|
From: <hz...@pr...> - 2003-11-30 19:37:42
|
On 11/29/2003 09:57:46 PM Diego Torres wrote: >On Sat, Nov 29, 2003 at 02:56:33PM -0800, Dean Nedelman wrote: > >> Diego - what are you proposing? To have the DL ISO image be AES >encrypted, >> or to allow users to create AES encrypted file systems? > >hope this clarifies some points about AES. > >the loop-aes module is built instead the loop kernel module. it has the >same >functionality PLUS being capable supporting AES encryption calls. (so >it can >be used for encrypting filesystems also). > >i don't want to make the dl iso aes encrypted. this won't add any value >to dl. > >i want loop-aes so i may create encrypted filesystems on a hard disk >(through >a loopback module or on the whole filesystem). for example, per user >encrypted >home directories. I personally think it's a good idea to include it. We have to ensure that the new loop fs really is compatible with the old one. One thing has to be clear when you guys want to use a encrypted loop fs: you have to enter the password during bootup, otherwise it doesn't make any sense ! So if you guys want to include it, ensure all the above works fine with the current 1.1 series and then go ahead. Heiko |
|
From: <hzu...@ra...> - 2003-12-01 19:30:33
|
On 11/30/2003 08:36:00 PM Diego Torres wrote: >On Sun, Nov 30, 2003 at 02:28:10PM -0500, hz...@pr... wrote: > >> I personally think it's a good idea to include it. >> We have to ensure that the new loop fs really is compatible with the >old >> one. > >yes, that's what i'm doing now. i'm facing a couple of problems. now >that >loop is compiled as a module, it has to be included in the initrd image >(for the normal bootup process). it's the first time i'm doing such a >thing :) Oh that's very confusing at the beginning, when I just think back until we had the first working version. But that's just something you're never working on a "normal" Linux box. >> One thing has to be clear when you guys want to use a encrypted loop >fs: >> you have to enter the password during bootup, otherwise it doesn't >make any >> sense ! > >well, currently with a per-user encrypted home, the password is asked >when the >user logs in. there is a small .bash_rc file that mounts the encrypted >image >on the home directory, and umounts it when logging out. That's not bad, but that only works with SSH or console logins, correct? >> So if you guys want to include it, ensure all the above works fine >with the >> current 1.1 series and then go ahead. > >i'm testing it. i'll ask for help on a couple of days ;) btw, we need >loop-AES >v1.7 because it has the patches for the 2.4.22 kernel, and a small diff >from >loop-AES v2.0b to patch util-linux 2.12. hope that isn't a problem. Is v2.0b only for 2.6 Kernels ? Heiko |
|
From: Diego T. <dt...@co...> - 2003-12-01 19:44:35
|
On Mon, Dec 01, 2003 at 02:20:44PM -0500, hzu...@ra... wrote: > Oh that's very confusing at the beginning, when I just think back until we > had the first working version. time passes very quickly :) > >user logs in. there is a small .bash_rc file that mounts the encrypted > >image > >on the home directory, and umounts it when logging out. > > That's not bad, but that only works with SSH or console logins, correct? right. but also you could make samba to work with this. i think there are a couple of options regarding shell scripts running just before a log-in (when the users authenticates) > >i'm testing it. i'll ask for help on a couple of days ;) btw, we need > >loop-AES > >v1.7 because it has the patches for the 2.4.22 kernel, and a small diff > >from > >loop-AES v2.0b to patch util-linux 2.12. hope that isn't a problem. > > Is v2.0b only for 2.6 Kernels ? no, it has 2.4.23 support, but is not compatible with 2.4.22, it doesn't patch cleanly, 4 or 5 rejects). -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dt...@co... - Madrid / España |
|
From: Diego T. <dt...@co...> - 2003-12-01 19:50:09
|
On Mon, Dec 01, 2003 at 02:20:44PM -0500, hzu...@ra... wrote: loop-aes support is now working. i was going to make the commit to the cvs, but i need that someone upload the following files to the mirror: http://www.anthalia.com/util-linux-2.12.diff.bz2 http://loop-aes.sourceforge.net/loop-AES/loop-AES-v1.7e.tar.bz2 because without them, compilation breaks. i've updated linuxrc (oneline, modprobe loop), and added the loop-AES script. Also the loop device from the kernel is now de-selected. loop-AES provides its own loop.o module, that is fully compatible with the kernel loop. you can find more information about performance and useful advices here: http://loop-aes.sourceforge.net/loop-AES.README -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dt...@co... - Madrid / España |
|
From: <hzu...@ra...> - 2003-12-01 19:54:57
|
On 12/01/2003 02:44:10 PM Diego Torres wrote: >On Mon, Dec 01, 2003 at 02:20:44PM -0500, hzu...@ra... >wrote: > >> Oh that's very confusing at the beginning, when I just think back >until we >> had the first working version. > >time passes very quickly :) Too quickly for my taste ;-) >> >user logs in. there is a small .bash_rc file that mounts the >encrypted >> >image >> >on the home directory, and umounts it when logging out. >> >> That's not bad, but that only works with SSH or console logins, >correct? > >right. but also you could make samba to work with this. i think there >are >a couple of options regarding shell scripts running just before a log-in >(when the users authenticates) Sounds interesting. >> >i'm testing it. i'll ask for help on a couple of days ;) btw, we need >> >loop-AES >> >v1.7 because it has the patches for the 2.4.22 kernel, and a small >diff >> >from >> >loop-AES v2.0b to patch util-linux 2.12. hope that isn't a problem. >> >> Is v2.0b only for 2.6 Kernels ? > >no, it has 2.4.23 support, but is not compatible with 2.4.22, it doesn't >patch cleanly, 4 or 5 rejects). I just downloaded the patch from 2.4.23, I will start working on the update over the next days. I'm just a bit handikapped, since I have to boot windows in order to get into the Internet... Heiko |
|
From: <hzu...@ra...> - 2003-12-02 13:01:24
|
On 12/01/2003 02:49:30 PM Diego Torres wrote: >On Mon, Dec 01, 2003 at 02:20:44PM -0500, hzu...@ra... >wrote: > >loop-aes support is now working. i was going to make the commit to the >cvs, >but i need that someone upload the following files to the mirror: > >http://www.anthalia.com/util-linux-2.12.diff.bz2 >http://loop-aes.sourceforge.net/loop-AES/loop-AES-v1.7e.tar.bz2 Bruce ? My dial up line here sucks..... >because without them, compilation breaks. i've updated linuxrc (oneline, >modprobe loop), and added the loop-AES script. Also the loop device from >the kernel is now de-selected. loop-AES provides its own loop.o module, >that is fully compatible with the kernel loop. Cool. Damned, I can't update from CVS for the next 2 weeks..... >you can find more information about performance and useful advices here: > >http://loop-aes.sourceforge.net/loop-AES.README Downloaded, I'll read it later. Heiko |
|
From: Bruce S. <bw...@ar...> - 2003-12-02 13:33:54
|
> >loop-aes support is now working. i was going to make the commit to the > >cvs, but i need that someone upload the following files to the mirror: > > > >http://www.anthalia.com/util-linux-2.12.diff.bz2 > >http://loop-aes.sourceforge.net/loop-AES/loop-AES-v1.7e.tar.bz2 > > Bruce ? My dial up line here sucks..... No problem, they are on the server now (for 1.1). - BS |
|
From: Diego T. <dt...@co...> - 2003-12-01 01:36:33
|
On Sun, Nov 30, 2003 at 02:28:10PM -0500, hz...@pr... wrote: > I personally think it's a good idea to include it. > We have to ensure that the new loop fs really is compatible with the old > one. yes, that's what i'm doing now. i'm facing a couple of problems. now that loop is compiled as a module, it has to be included in the initrd image (for the normal bootup process). it's the first time i'm doing such a thing :) > One thing has to be clear when you guys want to use a encrypted loop fs: > you have to enter the password during bootup, otherwise it doesn't make any > sense ! well, currently with a per-user encrypted home, the password is asked when the user logs in. there is a small .bash_rc file that mounts the encrypted image on the home directory, and umounts it when logging out. > So if you guys want to include it, ensure all the above works fine with the > current 1.1 series and then go ahead. i'm testing it. i'll ask for help on a couple of days ;) btw, we need loop-AES v1.7 because it has the patches for the 2.4.22 kernel, and a small diff from loop-AES v2.0b to patch util-linux 2.12. hope that isn't a problem. -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dt...@co... - Madrid / España |