#27 Debian FDE w/ luks2 broken in 20210522

Açık
larbob tarafından 3 yıl önce kere açıldı · 4 yorum
larbob 3 yıl önce olarak yorumlandı

Following the Libreboot guide to setup Debian FDE does not result in a working install w/ Debian 10+ as luks2 is used. After cryptsetup -a is run, grub will ask for the passphrase, but instantly give an error that it is incorrect. Downgrading from luks2 to luks1 worked around the issue and the disk was able to be mounted.

Following the Libreboot guide to setup Debian FDE does not result in a working install w/ Debian 10+ as luks2 is used. After `cryptsetup -a` is run, grub will ask for the passphrase, but instantly give an error that it is incorrect. Downgrading from luks2 to luks1 worked around the issue and the disk was able to be mounted.
Leah Rowe 3 yıl önce olarak yorumlandı
Sahibi

yes, grub luks2 is still broken. technically not an issue, just need to update the documentation to reflect this. i will do so

yes, grub luks2 is still broken. technically not an issue, just need to update the documentation to reflect this. i will do so
vimuser 2 yıl önce yeniden açtı
madbehaviorus 2 yıl önce olarak yorumlandı

Please see the docs for more information.

In short:

Actually, its only the PBKDF2 key derivation function supported. Standard luks2 key derivation function is Argon2i.

Solution:

  1. change from Argon2i to PBKDF2
  2. or use luks1...
Please see the [docs](https://libreboot.org/docs/gnulinux/encrypted_debian.html#luksv2) for more information. In short: Actually, its only the PBKDF2 key derivation function supported. Standard luks2 key derivation function is Argon2i. Solution: 1. change from Argon2i to PBKDF2 2. or use luks1...
Leah Rowe 1 yıl önce olarak yorumlandı
Sahibi

still broken, but there are patches dotted about the internet. i have this on todo to fix.

still broken, but there are patches dotted about the internet. i have this on todo to fix.
madbehaviorus 1 yıl önce olarak yorumlandı

I think you mean patches to use the Argon2i key derivation function in luks2 ? Can you say why do you removed the hint to change only the key derivation? You don't need downgrade to luks1.

I think you mean patches to use the Argon2i key derivation function in luks2 ? Can you say why do you removed the hint to change only the key derivation? You don't need downgrade to luks1.
Giriş yap bu konuşmaya katılmak için.
Etiket Yok
Kilometre Taşı Yok
Atanan Kişi Yok
3 Katılımcı
Yükleniyor...
İptal
Kaydet
Henüz bir içerik yok.