LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 09-13-2020, 07:42 PM   #1
Nikosis
Member
 
Registered: Dec 2005
Location: In front of the monitor
Distribution: Slackware
Posts: 322

Rep: Reputation: 59
Full Disk Encryption Luks with USB keyfile and fallback to passphrase


I have a bit of a problem getting this to work. I have 2 key slots on my luks, one for passphrase, another for a keyfile.
here is my :

cat /etc/crypttab
Code:
sda5_crypt UUID=a928ff73-50f1-44e4-80e1-03b79905d294 UUID=341785d4-e610-49c8-b4ac-a0ec71362f21:/KLinux/keyfile.key luks,noauto,keyscript=passdev
cat /etc/fstab
Code:
# /dev/mapper/cryptolinux-cryptroot                /                       ext4                errors=remount-ro            0       1
  UUID=853af3dc-9042-4144-91d1-a58dfa95b513        /                       ext4                errors=remount-ro            0       1
# /boot was on /dev/sda1 during installation
  UUID=ef571281-d77f-4822-8786-b00c6b94dbb6        /boot                   ext4                defaults                     0       2
  /dev/mapper/cryptolinux-crypthome                /home                   ext4                defaults                     0       2
  /dev/mapper/cryptolinux-cryptswap                 none                   swap                sw                           0       0
  /dev/sr0                                                                /media/cdrom0        udf,iso9660 user,noauto      0       0
  UUID=341785d4-e610-49c8-b4ac-a0ec71362f21       /mnt/usb                 auto                user,noauto                  0       0
lsblk -o name,uuid,mountpoint
Code:
NAME                        UUID                                   MOUNTPOINT
sda                                                                
├─sda1                      ef571281-d77f-4822-8786-b00c6b94dbb6   /boot
├─sda2                                                             
└─sda5                      a928ff73-50f1-44e4-80e1-03b79905d294   
  └─sda5_crypt              jLtERN-KGRK-fasi-PWh0-BRjV-e7Ew-8UFRPM 
    ├─cryptolinux-cryptroot 853af3dc-9042-4144-91d1-a58dfa95b513   /
    ├─cryptolinux-cryptswap 2e1226c7-124f-40f5-ad7b-5eae802b4fc3   [SWAP]
    └─cryptolinux-crypthome 7b7a2296-ccea-4a02-a201-c2a78787bbb1   /home
sdb                                                                
└─sdb1                      341785d4-e610-49c8-b4ac-a0ec71362f21
after restart nothing happens though, it's just stuck on splash screen, what am I missing here?

Also on my previous install of 2020.2 I could boot it with keyfile on USB, but if usb was not present it did not fallback to passphrase option.

Did anyone get this working?

UPDATE

Now on top of everything I can't even update initramfs anymore
Code:
cryptsetup: WARNING target 'sda5_crypt' not found in /etc/crypttab
I appreciate any help
Thx

Last edited by Nikosis; 09-13-2020 at 08:07 PM.
 
Old 09-14-2020, 09:02 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,160

Rep: Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266
To find the problem, boot with debug cmdline options: remove quiet, and set log_level=6. If you have a serial line, add "console=tty0 console=ttyS0,115200n8" to send messages to the serial port. Capture the output on a separate system running miniterm or putty. I use a USB serial cable.

Typical problem is a module that is not included or not being loaded by initrd. It's best to have initrd drop to a shell when it can't mount the root filesystem.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Keyscript for ubuntu to unlock a luks partition with a keyfile and fallback to a passphrase LBuhler Ubuntu 0 04-22-2020 03:44 PM
How to have luks encryption with keyfile OR passphrase (efi full disk encryption including boot)? byroncollege Linux - Security 2 03-30-2017 07:45 AM
Mint 18 Full disk encryption VS Veracrypt Full Disk encryption: Help a Noob Decide Please ! APeacefulRig Linux - Security 2 11-11-2016 08:10 AM
Passphrase protected keyfile usbs hutyerah Slackware 21 10-03-2013 07:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 03:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration