|
From: Heiko Z. <hz...@pr...> - 2002-04-09 20:58:48
|
On 04/09/2002 03:49:12 PM Friedrich Lobenstock wrote: >On Mon, 8 Apr 2002 21:15, Heiko Zuerker wrote: > >> I would like to keep the installation of the packages inside Initrd.= >> I planned to encrypt the tarballs of the packages, to make it harder= >> for an intruder add software after he managed to break into the >> system. Currently he has just to run tar -xzf >> /cdrom/packages/XYZ.tar.gz . > >Ok, point taken. So you're right we need LVM (just /sbin/vgscan, >/sbin/vgchange and libs) in the initrd. Ok. >> We could add only the really needed tools to initialize the LVM. >> Or we could just work with symlinks to the SHMFS. > >I suggest we put chroot on the intial ramdisk then we run the LVM >utilities chroot /dev/shm, so when we switch to the real root >everything is in place. Can you take care about that? > >BTW when you want to be more secure then we should get rid of the >/etc/initrd dir and should not rely on possibly forgable scripts. Good point. cu Heiko= |