Bug#774647: can't a use key file stored on an encrypted rootfs to unlock the resume device at initramfs stage

2023-03-27 Thread Christoph Anton Mitterer
Hey. I rather think now that even my hack with the swapfile isn't really save. The idea with that was that it's just the file, but not activated as swap of course. But who knows for sure that in this case the file is never moved. Anyway, @Guilhem, would you agree to close this as wontfix and

Bug#774647: can't a use key file stored on an encrypted rootfs to unlock the resume device at initramfs stage

2023-03-25 Thread Christoph Anton Mitterer
Hey. I recently considered to do the same, i.e.: - have a passphrase only for the dm-crypt encrypted rootfs - have a separate dm-crypt encrypted swap device for hibernate only - use a high-entropy key-file on the rootfs to decrypt the swap device My understanding of the initramfs-tools boot is