You are not logged in.

#1 2019-12-26 13:57:34

xerox
Member
Registered: 2019-12-26
Posts: 2

[SOLVED] problems with setting luks + lvm + efi + sd-encrypt up

Hello and Merry Christmas to all,

maybe someone could help me with my problem. I have done a lot of research on this and unfortunately I did not get any smarter.
I'm about to set up a new Arch Linux installation.
Here's what I'd like to do:

I would like to encrypt the two hard drives with LVM on LUKS using the sd-encrypt hook.
At boot time Grub asks me for a password to decrypt my initramfs, which decrypts the rest of the disks using a keyfile, so I only have to enter the password once to decrypt both disks. I would like to use only one keyfile for both disks, preferably at the default location at /crypto_keyfile.bin.

I have followed these two tutorials:
https://wiki.archlinux.org/index.php/Dm … _initramfs
https://wiki.archlinux.org/index.php/Dm … rase_twice

Unfortunately this does not work as expected.

lsblk

sda 8:0 0 298.1G 0 disk  
└─sda1 8:1 0 298.1G 0 part  
  └─cryptlvm_hdd 253:3 0 298.1G 0 crypt 
    ├─vgHDD-var 253:4 0 15G 0 lvm   
    └─vgHDD-home 253:5 0 283.1G 0 lvm   
sdb 8:16 0 232.9G 0 disk  
├─sdb1 8:17 0 512M 0 part   --> efi boot unencrypted 
└─sdb2 8:18 0 232.4G 0 part  
  └─cryptlvm_ssd 253:6 0 232.4G 0 crypt 
    ├─vgSSD-swap 253:7 0 12G 0 lvm   
    ├─vgSSD-root 253:8 0 26G 0 lvm   
    └─vgSSD-env1 253:9 0 194.4G 0 lvm

Here are my configuration files:

/etc/crypttab

# Configuration for encrypted block devices.
# See crypttab(5) for details.

# NOTE: Do not list your root (/) partition here, it must be set up
#	beforehand by the initramfs (/etc/mkinitcpio.conf).

# <name>       <device>                                     <password>         $
# home         UUID=b8ad5c18-f445-495d-9095-c9ec4f9d2f37    /etc/mypassword1
  vgHDD        UUID=8nceKK-CPqy-KFPs-30qb-fwQg-w7az-aB99lw  /crypto_keyfile.bin$
# data2        /dev/sda5                                    /etc/cryptfs.key
# swap         /dev/sdx4                                    /dev/urandom       $
# vol          /dev/sdb7                                    none

/etc/fstab

                               
# Static information about the filesystems.
# See fstab(5) for details.

# <file system> <dir> <type> <options> <dump> <pass>
# /dev/mapper/vgSSD-root
UUID=d76b8d4d-7590-4c0c-a6e9-951afdef9e15	/               ext4           

# /dev/mapper/vgSSD-dev1
UUID=c4f6070f-49b2-4eae-8899-37c0561ed69c	/dev1           ext4           
# /dev/mapper/vgHDD-home
UUID=ccc87863-eb38-4e59-84e8-94d0e8346caa	/home           ext4           

# /dev/mapper/vgHDD-var
UUID=27b875c5-239c-4786-8e63-2802df866da1	/var            ext4           

# /dev/sdb1
UUID=2809-2A01          /efi            vfat            rw,relatime,fmask=0022

/etc/mkinitcpio.conf

                          
# vim:set ft=sh
# MODULES
# The following modules are loaded before any boot hooks are
# run.  Advanced users may wish to specify all system modules
# in this array.  For instance:
#     MODULES=(piix ide_disk reiserfs)
MODULES=()

# BINARIES
# This setting includes any additional binaries a given user may
# wish into the CPIO image.  This is run last, so it may be used to
# override the actual binaries included by a given hook
# BINARIES are dependency parsed, so you may safely ignore libraries
BINARIES=()

# FILES
# This setting is similar to BINARIES above, however, files are added
# as-is and are not parsed in any way.  This is useful for config files.
FILES=(/crypto_keyfile.bin)
               
HOOKS=(base systemd autodetect keyboard sd-vconsole modconf block sd-encrypt sd-lvm2 filesystems fsck)
                
# COMPRESSION
# Use this to compress the initramfs image. By default, gzip compression
# is used. Use 'cat' to create an uncompressed image.
#COMPRESSION="gzip"
#COMPRESSION="bzip2"
#COMPRESSION="lzma"
#COMPRESSION="xz"
#COMPRESSION="lzop"
#COMPRESSION="lz4"

# COMPRESSION_OPTIONS
# Additional options for the compressor
#COMPRESSION_OPTIONS=()

/etc/grub/default

                           

# GRUB boot loader configuration

GRUB_DEFAULT=0
GRUB_TIMEOUT=5
GRUB_DISTRIBUTOR="Arch"
GRUB_CMDLINE_LINUX_DEFAULT="loglevel=3 quiet"
GRUB_CMDLINE_LINUX="rd.luks.name=29d883a1-0a63-4645-876c-517c9bf4fdb5:cryptlvm_ssd root=/dev/vgSSD/root rd.luks.key=29d883a1-0a63-4645-876c517c9bf4fdb5=/crypto_keyfile.bin"

# Preload both GPT and MBR modules so that they are not missed
GRUB_PRELOAD_MODULES="part_gpt part_msdos"

# Uncomment to enable booting from LUKS encrypted devices
GRUB_ENABLE_CRYPTODISK=y

# Set to 'countdown' or 'hidden' to change timeout behavior,
# press ESC key to display menu.
GRUB_TIMEOUT_STYLE=menu

Last edited by xerox (2020-01-01 11:36:04)

Offline

#2 2019-12-28 23:52:04

twelveeighty
Member
Registered: 2011-09-04
Posts: 1,456

Re: [SOLVED] problems with setting luks + lvm + efi + sd-encrypt up

xerox wrote:

Unfortunately this does not work as expected.

Welcome to the forums. "It does not work" is not an error message. Please describe what you expect to see happen and (in detail) what actually happens, especially all error messages in [code] tags. Also please edit your post and change the [quote] tags to [code] tags as well.

Offline

#3 2019-12-29 11:25:11

frostschutz
Member
Registered: 2013-11-15
Posts: 1,658

Re: [SOLVED] problems with setting luks + lvm + efi + sd-encrypt up

your crypttab seems to be incorrect; 1) lines should not start with space 2) probably the wrong uuid 3) truncated line at the end (#3 might be a copy-paste-from-nano problem)

your fstab entries seem to be missing options, dump, pass values

if you want it to be active in initramfs, you should also name it crypttab.initramfs.

crypto_keyfile.bin is an invention of the regular encrypt hook, unrelated to sd-encrypt so if you want to work with keyfiles at all, you can pick any name here

is the sda device really a 300GB HDD? if so you should consider putting /home on SSD, otherwise it will slow you down

Last edited by frostschutz (2019-12-29 11:26:35)

Offline

#4 2020-01-01 11:39:09

xerox
Member
Registered: 2019-12-26
Posts: 2

Re: [SOLVED] problems with setting luks + lvm + efi + sd-encrypt up

Thanks for responding.
I used the encrypt hook instead of the sd-encrypt hook and now everything works as expected.
Thanks for the help anyway.

Offline

Board footer

Powered by FluxBB