Re: Delayed encrypted partition mount

2011-04-02 Thread Gilboa Davara
On Mon, 2011-03-28 at 16:23 +0200, Lennart Poettering wrote: > On Mon, 21.03.11 09:35, Bruno Wolff III (br...@wolff.to) wrote: > > > > > On Mon, Mar 21, 2011 at 16:22:59 +0200, > > Gilboa Davara wrote: > > > > > > My question is simple: Given the fact that I rarely encrypt the root, > > > can

Re: Delayed encrypted partition mount

2011-03-28 Thread Lennart Poettering
On Mon, 21.03.11 13:17, Nathanael D. Noblet (nathan...@gnat.ca) wrote: > > On 03/21/2011 12:43 PM, Richard W.M. Jones wrote: > > Off the same topic, I'd love a way to have a "key server" on my > > network that machines can grab their keys from at boot. Obviously I > > would then work on physical

Re: Delayed encrypted partition mount

2011-03-28 Thread Lennart Poettering
On Mon, 21.03.11 09:35, Bruno Wolff III (br...@wolff.to) wrote: > > On Mon, Mar 21, 2011 at 16:22:59 +0200, > Gilboa Davara wrote: > > > > My question is simple: Given the fact that I rarely encrypt the root, > > can I somehow delay the encrypted partition mount to right-before-gdm, > > so al

Re: Delayed encrypted partition mount

2011-03-23 Thread Gilboa Davara
On Mon, 2011-03-21 at 15:32 -0400, Gregory Maxwell wrote: > On Mon, Mar 21, 2011 at 10:22 AM, Gilboa Davara wrote: > > Hello all, > > > > I routinely encrypt all important partitions on my laptops / > > workstations / servers using LUKS both at home and at work. > > However, due to the above, I c

Re: Delayed encrypted partition mount

2011-03-21 Thread Gregory Maxwell
On Mon, Mar 21, 2011 at 10:22 AM, Gilboa Davara wrote: > Hello all, > > I routinely encrypt all important partitions on my laptops / > workstations / servers using LUKS both at home and at work. > However, due to the above, I can no longer remotely reboot the machines > (at least the ones that doe

Re: Delayed encrypted partition mount

2011-03-21 Thread Nathanael D. Noblet
On 03/21/2011 12:43 PM, Richard W.M. Jones wrote: > Off the same topic, I'd love a way to have a "key server" on my > network that machines can grab their keys from at boot. Obviously I > would then work on physically securing / hiding the key server so that > no one could steal it ... I think th

Re: Delayed encrypted partition mount

2011-03-21 Thread Richard W.M. Jones
Off the same topic, I'd love a way to have a "key server" on my network that machines can grab their keys from at boot. Obviously I would then work on physically securing / hiding the key server so that no one could steal it ... Rich. -- Richard Jones, Virtualization Group, Red Hat http://peopl

Re: Delayed encrypted partition mount

2011-03-21 Thread Gilboa Davara
On Mon, 2011-03-21 at 09:35 -0500, Bruno Wolff III wrote: > On Mon, Mar 21, 2011 at 16:22:59 +0200, > Gilboa Davara wrote: > > > > My question is simple: Given the fact that I rarely encrypt the root, > > can I somehow delay the encrypted partition mount to right-before-gdm, > > so all the esse

Re: Delayed encrypted partition mount

2011-03-21 Thread MichaƂ Piotrowski
Hi, 2011/3/21 Gilboa Davara : > Hello all, > > I routinely encrypt all important partitions on my laptops / > workstations / servers using LUKS both at home and at work. > However, due to the above, I can no longer remotely reboot the machines > (at least the ones that doesn't have a serial consol

Re: Delayed encrypted partition mount

2011-03-21 Thread Bruno Wolff III
On Mon, Mar 21, 2011 at 16:22:59 +0200, Gilboa Davara wrote: > > My question is simple: Given the fact that I rarely encrypt the root, > can I somehow delay the encrypted partition mount to right-before-gdm, > so all the essential services (samba, nfs, cups) - especially network > and sshd, wil

Delayed encrypted partition mount

2011-03-21 Thread Gilboa Davara
Hello all, I routinely encrypt all important partitions on my laptops / workstations / servers using LUKS both at home and at work. However, due to the above, I can no longer remotely reboot the machines (at least the ones that doesn't have a serial console attached) as I'm required to baby-sit th