Re: booting gbde-encrypted filesystem

From: Poul-Henning Kamp (phk_at_phk.freebsd.dk)
Date: 07/29/05

  • Next message: Alexander Leidinger: "Re: booting gbde-encrypted filesystem"
    To: Alexander Leidinger <Alexander@Leidinger.net>
    Date: Fri, 29 Jul 2005 13:52:40 +0200
    
    

    In message <20050729134548.1cc28dr8gg0k4k0g@netchild.homeip.net>, Alexander Leidinger writes:
    >Pawel Jakub Dawidek <pjd@freebsd.org> wrote:
    >
    >> This is not not possible with current GBDE.
    >> I've patches which allows this here:
    >>
    >> http://people.freebsd.org/~pjd/patches/gbde.patch
    >
    >I fail to see how this allows an encryted root-FS, it doesn't add gbde
    >support to boot0(ext) or to the loader. It needs access to an unencrypted
    >kernel. I don't think this is what Ronnel had in mind (overlooking the fact
    >that his suggestion to save the passphrase in the loader is insecure).

    There is a difference between loading the kernel from an encrypted volume
    (very hard!) and mounting the root filesystem from an encrypted volume
    (possible with pawels patch.

    Now of course, if your kernel has been trojaned, you're in trouble, but
    then again, most people just worry about their data if the machine gets
    stolen.

    -- 
    Poul-Henning Kamp       | UNIX since Zilog Zeus 3.20
    phk@FreeBSD.ORG         | TCP/IP since RFC 956
    FreeBSD committer       | BSD since 4.3-tahoe    
    Never attribute to malice what can adequately be explained by incompetence.
    _______________________________________________
    freebsd-hackers@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
    To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org"
    

  • Next message: Alexander Leidinger: "Re: booting gbde-encrypted filesystem"

    Relevant Pages

    • Re: booting gbde-encrypted filesystem
      ... >> This is not not possible with current GBDE. ... >I fail to see how this allows an encryted root-FS, ... >that his suggestion to save the passphrase in the loader is insecure). ... There is a difference between loading the kernel from an encrypted volume ...
      (FreeBSD-Security)
    • Re: booting gbde-encrypted filesystem
      ... I fail to see how this allows an encryted root-FS, it doesn't add gbde ... support to boot0or to the loader. ... that his suggestion to save the passphrase in the loader is insecure). ...
      (FreeBSD-Security)
    • Re: booting gbde-encrypted filesystem
      ... I fail to see how this allows an encryted root-FS, it doesn't add gbde ... support to boot0or to the loader. ... that his suggestion to save the passphrase in the loader is insecure). ...
      (freebsd-hackers)
    • Kernel Source Divergence, Security (was: booting gbde-encrypted filesystem)
      ... > There is a difference between loading the kernel from an encrypted volume ... I don't think it wise to have GBDE and GEOM subsystems which are rather ... before I post patches. ... implementation by core GEOM developers -- but even pjd isn't committing ...
      (freebsd-hackers)
    • Re: instant reboot when trying to load recent RELENG_5 kernel
      ... When the loader tries to load the kernel, ... > after reboot. ... By any chance are you defining CPUTYPE? ...
      (freebsd-current)