F1wx3eFR8klxJRBCQlHNPVZFaTH3xiM 1PliyRy9nOg7RagxsJtumzEB1vE4n3Sw4YhXVwDGKSiQENAkWWOWolUjNGpDQAPivxeA HNmA== X-Received: by 10.15.83.8 with SMTP id b8mr10091192eez.6.1385089302299; Thu, 21 Nov 2013 19:01:42 -0800 (PST) Received: from [192.168.1.121] (31-249.1-85.cust.bluewin.ch. [85.1.249.31]) by mx.google.com with ESMTPSA id 1sm75199399eeg.4.2013.11.21.19.01.40 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 21 Nov 2013 19:01:41 -0800 (PST) Message-ID: <528EC901.8000704@gmail.com> Date: Fri, 22 Nov 2013 04:01:21 +0100 From: =?UTF-8?B?VmxhZGltaXIgJ8+GLWNvZGVyL3BoY29kZXInIFNlcmJpbmVua28=?= User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20131005 Icedove/17.0.9 MIME-Version: 1.0 To: grub-devel@gnu.org Subject: Re: Keyfile Support for GRUBs LUKS References: <528BF7A9.8010702@ramses-pyramidenbau.de> <528E6058.9000608@ramses-pyramidenbau.de> In-Reply-To: <528E6058.9000608@ramses-pyramidenbau.de> X-Enigmail-Version: 1.5.1 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="----enig2IJLAVGGBIXRWRUUCRQIQ" X-detected-operating-system: by eggs.gnu.org: Error: Malformed IPv6 address (bad octet value). X-Received-From: 2a00:1450:4013:c00::235 X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list Reply-To: The development of GNU GRUB List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 22 Nov 2013 03:02:00 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) ------enig2IJLAVGGBIXRWRUUCRQIQ Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On 21.11.2013 20:34, Ralf Ramsauer wrote: > On 11/21/13 16:31, Vladimir 'phcoder' Serbinenko wrote: >> >> Why do you need offset and size options? keyfile option should be >> repeteable. The whole array would be passed down and file would be >> opened instead before reading password and concatebated with it unless= >> --no-password was specified as well. If you have remaining questions >> feel free to ask here or on IRC. >> > See man 8 cryptsetup: > / --keyfile-offset value// > // Skip value bytes at the beginning of the key file.=20 > Works with all commands that accepts key files.// > // > // --keyfile-size, -l value// > // Read a maximum of value bytes from the key file.=20 > Default is to read the whole file up to the compiled-in maximum that ca= n > be queried with --help. Supplying more data than the compiled-in maximu= m > aborts the operation.// > // > // This option is useful to cut trailing newlines, for > example. If --keyfile-offset is also given, the size count starts after= > the offset. Works with all commands that accepts key files./ >=20 Cutting trailing newlines throuch such options is IMHO inelegant and would require more scripting than we currently have. Also those options result in ambiguous syntax if you have multiple keyfiles (like geli). I think it's better to skip those options, at least for now. ------enig2IJLAVGGBIXRWRUUCRQIQ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) Comment: Using GnuPG with Icedove - http://www.enigmail.net/ iF4EAREKAAYFAlKOyRMACgkQmBXlbbo5nOucsAD/dZXSRVOaWv+sqsUF9zl9JsEh iYDWaA5ujJ55FpjYVF4A/3Wf2Zv37o4tESi2Mv7NSk6B08VDYSMu2fOH0M1qVO3P =Q689 -----END PGP SIGNATURE----- ------enig2IJLAVGGBIXRWRUUCRQIQ--