LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 10-11-2019, 04:51 PM   #1
JacekZ
Member
 
Registered: Sep 2005
Location: Notts, England
Distribution: Debian 10
Posts: 71

Rep: Reputation: 15
Debian 10: two encrypted disks with one password - entered only once?


Hi folks

I installed buster on one encrypted drive using the built in installer, and later added another one using:
- cryptsetup and
- mount
and by editing
- /etc/crypttab and
- /etc/fstab

I gave both encrypted drives the same passphrase

Buster's installation guide 7.2 says:
"you will be asked to enter the passphrase for each of these volumes during the boot"

So i'd expect to enter the passphrase twice, and indeed, this stackexchange item says how you have to work around things to only have to enter the password once.

But what's happening is that I only have to enter the password once with no work-around required.

At risk of sounding like complaining that this is too good to be true, does anyone know how this is possible? Have I done something wrong? Has Buster been improved in some undocumented way / documented somewhere else? I've done quite a bit of reading around this and can find nothing to explain.

Thanks.
 
Old 10-13-2019, 04:59 AM   #2
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Maybe the system is set up to try decrypt_keyctl first, ootb?
 
Old 10-13-2019, 07:38 AM   #3
JacekZ
Member
 
Registered: Sep 2005
Location: Notts, England
Distribution: Debian 10
Posts: 71

Original Poster
Rep: Reputation: 15
Well maybe, maybe.
looking at https://gitlab.com/cryptsetup/crypts...0-ReleaseNotes starting line 347 I can see what looks like saying that a passphrase can be stored in the kernel keyring if a cryptsetup token is set first. But is it? I didn't. And if it is set automatically, perhaps by the installer, does it work across drives? Manpage for cryptsetup echoes that tokens work across all keyslots but doesn't say if that means all slots per drive, or all across all drives. I'm still none the wiser..
 
Old 10-14-2019, 01:59 AM   #4
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
You could show us the files in question.
You could read the documentation and see what it says about built-in defaults or some such.
 
Old 10-14-2019, 09:00 AM   #5
rknichols
Senior Member
 
Registered: Aug 2009
Distribution: Rocky Linux
Posts: 4,780

Rep: Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213Reputation: 2213
I know that systems in the Red Hat family have, for years, tried any manually entered passphrase against all devices for which /etc/crypttab specifies a manual passphrase. That's actually pretty important since the passphrase dialog popup(s) during boot somehow neglect to mention the device for which a passphrase is being demanded.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Unable to find Administrators password does not recognize my login password the only password I entered at setup of Linux scholarsgold Linux - Newbie 6 01-23-2018 03:58 PM
Resizable encrypted LVM requiring just one password on boot (encrypted volume group)? Nyyr Linux - Software 9 01-24-2013 05:52 AM
[SOLVED] make system ask password for encrypted partitions only once, not for each of them? saivnoba Debian 5 06-02-2011 01:07 PM
passwd prompts for new password only once when a short password is entered powah Linux - Security 0 09-19-2007 04:20 PM
Knoppix booted once, and only once... abowling Debian 7 02-29-2004 09:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 06:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration