You are not logged in.
Hello folks,
i am into trouble. For any reason my backup did not contain my latest keepass file, so i lost the two keys to my self-build raid5-nas.
I tried this: https://unix.stackexchange.com/question … e-password
but this didnt work for me.
Is there any way to get/reset the key from my still encrypted volumes?
my root partition has one key, so has the raid, too.
lsblk + blkid
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT
sda 8:0 0 465,8G 0 disk
├─sda1 8:1 0 250M 0 part /boot
└─sda2 8:2 0 465,5G 0 part
└─main 254:0 0 465,5G 0 crypt
├─main-root 254:1 0 200G 0 lvm /
├─main-swap 254:2 0 8G 0 lvm [SWAP]
└─main-home 254:3 0 257,5G 0 lvm /home
sdb 8:16 0 3,7T 0 disk
└─sdb1 8:17 0 2,7T 0 part
└─md127 9:127 0 10,9T 0 raid5
└─archnas 254:4 0 10,9T 0 crypt
└─smartCryptArray-lvhome 254:5 0 10,9T 0 lvm /mnt/smartCryptRaid
sdc 8:32 0 2,7T 0 disk
└─sdc1 8:33 0 2,7T 0 part
└─md127 9:127 0 10,9T 0 raid5
└─archnas 254:4 0 10,9T 0 crypt
└─smartCryptArray-lvhome 254:5 0 10,9T 0 lvm /mnt/smartCryptRaid
sdd 8:48 0 2,7T 0 disk
└─sdd1 8:49 0 2,7T 0 part
└─md127 9:127 0 10,9T 0 raid5
└─archnas 254:4 0 10,9T 0 crypt
└─smartCryptArray-lvhome 254:5 0 10,9T 0 lvm /mnt/smartCryptRaid
sde 8:64 0 2,7T 0 disk
└─sde1 8:65 0 2,7T 0 part
└─md127 9:127 0 10,9T 0 raid5
└─archnas 254:4 0 10,9T 0 crypt
└─smartCryptArray-lvhome 254:5 0 10,9T 0 lvm /mnt/smartCryptRaid
sdf 8:80 0 2,7T 0 disk
└─sdf1 8:81 0 2,7T 0 part
└─md127 9:127 0 10,9T 0 raid5
└─archnas 254:4 0 10,9T 0 crypt
└─smartCryptArray-lvhome 254:5 0 10,9T 0 lvm /mnt/smartCryptRaid
/dev/sda1: LABEL="boot" UUID="aa33e75d-9248-40bd-958f-5cde065a48b3" BLOCK_SIZE="1024" TYPE="ext4" PARTUUID="f9a5291b-53ee-2844-be4a-efaef3fc97cb"
/dev/sda2: UUID="4a9b7803-9437-44af-b9c4-4fd65651e5d8" TYPE="crypto_LUKS" PARTUUID="0f79c7cc-1cbc-f34c-b630-1203fd51eff3"
/dev/sde1: UUID="c446f55b-6ff8-cbce-ee69-0b874f613e32" UUID_SUB="7b7c1d0a-8463-4f7a-ce2e-6caa8c6cae55" LABEL="archnas:archnas" TYPE="linux_raid_member" PARTLABEL="Linux RAID" PARTUUID="ca51bab9-7ee8-408d-84c3-6ab5a85ddbe1"
/dev/sdb1: UUID="c446f55b-6ff8-cbce-ee69-0b874f613e32" UUID_SUB="49032f82-beeb-6561-dcb8-8f32c3e5ebc5" LABEL="archnas:archnas" TYPE="linux_raid_member" PARTLABEL="Linux RAID" PARTUUID="831fadaa-a0c3-4ea4-b567-ebc25ae7a1d9"
/dev/sdd1: UUID="c446f55b-6ff8-cbce-ee69-0b874f613e32" UUID_SUB="606b5b3c-beda-845e-bd69-78c480ffb8cc" LABEL="archnas:archnas" TYPE="linux_raid_member" PARTLABEL="Linux RAID" PARTUUID="02016052-e0f3-48c3-86e7-7c0d87972688"
/dev/sdc1: UUID="c446f55b-6ff8-cbce-ee69-0b874f613e32" UUID_SUB="b4cc780b-12bc-0df6-3b6c-186e1df63114" LABEL="archnas:archnas" TYPE="linux_raid_member" PARTLABEL="Linux RAID" PARTUUID="ca11e7a7-7df9-4599-b361-bdebf4951b2e"
/dev/sdf1: UUID="c446f55b-6ff8-cbce-ee69-0b874f613e32" UUID_SUB="8cf1b5b8-0475-e98c-b8b0-7871fc38fc02" LABEL="archnas:archnas" TYPE="linux_raid_member" PARTLABEL="Linux RAID" PARTUUID="8933d643-3aa8-427c-affe-4579f0f5e077"
/dev/md127: UUID="b980a647-393c-44fd-9ad7-69884f9b085b" TYPE="crypto_LUKS"
/dev/mapper/main: UUID="gKZyGU-eVJY-qbk5-Girs-VFPm-JLSI-WQoVNY" TYPE="LVM2_member"
/dev/mapper/main-root: LABEL="root" UUID="9611eeaa-6b57-456f-8508-71151a169f1b" BLOCK_SIZE="4096" TYPE="ext4"
/dev/mapper/main-swap: LABEL="swap" UUID="75570ab1-0dfe-408a-a324-bd530d358a0a" TYPE="swap"
/dev/mapper/main-home: LABEL="root" UUID="b923218b-e189-4ea6-85ce-f1fb01d0b67b" BLOCK_SIZE="4096" TYPE="ext4"
/dev/mapper/archnas: UUID="6G11ew-h930-usfC-lWgW-70by-hLV9-uew7no" TYPE="LVM2_member"
/dev/mapper/smartCryptArray-lvhome: UUID="e0c1a80a-86ca-4061-8b8d-065ac41663be" BLOCK_SIZE="4096" TYPE="ext4"Thanks in advance.
Edit, the issue might be here:
dmsetup table --showkeys /dev/mapper/archnas
0 23441033216 crypt aes-xts-plain :64:logon:cryptsetup:b980a647-393c-44fd-9ad7-69884f9b085b-d0 0 9:127 32768i assume, that the syntax from the linked page requieres a different format.
Last edited by Gonzo2028 (2020-02-02 10:01:54)
Offline
It looks like it is diffuclt or impossible with LUKS2: https://gitlab.com/cryptsetup/cryptsetup/issues/453
Last edited by progandy (2020-02-02 10:22:04)
| alias CUTF='LANG=en_XX.UTF-8@POSIX ' | alias ENGLISH='LANG=C.UTF-8 ' |
Offline
i would choose difficult then.... ![]()
suggestions?
Offline
I am not familiar enough with the kernel keyring and the way it is used by cryptsetup to say whether there is a way to extract the key with e.g. "keyctl print".
| alias CUTF='LANG=en_XX.UTF-8@POSIX ' | alias ENGLISH='LANG=C.UTF-8 ' |
Offline
okay, maybe someone else might help then. for now i ll copy as much as possible and told the gf to not use any powerconsuming devices to prevent power loss. what a mess, i am such an idiot.....
the hdd where the key was has been formatted and is my encrypted home now.
but i havent zeroed it, maybe we can recover my kbdx file from it?
Offline
but i havent zeroed it, maybe we can recover my kbdx file from it?
Very unlikely. You could try PhotoRec, I think it has support to find kdbx files.
https://www.cgsecurity.org/wiki/File_Fo … y_PhotoRec
Otherwise you might be have to scan the raw disk for the kdbx file signature and manually extract it
https://gist.github.com/lgg/e6ccc6e212d … c116fb1e45
https://github.com/lgg/awesome-keepass# … d-articles
Do not mount or use the hdd in any way until you succeed or have determined that the file is not recoverable. Preferrably you create a disk image and only use that for your recovery attempts.
Last edited by progandy (2020-02-02 14:58:37)
| alias CUTF='LANG=en_XX.UTF-8@POSIX ' | alias ENGLISH='LANG=C.UTF-8 ' |
Offline