Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Detached LUKS headers on USB flash, bad idea?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
389292
Guru
Guru


Joined: 26 Mar 2019
Posts: 504

PostPosted: Wed Apr 10, 2019 5:50 pm    Post subject: Detached LUKS headers on USB flash, bad idea? Reply with quote

I've read here that if you detach your LUKS header, you shouldn't really unmount that drive (with the header) after boot, is it true? Shouldn't it stay in memory while the drive is mounted? I don't plan to use hibernation or any kind of sleep function.

Last edited by 389292 on Wed Apr 10, 2019 10:06 pm; edited 1 time in total
Back to top
View user's profile Send private message
Ant P.
Watchman
Watchman


Joined: 18 Apr 2009
Posts: 6920

PostPosted: Wed Apr 10, 2019 8:54 pm    Post subject: Reply with quote

The cryptsetup package, as the name hints, is only really used to set up the in-kernel encryption stuff and load the keys/metadata used to make the container mountable. You can double-check this for yourself using tools like fuser(1) on the header device - it shouldn't show anything holding an open filehandle to the header.
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23064

PostPosted: Thu Apr 11, 2019 1:59 am    Post subject: Reply with quote

That claim, with no supporting evidence that I can see, is the first I have heard of it being a problem. The same person goes on to say that you should not mix LUKS with LVM, again without a good description of why to avoid this. I generally see LUKS+LVM proposed as the preferred way to handle LUKS, since it minimizes the number of unique password prompts while still granting you multiple independent filesystems inside the container. Without a more precise description of what happened and why, I am not inclined to accept either of those claims.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum