LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-21-2012, 01:03 PM   #1
Nerd2
Member
 
Registered: Apr 2003
Location: Brissle, England
Posts: 97

Rep: Reputation: 19
Two stage encrypted boot


Hi there,

I'm after a simple way to do the following: Note I usually use Centos, so we can assume Centos throughout.

1. Boot some plain Linux distribution ("Linux 1")
2. SSH into "Linux 1"
3. Run some script, and enter some password
4. Decrypt partition 2, containing "Linux 2"
5. Boot into "Linux 2"

My problem is step 5 - I'm not sure how to do this "two stage" boot process. My initial thought was just to chroot into that enviroment, then run all the init scripts. Is this going to do anything wierd? It will also mean that any subsequent SSH access into the system will get "Linux 1", instead of "Linux 2". Any way I can effectively get rid of "linux 1" and be left with only "linux 2" running?

Thanks,
Nerd2
 
Old 03-23-2012, 04:49 AM   #2
Nerd2
Member
 
Registered: Apr 2003
Location: Brissle, England
Posts: 97

Original Poster
Rep: Reputation: 19
Solved. I was thinking of chrooting from Linux1 to Linux2, but forget that, I needed to modify the initrd. Steps were:

1) Install Centos with all partitions except /boot encrypted
2) Install dropbear and busybox.
3) Overwrite /sbin/mkinitrd with new mkinitrd (attached - stolen then tweaked from someone else)
4) /sbin/mkinitrd -f --with-dropbear --net-dev=eth0 /boot/initrd-`uname -r`.img `uname -r`

Done. Reboot and ssh access will all you to run the "unlock" script to decrypt the root partition (& others).
Attached Files
File Type: txt mkinitrd.txt (58.1 KB, 16 views)

Last edited by Nerd2; 03-23-2012 at 04:50 AM.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Changing the first boot stage of grub xeagle General 1 11-30-2007 10:16 AM
Half of my applications are broken. I am using Gentoo stage 1 on 3 nptl (stage 1.5) dragonslay Linux - Games 3 04-01-2005 05:23 PM
First stage boot loader hansi umayangan General 1 03-16-2005 09:15 PM
Stage two of boot failing! skeetnah Slackware 0 11-19-2003 05:03 PM
iptables at boot stage luoluotu Linux - General 3 03-05-2003 08:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration