• 0 Posts
  • 2 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2023

help-circle

  • But how to get the OS to recognize it?

    My approach for doing this in Gentoo with an encrypted /home is to configure dracut to make a slightly customized initrd.

    Thanks to dracut modules, not too much configuration is needed - it prompts on boot for the password to decrypt, and then fstab is just configured to mount the decrypted uuid.

    Someone else mentioned using multiple key slots, but I think this is your only real secure option.

    Edit: on second thought, you may be able to get this to work in grub simply by adding rd.luks.uuid=xxx as a kernel boot parameter, and then having the decrypted /dev/mapper uuid in fstab for /home