<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=597&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Install Devuan into encrypted root and swap partitions]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=597</link>
		<description><![CDATA[The most recent posts in Install Devuan into encrypted root and swap partitions.]]></description>
		<lastBuildDate>Mon, 15 May 2017 22:25:59 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1476#p1476</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>Wow. It took me five attempts to get it right. Here&#039;s a video of manual partitioning<br />...<br /><a href="http://distro.ibiblio.org/refracta/misc/partition_encrypt-4.ogv" rel="nofollow">http://distro.ibiblio.org/refracta/misc … rypt-4.ogv</a></p></div></blockquote></div><p>I think I see now... It took you five attempts, and it took me applying workarounds instead, for my main Devuan Air-Gapped + cloned system(s).<br />But the two, first 8min of 81min video (the remaining 73min is randomizing the three volumes) and&#160; the second 4 min video, are both on another Devuan system of mine, in the works.</p><p>And thanks to your demonstration, I think I can now do it.</p><p>I think I&#039;ll soon (well, it&#039;s late now in Europe, and in your UK, if I correctly placed you in my memory)...</p><p>I think I&#039;ll soon be able to thank you for making sense out of this tips page... <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />--<br />LATER: Yes. It works! <span style="color: green">Thanks! <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /></span> I&#039;ll post the successful encrypted root+swap (and one more partition, just the /boot is unencrypted in the entire 200GB old Western Digital) screencast tomorrow I hope.</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Mon, 15 May 2017 22:25:59 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1476#p1476</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1475#p1475</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>Wow. It took me five attempts to get it right. Here&#039;s a video of manual partitioning (you can get there from non-expert as well as expert install).</p><p>Create a boot partition<br />Create a partition to be used as physical volume for encryption.<br />Uh... watch the video.</p><p>There are a lot of places where I drop the highlight down below the item I&#039;m about to select, and then move up one line and select it. Did that in case it&#039;s hard to read in the red highlight.<br /><a href="http://distro.ibiblio.org/refracta/misc/partition_encrypt-4.ogv" rel="nofollow">http://distro.ibiblio.org/refracta/misc … rypt-4.ogv</a></p></div></blockquote></div><p>I didn&#039;t know you were doing it... And I can&#039;t view it before I give the links of my videos that show where I get stuck...</p><p>Because I just minimally prepared the videos, and I like to post the sooned the more credible, when I document things:</p><p><a href="https://www.croatiafidelis.hr/foss/cap/cap-170515-encrypt-root/" rel="nofollow">https://www.croatiafidelis.hr/foss/cap/ … rypt-root/</a><br />(no HTML at the time of posting this)</p><p>But the videos (verifiable with SHA256 hashes, PGP-signed):</p><p><a href="https://www.croatiafidelis.hr/foss/cap/cap-170515-encrypt-root/S-video_H0515_2148_8of81min.webm" rel="nofollow">https://www.croatiafidelis.hr/foss/cap/ … 81min.webm</a></p><p><a href="https://www.croatiafidelis.hr/foss/cap/cap-170515-encrypt-root/S-video_H0515_2309.webm" rel="nofollow">https://www.croatiafidelis.hr/foss/cap/ … _2309.webm</a></p><p>show where I&#039;m stuck...</p><p>Got to rush (I&#039;m online, and I&#039;m not a wizard... been owned in the past), and then I&#039;ll watch your video...</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Mon, 15 May 2017 22:03:44 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1475#p1475</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1461#p1461</link>
			<description><![CDATA[<p>Wow. It took me five attempts to get it right. Here&#039;s a video of manual partitioning (you can get there from non-expert as well as expert install).</p><p>Create a boot partition<br />Create a partition to be used as physical volume for encryption.<br />Uh... watch the video.</p><p>There are a lot of places where I drop the highlight down below the item I&#039;m about to select, and then move up one line and select it. Did that in case it&#039;s hard to read in the red highlight.<br /><a href="http://distro.ibiblio.org/refracta/misc/partition_encrypt-4.ogv" rel="nofollow">http://distro.ibiblio.org/refracta/misc … rypt-4.ogv</a></p>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Mon, 15 May 2017 17:27:14 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1461#p1461</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1458#p1458</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>I can believe that encrypted install with the debian-installer failed. It is not intuitive or straightforward, but if you can find the right path through the maze, you will get to the end. Here&#039;s a guide. Unfortunately, the pictures are long gone, but the words should help you get the steps in the right order. Also, if you go to forums.debian.net and search for posts about encrypted lvm install, you will find a couple of guides.</p><p><a href="http://www.debianuserforums.org/viewtopic.php?f=9&amp;t=460&amp;sid=267a2ec218a70d97a93527b033775ccc" rel="nofollow">http://www.debianuserforums.org/viewtop … b033775ccc</a></p></div></blockquote></div><p>Read it, up unto &quot;Adding a keyfile (optional)&quot; (because in the:</p><div class="codebox"><pre><code>/usr/share/doc/cryptsetup/README.initramfs.gz</code></pre></div><p>there is great stuff that I want to re-read (and re-read till I can apply it, such as <span style="color: green">decrypt_derived</span>) first.</p><p>Maybe it&#039;s the maze, but I do think I tried the way explained in that guide, but it wouldn&#039;t work for me... Not sure, maybe I get a way to retry soon (really don&#039;t know...) and be able to tell...</p><p>Thanks for caring!</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Mon, 15 May 2017 10:39:36 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1458#p1458</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1437#p1437</link>
			<description><![CDATA[<p>I can believe that encrypted install with the debian-installer failed. It is not intuitive or straightforward, but if you can find the right path through the maze, you will get to the end. Here&#039;s a guide. Unfortunately, the pictures are long gone, but the words should help you get the steps in the right order. Also, if you go to forums.debian.net and search for posts about encrypted lvm install, you will find a couple of guides.</p><p><a href="http://www.debianuserforums.org/viewtopic.php?f=9&amp;t=460&amp;sid=267a2ec218a70d97a93527b033775ccc" rel="nofollow">http://www.debianuserforums.org/viewtop … b033775ccc</a></p>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Sun, 14 May 2017 15:56:32 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1437#p1437</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1433#p1433</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>The regular installer isos use the debian installer, so encryption is supported.</p></div></blockquote></div><p>That&#039;s what the books say. But, I tried quite a few times. Unfortunately, my Gentoo is broken currently, and I couldn&#039;t demonstrate it my usual way, with screencasts and traffic dumps while running Devuan in a VM... (And adapting my <a href="https://github.com/miroR/uncenz" rel="nofollow">uncenz</a> set of scripts for Devuan will take longer.)<br />But I assure you it was a real no go. Encrypt the partitions -- fine, but can&#039;t use them, no setting / on any of the partitions set to be encrypted... Try again. Set a partition to be / , well then you have to set some file system on it (ext4 the usual choice)... And then you can&#039;t encrypt them any more... And I didn&#039;t want to use LVM, just plain one /boot and the rest of the system all in / and one swap...</p><div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>You can encrypt individual partitions or use lvm to have multiple partitions inside one encrypted volume. For lvm, you can do it manually or let the installer do the partitioning for you.</p><p>The devuan-live isos use refractainstaller, which supports encryption of separate root and/or home partitions. It does not support lvm, and it does not support encrypted swap partition, but it can create a swapfile inside the encrypted root partition.</p></div></blockquote></div><p>It would be great if I could find time and dive into the above more... I trust your word though that it is so, but I couldn&#039;t get it to work for me.</p><p>I had to chroot into a copied content of my / partition, and run:</p><div class="codebox"><pre><code># update-initramfs -t</code></pre></div><p>from it, and only then my encrypted / (and swap as well!) were functional. (And there were more interim steps, which I can not remember in detail any more, but they were either what I found in the links or in some manpages available in Devuan installation.) And now that I compiled <a href="https://dev1galaxy.org/viewtopic.php?id=596" rel="nofollow">unoffic-grsec kernel</a>, the initrd for it is just perfect... It all set into place...</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Sun, 14 May 2017 05:30:46 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1433#p1433</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1430#p1430</link>
			<description><![CDATA[<p>The regular installer isos use the debian installer, so encryption is supported. You can encrypt individual partitions or use lvm to have multiple partitions inside one encrypted volume. For lvm, you can do it manually or let the installer do the partitioning for you.</p><p>The devuan-live isos use refractainstaller, which supports encryption of separate root and/or home partitions. It does not support lvm, and it does not support encrypted swap partition, but it can create a swapfile inside the encrypted root partition.</p>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Sat, 13 May 2017 22:41:22 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1430#p1430</guid>
		</item>
		<item>
			<title><![CDATA[Re: Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1424#p1424</link>
			<description><![CDATA[<p>For now, I&#039;ll only get readers the links, without repeating what is clearly explained in those.</p><p>First of all, installing an encrypted root+swap Devuan system may already be supported in Devuan, but I wasn&#039;t able to get it (and I made numerous tries), or if it isn&#039;t at the time of writing this how-to, it is likely to be in the future when, kind aspirant Devuaner, are reading it. Pls. check around before&#160; diving in here!</p><p>(We need not shy from our precursor&#039;s ducumentation, and they cherich it in the free way, and we need to thank them for that:)<br /><a href="https://wiki.debian.org/initramfs" rel="nofollow">https://wiki.debian.org/initramfs</a><br />needed, the key to build an encrypted root+swap Devuan system.</p><p>LINKS/NAMES OF MAN PAGES</p><p><a href="https://wiki.debian.org/InitramfsDebug" rel="nofollow">https://wiki.debian.org/InitramfsDebug</a><br />my first booting into a freshly installed partially working encrypted root+swap Devuan system was thanks to the sticking of &quot;break&quot; into kernel command line</p><p>There&#039;s also:<br /><a href="https://wiki.debian.org/CryptsetupDebug" rel="nofollow">https://wiki.debian.org/CryptsetupDebug</a><br />but it hasn&#039;t been needed (yet) in my tentatives </p><p>Here is where, allegedly by some, encrypted root+swap is available out-of-the-box:<br /><a href="https://wiki.debian.org/DebianInstaller/PartmanCrypto" rel="nofollow">https://wiki.debian.org/DebianInstaller/PartmanCrypto</a></p><p>and also Ubuntu installer claims it can do it, as I read somewhere in some links starting from this page:<br /><a href="https://help.ubuntu.com/community/EncryptedFilesystem" rel="nofollow">https://help.ubuntu.com/community/EncryptedFilesystem</a></p><p>This one is four (4) years old, but it helped me a lot to get going:<br /><a href="http://madduck.net/docs/cryptdisk/" rel="nofollow">http://madduck.net/docs/cryptdisk/</a></p><p>And there is this guide, from my other home-distro:<br /><a href="https://wiki.gentoo.org/wiki/Custom_Initramfs" rel="nofollow">https://wiki.gentoo.org/wiki/Custom_Initramfs</a></p><p>And maybe bug reports like this:<br />initramfs-tools: Missing crypto-components in initramfs when explicitly requested<br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783393" rel="nofollow">https://bugs.debian.org/cgi-bin/bugrepo … bug=783393</a></p><p>That much for now. And just: after reading the madduck&#039;s page linked above (<a href="http://madduck.net/docs/cryptdisk/" rel="nofollow">http://madduck.net/docs/cryptdisk/</a>) I slowly started figuring out how to do it...</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Sat, 13 May 2017 08:00:39 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1424#p1424</guid>
		</item>
		<item>
			<title><![CDATA[Install Devuan into encrypted root and swap partitions]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=1423#p1423</link>
			<description><![CDATA[<p>This is a placeholder. I managed to do it, and I need the link, see also:<br />Grsecurity/Pax installation on Devuan GNU/Linux<br /><a href="https://dev1galaxy.org/viewtopic.php?pid=1422#p1422" rel="nofollow">https://dev1galaxy.org/viewtopic.php?pid=1422#p1422</a></p><p>It&#039;s still partly a placeholder. Quickly, if I manage to paste from lynx... Namely I don&#039;t (yet) know where to get and how to install<br />paxctl-ng, and Iceweasel crashes yet, without paxctl{,-ng} treatment...</p><p>But, hey, I&#039;m pasting here from my Devuan! ...</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Sat, 13 May 2017 00:54:57 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=1423#p1423</guid>
		</item>
	</channel>
</rss>
