[gentoo-user] Initrd-script questions

2008-03-18 Thread Florian Philipp
Hi list! I'd like to have some advice on my situation: I have a custom init-script (derived from genkernel). What it already does is to let gpg ask for a passphrase to decrypt a file on /boot and then to use to content of that file as the key to a LUKS-formatted swap (logical volume) which is

Re: [gentoo-user] Initrd-script questions

2008-03-18 Thread Neil Bothwick
On Tue, 18 Mar 2008 17:56:30 +0100, Florian Philipp wrote: Third idea: Using a dedicated volume for storing the plaintext key. Cumbersome, doesn't reduce the risk that srm isn't enough to protect the key. You could use an encrypted volume to store the key. Your init script asks for the key