Unlock Multiple Encrypted Volumes at Boot w/One Password?

I've set up my system to encrypt my /home and other data partitions (on two different hard drives), using LUKS and dm-crypt, but did not want to encrypt my root partition.
This has created the problem that if I want to store keyfiles to unlock the encrypted partitions and only have to enter a password once at boot, there is no encrypted partition to securely store the keyfiles on. (I don't want to use a USB key.) The problem seems to be that at the point that the system asks for the password to the first listed encrypted partition in /etc/crypttab it only unlocks that partition, but does not seem to mount it yet, so I can't store the keyfiles for the other encrypted partitions there.
I found this post (https://bbs.archlinux.org/viewtopic.php … 98#p523098) that suggests a way to store the keys in an encrypted loop partition partition stored on the root partition, then mount it with a modified version of rc.sysinit that executes a couple other scripts.
My difficulty with this solution is that I'm an end user and patching rc.sysint, creating the scripts, etc., is a little beyond me. I don't know how to do the patching. I don't really know how to create scripts. (Although I'm trying to figure it out.)
So I'm wondering if this is really the simplest solution, if I don't have an encrypted root partition? Thanks for any help.

I've set up my system to encrypt my /home and other data partitions (on two different hard drives), using LUKS and dm-crypt, but did not want to encrypt my root partition.
This has created the problem that if I want to store keyfiles to unlock the encrypted partitions and only have to enter a password once at boot, there is no encrypted partition to securely store the keyfiles on. (I don't want to use a USB key.) The problem seems to be that at the point that the system asks for the password to the first listed encrypted partition in /etc/crypttab it only unlocks that partition, but does not seem to mount it yet, so I can't store the keyfiles for the other encrypted partitions there.
I found this post (https://bbs.archlinux.org/viewtopic.php … 98#p523098) that suggests a way to store the keys in an encrypted loop partition partition stored on the root partition, then mount it with a modified version of rc.sysinit that executes a couple other scripts.
My difficulty with this solution is that I'm an end user and patching rc.sysint, creating the scripts, etc., is a little beyond me. I don't know how to do the patching. I don't really know how to create scripts. (Although I'm trying to figure it out.)
So I'm wondering if this is really the simplest solution, if I don't have an encrypted root partition? Thanks for any help.

Similar Messages

  • Controlling Multiple track volumes by moving only one fader???

    I have a 4 part harmony, 4 vocals on 4 separate tracks. I have the volume mix of the 4 vox tracks exactly how i want them to sound together. Is there any way to lock them to each other so i can move one fader to change the volume of all 4 in unison? it's getting annoying changing each track by .2db at a time to try and get the right level for the harmony as a whole. thanks in advance.

    DannyMac wrote:
    Similar question, can volume automation of a track be moved in unison with the volume of other tracks in a group? example: 3 vocal tracks in a group, all have volume automation data and all are the perfect levels with regards to one another, but i want to lower the entire vocal mix, having all the automation points for each track change by the same amount. thanks again in advance.
    Jim Frazier's suggestion works great for this: route the three tracks to a bus/aux track, and use that fader to adjust the master vocal level. It's also possible to group/select all automation points at once across multiple tracks, but I think you'll find using a fader will be easier for this.
    James
    [email protected]

  • I dont know my password to unlock iphone4 encrypted backup?

    I dont know my password to unlock iphone4 encrypted backup?

    Well no one here will know it either.  You will need to delete the backup and create another one.  Tis time if you choose to encrypt make sure you remember pw. Or you cou.ld back up without encryption

  • Unlocking Encrypted Volumes?

    Durring the bootup process i have always noticed "Unlocking Encrypted Volumes" stays "busy" like its failing? is this something to worry about?
    i have searched and searched. I dont believe i have any encrypted volumes?
    Thank You For Your Help!
    PAUL

    I used scroll lock to stop the boot process and was going to take a picture. i then relized that it is not "Unlocking Encrypted Volumes" and its "checking filesystems" that is staying [BUSY] and not switching to [DONE]. SORRY!!!!   is this ok?? the filesystems do say clean? just rather ugly.
    thanks
    ... By the way "unlocking encrypted volumes" was right above it. lol
    Last edited by paulb787 (2012-05-28 11:39:05)

  • Prevent Lion from automatically trying to mount Filevault 2 encrypted volume at startup?

    Here's what I'm trying to accomplish: I need two separate partitions, one encrypted with Filevault 2 as a primary working partition, and a second token partition as a "decoy" of sorts, containing a pretty stock install and set as the default boot volume with automatic Guest account log on.  In other words, you turn on the computer and it boots to a guaranteed sterile clean desktop.  An unsophisticated snoop thinks that's all there is.  A more-sophisticated snoop may notice that there's a second (encrypted) volume, but can't access anything without the password.
    So I did a clean install of Lion, filling the entire SSD, and then used Disk Utility to shrink the main partition and create a 14 GB secondary partition.  I then encrypted the main partition with Filevault 2 from within that logon.  Then I rebooted from the clean install USB drive and installed a second instance of Lion on the secondary partition, set up the Guest account, and then set it for auto log on.
    So far so good, however, every time I boot into what is supposed to be—to the casual observer anyway—the "decoy" OS, it helpfully throws up a big dialog box stating "Enter a password to unlock the disk '<Your Super-Secret Volume Name Here>'." which I then have to cancel.  This is hardly helpful in disguising the fact that there is another partition on the SSD.
    I've looked all over Finder's preferences and the System Preferences for a way to make this stop, but I can't seem to figure it out.  Anybody know how to keep Lion from helpfully trying to mount encrypted volumes when it loads?
    Thanks!

    FYI, similar discusion here: http://discussions.apple.com/message/15744942
    This is more of a workaround than a solution, but I ended up installing Snow Leopard to the "decoy" partition.  It has no idea what to do with the encrypted partition, so it doesn't ask.  Good enough for now I guess, but it would be nice if Apple made this configurable.

  • [solved] Unlocking luks partitions fails at boot, no prompt.

    Hello,
    I have just installed Arch and I really like it so far - I'm a convert from Ubuntu. I did face a couple of problems that I have not been able to solve and have not been able to find any solutions for anywhere. The most important one at the moment is that with my two encrypted partitions.
    Here's my fstab:
    # /etc/fstab: static file system information
    # <file system>        <dir>         <type>    <options>          <dump> <pass>
    none                   /dev/pts      devpts    defaults            0      0
    none                   /dev/shm      tmpfs     defaults            0      0
    #/dev/cdrom             /media/cd   auto    ro,user,noauto,unhide   0      0
    #/dev/dvd               /media/dvd  auto    ro,user,noauto,unhide   0      0
    #/dev/fd0               /media/fl   auto    user,noauto             0      0
    /dev/scd0 /media/dvd   udf,iso9660 user,noauto,exec,utf8 0 0
    /dev/sda3 / ext3 defaults 0 1
    /dev/sdb1 swap swap defaults 0 0
    /dev/sdb2 /home reiserfs user,owner,auto 0 0
    /dev/sda6 /home/nerd/E   reiserfs defaults 0 0
    /dev/mapper/croot /home/nerd/F ext3 defaults 0 0
    /dev/mapper/crypt /home/nerd/D ext3 defaults 0 0
    and here's my crypttab:
    crypt /dev/sda5 none
    croot /dev/sda7 none
    I have cryptsetup installed, enabled the dm-crypt and aes-i586 kernel modules, and even edited mkinitcpio and added the encrypt hook. At boot, my computer does see both of the drives, but it just doesn't prompt for passwords, what it prints out is:
    Password:!unlocking encrypted volume crypt
    command failed: No key available with this passphrase.
    I am able to mount the drives manually using cryptsetup, and the data is there. Is there any way for me to fix that? Thanks!
    Last edited by DavidR (2009-09-19 10:32:57)

    afaik, you should have 'ASK' instead of 'none' in crypttab
    edit: argh. too late again
    Last edited by bender02 (2009-09-18 19:35:37)

  • [Solved] Clone existing arch system onto dm-crypt encrypted volume

    Hi all,
    I've been playing around with full disk encryption using dm-crypt and luks, and have it working pretty well on a spare harddrive. I don't want to go through the process of re-customizing a full install again, so I was wondering if it's possible to clone my / partition from my current install to an encrypted disk?
    My end goal is to have my /boot partition on a USB thumb drive and a giant encrypted volume for the rest of the / partition (including /home).
    My current drive has a / partition and a separate /home partition.
    I'm imagining something like this:
    Set up the whole new drive as an encrypted volume, unlock it with cryptsetup and map it to /dev/mapper/root
    dd if=/dev/myOldDisk/rootPartition of=/dev/mapper/root
    delete the encrypted /boot (it came over from OldDisk but I don't want it on the new encrypted disk).
    Copy files from old home to encrypted disk's /home folder.
    Would that work? Or am I better off just copying files over from my old / folder rather than using dd?
    I appreciate any input you've got!
    -Lefty
    Last edited by LeftyAce (2014-01-06 22:41:14)

    LeftyAce wrote:Set up the whole new drive as an encrypted volume, unlock it with cryptsetup and map it to /dev/mapper/root
    dd if=/dev/myOldDisk/rootPartition of=/dev/mapper/root
    +1 to dodo3773's suggestion to use rsync, the above dd would create garbage anyway. You could dd an encrypted partition to another empty one (on the new drive), but creating and mapping a new encrypted volume first will result in a fresh encryption key. The garbage occurs since your command clones encrypted bytes incl. the old encryption header to a transparent (non-encrypted) mapper. A bit more info here.

  • In recovery mode, I cannot unlock Filevault2-encrypted Macintosh HD

    Hello!
    I boot with cmd-R to access recovery tools
    If I try to reinstall Lion or do a "checkdisk", I have to unlock Macintosh HD first.
    So the small popup appears and I enter my password
    My password is refused. No way to unlock the encrypted Macintosh HD.
    I know I type the right password because it is only 4 lowercase letters and the password is accepted when I boot in "normal" mode
    Apple, please correct this bug as soon as possible!!
    Anyone got this problem?

    The object of Filevault is so that no access is possible via any other means except the secure path laid out with a fully running OS X to ensure your data is secure. This is a very secure and limited access state intentional to supply the security provided.
    The Lion Recovery Partition is just a tiny program on a partition, the window asking for your password shouldn't have appeared at all.
    If the Lion Recovery Partition allowed a unlocking of a Filevault drive, means that that code could be easily cloned, altered and used to crack any Mac with Filevault with a simple USB key. The government snoops would be screaming if they knew this was possible.
    Filevault is a complete waste of time and effort for most users, it hogs CPU cycles, slows down one's machine and disables recovery options if OS X fails to boot as one can't decrypt the image and simply recover files using a alternative means (like Firewire Target Disk Mode for instance)
    It's better for most users to leave Filevault alone and either use a Iron Key or individual file/folder encryption software on just the items they need.
    This way if something goes wrong, the files are either off the machine or the drive can be accessed and the encrypted files/folders transferred to another Mac, decryption software installed and the correct password used to decrypt the files.
    Military and Government parnoid level total drive encryption is overkill for most regular users needs as they don't access super secure networks that require it. And since most all of those super secure networks are not on the internet, makes it inaccessible to most users anyway.
    Most users just need a folder or two encrypted, with the ability to move them to another comptuer, not their entire drives encrypted in a unmovable state.
    Also the advatage of having something like a Iron Key is that one has the files off their computer and can easily and quickly dispose of the Iron Key in a rapid manner smashing it with a hard large rock for instance and spreading the pieces around at random, or burying it in the ground for another, try doing that with a computer.
    As if you don't already know, Apple is vulnerable to government influence, they certainly have complete access to Filevault no matter what Apple says.
    A four character password?, heck I could crack that on my Mac in about 5 minutes.
    So if your not super serious about protecting your data, just want to keep snoops at pay, do the file/folder encryption or Iron Key method instead of Filevault, don't be sorry later like your sorry now that you can't repair your drive permissions or access your drive if OS X fails to boot.

  • Unix layout question  single vs. multiple logical volumes

    Hello friends,
    I have a question which I have seen various points of view. I'm hoping you might be able to give me a better insight so I can either confirm my own sanity, or accept a new paradigm shift in laying out the file system for best performance.
    Here are the givens:
    Unix systems (AIX, HP-UX, Solaris, and/or Linux).
    Hardware RAID system on large SAN (in this case, RAID-05 striped over more than 100 physical disks).
    (We are using AIX 6.1 with CIO turned on for the database files).
    Each Physical Volume is literally striped over at least physical 100 disks (spindles).
    Each Logical Volume is also striped over at least 100 spindles (all the same spindles for each lvol).
    Oracle software binaries are on their own separate physical volume.
    Oracle backups, exports, flash-back-query, etc., are on their own separate physical volume.
    Oracle database files, including all tablespaces, redo logs, undo ts, temp ts, and control files are in their own separate physical volume (that is made up of logical volumes that are each striped over at least 100 physical disks (spindles).
    The question is if it makes any sense (and WHY) to break up the physical volume that is used for the Oracle database files themselves, into multiple logical volumes? At what point does it make sense to create individual logical volumes for each datafile, or type, or put them all in a single logical volume?
    Does this do anything at all for performance? If the volumes are logical, then what difference would it to put them into individual logical volumes that are striped across the same one-hundred (+) disks?
    Basically ALL database files are in a single physical volume (LUN), but does it help (and WHY) to break up the physical volume into several logical volumes for placing each of the individual data files (e.g., separating system ts, from sysaux, from temp, from undo, from data, from indexes, etc.) if the physical volume is created on a RAID-5 (or RAID-10) disk array on a SAN that literally spans across hundreds of high-speed disks?
    If this does makes sense, why?
    From a physical standpoint, there are only 4 hardware paths for each LUN, so what difference does it make to create multiple 'logical' volumes for each datafile, or for separating types of data files?
    From an I/O standpoint, the multi-threading of the operating system should only be able to use the number of pathways that are capable based on the various operating system options (e.g., multicore CPUs using SMT (simultaneous multipath threading). But I believe they are still based on physical paths, not based on logical volumes.
    I look forward to hearing back from you.
    Thanks.
    ji li

    Thanks for your reply damorgan.
    We have dual HBAs in our servers as standard equipment, along with dual controllers.
    I totally agree with the idea of getting rid of RAID-5, but that is not my choice.
    We have a very large (massive) data center and the decision to use RAID-5 was at the discretion of our unix team some time ago. Their idea is one-size-fits-all. When I questioned it, I was balked at. After all, what do I know? I've only been a sys admin for 10 years (but on HP-UX and Solaris, not on AIX), and I've only been an Oracle DBA for nearly 20 years.
    For whatever it is worth, they also mirror their RAID-5, so in essence, it is a RAID 5-1-0 (RAID-50).
    Anyway, as for the hardware paths, from my understanding, there are only 4 physical hardware paths going from the servers to the switches, to the SAN and back. Their claim (the unix team's) is that by using multiple logical volumes within a single physical volume, that it increases the number of 'threads' to pull data from the stripe. This is the part I don't understand and may be specific to AIX.
    So if each logical volume is a stripe within a physical volume, and each physical volume is striped across more than one hundred disks, I still don't understand how multiple logical volumes can increase I/O through-put. From my understanding, if we only have four paths, and there are 100+ spindles, even if it did increase I/O somehow by the way AIX uses multipathing (SMT) with its CPUs, how can it have any affect on the I/O. And if it did, it would still have to be negligible.
    Two years ago, I've personally set up three LUNs on a pair of Sun V480s (RAC'd) connected to a Sun Storage 3510 SAN. One LUN for Oracle binaries, one for database datafiles, and one for backups and archivelogs), and then put all my datafiles in a single logical volume on one LUN, and had fantastic performance for a very intense database that literally had 12,000 to 16,000 simultaneous active* connections using Webshere connection pools. While that was a Sun system, and now I'm dealing with an AIX P6 570 system, I can't imagine the concepts being that much different, especially when the servers are basically comparable.
    Any comments or feedback appreciated.
    ji li
    Edited by: ji li on Jan 28, 2013 7:51 AM

  • Unlock + Multiple Screens

    I have a macbook pro retina and I have 3 monitors hooked up to it. I am also using the screen as a 4th display. The issue is when I unlock the computer and after putting in the password, the windows that were open are moved around on different screens. Any reason/fix for this?
    Thanks.

    A DMP connects to a single screen as it has a single HDMI output. Some monitors allow daisy chaining across multiple monitors but this a function of the monitor not the DMP.  With this option you can get the image to fit across multiple monitors like a 2x2 monitor setup.  The primary monitor connects to the DMP and then the rest of the monitors connect monitor to monitor using a HDMI cable.  You then program the main monitor for how you want the screens to show the image.
    The datasheet is referring to content can be placed in separate regions on a monitor.  This way you could have a video in one region, text/image in another and an RSS feed in a third.
    Hope this helps.

  • Password on encrypted volume not being "forgotten"

    I've set up an encrypted disk image (sparsebundle) and written a short bash script to simulate the old-style FileVault (to protect just a single account.)  It uses a folder within the encrypted volume as the home folder of an account that I use for sensitive information.  While it took a little while to get the permissions/ownership right on the volume and image, it works fine.  The other tricky part was that I have the script close the volume after it detects the account has been logged out -- I discovered I needed to wait a while for the logout to complete before closing the volume (otherwise it seemed like the system was trying to read or write from the volume even after "who" showed the account was logged out, and so it created a new home directory that confuses things.)  Now, the "problem" I have is this.  The first time the script opens the encrypted volume the system of course asks for the password.  Thereafter unless I reboot (logging in and out of the non-protected account I start the script from doesn't help) and possibly after a *long* time, tthe system seems to be remembering the password to the file -- on subsequent uses of the script the volume is opened without me being asked for the password.  I have examined carefully what I do when entering the password to make sure it's not saved in the keychain -- and indeed it isn't (verified by looking at the keychain).  Does anyone have any idea where the system (presumably the Finder) is saving the password and how to get it to "forget" it?  (I just realized I haven't checked to see if the password is "remembered" system-wide or just in the un-protected account.)  I've looked in both the system and account set of caches and nothing is obvious (all the finder cached data is in a single database, presumably in some obscure format.)
    Ted Lee
    Minnetonka, MN

    Some more experiments.  Since I was using the encrypted image to simulate FileVault, I put the image in the /User directory (which is where the old FileVault put its image for an account.)  This time I created another encrypted sparsebundle in a directory on my desktop -- the system did *not* remember the password for it (I had to enter it each time I opened it.)   More interestingly, diskutil *knew* about and remembered the image I'd put in /Users, but not the one on my desktop.  Diskutil even said that the volume inside it was an unmounted (encrypted) partition.   So it appears the system is "remembering" images that are in the /User directory -- I have no idea if there are other directories (say, /Library) where it would be remembered too.  But the "memory" has something to do with the live system -- since if I restart, the "memory" is lost.  Whether it is kept in some none-obvious place in the file system that disappears on shutdown or restart or just in virtual memory I of course don't know.

  • I have multiple albums on spotify. Today one is saying can't start station, anyone have this probl

    I have multiple albums on spotify. Today one is saying can't start station, anyone have this problem? Help...

    Hello,
         What two countries are you living in? Are certain apps you have downloaded in one country not available in the other? The only solution I can see is to start new with a new apple ID or you can use one of e two you currently have. What do you mean "And now to boot I am unable to buy anymore apps as I appear to always be on the wrong country." This could be a problem with the firmware in which a restore may be necessary. Let me know if you have any questions and good luck. Don't forget to click this helped me or solved my question if this helped you. Thanks

  • HT4436 My family has multiple iPhones.  Can we use one Apple ID for all of our phones?

    My family has multiple iPhones.  Can we use one Apple ID for all of our phones?

    If you use the same AppleID for iMessage and iCloud though, you will all be sharing the same message account and iCloud email account.  You can use a common AppleID for purchased content, but each create your own unique AppleID for iMessage and iCloud so you each have your own private accounts for those services.

  • TS3367 If I have an IPad mini and my wife has an IPad, can I connect to her IPad with FaceTime from my IPad Mini? Are multiple Apple ID's required? One for each device/person?

    If I have an IPad mini and my wife has an IPad, can I connect to her IPad with FaceTime from my IPad Mini? Are multiple Apple ID's required? One for each device/person?

    Using FaceTime http://support.apple.com/kb/ht4319
    Troubleshooting FaceTime http://support.apple.com/kb/TS3367
    The Complete Guide to FaceTime + iMessage: Setup, Use, and Troubleshooting
    http://tinyurl.com/a7odey8
    Troubleshooting FaceTime and iMessage activation
    http://support.apple.com/kb/TS4268
    Using FaceTime and iMessage behind a firewall
    http://support.apple.com/kb/HT4245
    iOS: About Messages
    http://support.apple.com/kb/HT3529
    Set up iMessage
    http://www.apple.com/ca/ios/messages/
    Troubleshooting Messages
    http://support.apple.com/kb/TS2755
    Setting Up Multiple iOS Devices for iMessage and Facetime
    http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l
    FaceTime and iMessage not accepting Apple ID password
    http://www.ilounge.com/index.php/articles/comments/facetime-and-imessage-not-acc epting-apple-id-password/
    Unable to use FaceTime and iMessage with my apple ID
    https://discussions.apple.com/thread/4649373?tstart=90
    For non-Apple devices, check out the TextFree app https://itunes.apple.com/us/app/text-free-textfree-sms-real/id399355755?mt=8
     Cheers, Tom

  • How do you select and move more than one bookmark at a time? Shift+Click does not select multiple items that are next to one another in a list because the item

    How do you select and move more than one bookmark at a time?
    Shift+Click does not select multiple items that are next to one another in a list because the items open in firefox before this happens.

    Use the bookmarks library. You may use Shift +Click, and Ctrl + Click to create groupings of selected bookmarks to drag and drop.
    * one method of opening the bookmarks library is keyboard shortcut <br /> Ctrl+Shift+B (Windows)
    *see also [[How to use bookmarks to save and organize your favorite websites]]
    *and [[Use bookmark folders to organize your bookmarks]]

Maybe you are looking for

  • How to create Source Systems in BI or RFC ??

    Hi Gurus, I want to load data from an R/3 connection to BI. Now i have modified my Datasources in R/3 side. Question is how i connect R/3 to BI ? I will have to create RFC Connection , Yes ? I did following steps , so far, PLEASE LET ME KNOW WHAT ELS

  • How to branch to the delete link in report

    Hi all, i have a report with delete button in all rows.when i click the delete button the row should get deleted. To achieve this , I have given like this.......... In the column link link text : image of the delete button link attributes : &APP_ID.

  • Is ECC 5.0 and EP 6.0 Compatibility with Oracle 10g (10.2.0.2)?

    Hi, Is ECC 5.0 and EP 6.0 are Compatibility with Oracle 10g (10.2.0.2)? Is there any blog or link to get the details on SAP Compatibility? Regards, Vamshi.

  • How to take the value as seconds place[hh.mm.ss]

    double parseTime=10; here i am getting parseTime as 10 so i should take 10 in the place of seconds place[hh.mm.ss] Ex:00.00.10 how i should take ,any help regarding this

  • Why does Premiere Pro CC keep crashing??

    I just downloaded for the first time, so it's completely up to date.  But the application keeps crashing!  Every time I look at the source files, or when I get to a certain point in the video editing (dragging a clip down to the sequence board), it f