Re: Encrypting swap



On 05/03/2012 12:52 PM, Konstantin Svist wrote:
On 05/03/2012 12:04 PM, Heinz Diehl wrote:
On 03.05.2012, Konstantin Svist wrote:

Problem is, I can't seem to find a way to encrypt the swap so that it would
be usable for hibernation.
Have you looked at "luksSuspend" and "luksResume"?

I've only seen them as crytsetup options.. I'll google for those..


I'm not sure if the "same key" problem exists in Fedora 16, I've tried
setting it up this way and I'm able to boot but not resume.
Simply, you can't suspend the device which contains the cryptsetup
binary.

That's silly. Grub loads initramfs from an unencrypted /boot partition; initramfs knows about encryption and is able to mount root after I enter my key. There should be no technical reason why it can't mount the swap with the same key immediately after and tell kernel to resume from the now-available swap.


I see now - what you said applies to luksSuspend/luksResume. I'm guessing it should probably reside on /boot or inside initramfs for that reason...
From what I can tell, these commands work for an encrypted separate partition, e.g. /home, probably not so much for the whole disk. And/or they should generally be called by other tools, abstracted from the user.


--
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines
Have a question? Ask away: http://ask.fedoraproject.org


Relevant Pages

  • Re: Encrypting swap
    ... be usable for hibernation. ... setting it up this way and I'm able to boot but not resume. ... initramfs knows about encryption and is able to mount root after I enter my key. ... There should be no technical reason why it can't mount the swap with the same key immediately after and tell kernel to resume from the now-available swap. ...
    (Fedora)
  • Re: Network booting with PXE
    ... > drive into one of them for swap, as NFS swap is a bit slow, it hangs for ... > Mounting root from nfs: ... > I'd like to know if there is a way to not try to mount root on local disks ... how much RAM do you have in those machines? ...
    (freebsd-questions)
  • Re: swsusp: allow resume from initramfs
    ... >> where swap is on a logical volume. ... In that case, the initramfs needs to ... > a little more closely - perhaps we can get some shared code going that ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: How to disable a Ram Swap permanently
    ... I have now updated my initramfs and have removed ... the compcache (Ram Swap) permanently. ... However, using "swapon -s", it still tells me that my Swap Partition ... Does this negative priority hurt? ...
    (Ubuntu)
  • Re: One or Four?
    ... It has always been FreeBSD's default to create four partitions and swap ... I have had bad experiences with Windows running all on a single partition including swap. ... It does not matter if it is just full or damages for some other reason. ... How should it be possible to mount root as read only if root contains /usr? ...
    (freebsd-questions)