Re: booting gbde-encrypted filesystem

From: Alexander Leidinger (Alexander_at_Leidinger.net)
Date: 07/29/05

  • Next message: Kostik Belousov: "swap reservation accounting"
    Date: Fri, 29 Jul 2005 13:45:48 +0200
    To: Pawel Jakub Dawidek <pjd@freebsd.org>
    
    

    Pawel Jakub Dawidek <pjd@freebsd.org> wrote:

    > This is not not possible with current GBDE.
    > I've patches which allows this here:
    >
    > http://people.freebsd.org/~pjd/patches/gbde.patch

    I fail to see how this allows an encryted root-FS, it doesn't add gbde
    support to boot0(ext) or to the loader. It needs access to an unencrypted
    kernel. I don't think this is what Ronnel had in mind (overlooking the fact
    that his suggestion to save the passphrase in the loader is insecure).

    Bye,
    Alexander.

    -- 
    http://www.Leidinger.net  Alexander @ Leidinger.net: PGP ID = B0063FE7
    http://www.FreeBSD.org     netchild @ FreeBSD.org  : PGP ID = 72077137
    The man who can smile when things go wrong has thought of
    someone he can blame it on.
    _______________________________________________
    freebsd-hackers@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
    To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org"
    

  • Next message: Kostik Belousov: "swap reservation accounting"

    Relevant Pages

    • Re: booting gbde-encrypted filesystem
      ... I fail to see how this allows an encryted root-FS, it doesn't add gbde ... support to boot0or to the loader. ... that his suggestion to save the passphrase in the loader is insecure). ...
      (FreeBSD-Security)
    • Re: booting gbde-encrypted filesystem
      ... >> This is not not possible with current GBDE. ... >I fail to see how this allows an encryted root-FS, ... >that his suggestion to save the passphrase in the loader is insecure). ... There is a difference between loading the kernel from an encrypted volume ...
      (freebsd-hackers)
    • Re: booting gbde-encrypted filesystem
      ... >> This is not not possible with current GBDE. ... >I fail to see how this allows an encryted root-FS, ... >that his suggestion to save the passphrase in the loader is insecure). ... There is a difference between loading the kernel from an encrypted volume ...
      (FreeBSD-Security)
    • Re: /boot/loader graphics support & extensibility
      ... It needs a different loader. ... If you want to support EFI ... which graphics functions we're talking about. ... The Forth code clearly needs a way to query the resolution ...
      (freebsd-hackers)
    • RE: application failed to initialize - Visual Studio 2005 with or with
      ... customers complaining the lack of information from OS loader. ... the explorer error dialog is the standard error message for Win32 error ... Microsoft Online Community Support ... where an initial response from the community or a Microsoft Support ...
      (microsoft.public.vsnet.debugging)