I have a file system on LVM inside LUKS on a 2nd SSD that I’d like to mount at boot time. The OS boots fine on the main (non-LUKS) SSD.

/etc/crypttab contains a line mapping a UUID to a name, with no keyfile.

/etc/fstab contains a line mapping /dev/LVMvg/volume to /home/special

But I’m not asked for the passphrase at boot.

I can do it manually once booted (cryptdisks_start asks for the passphrase, decrypts it, and then LVM picks up the volumes enabling me to mount /home/special.) But I’d like all this to happen early in the boot.

How can I make the early processes ask me for the crypt password?

Thanks!

  • nettie@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Thanks for your post. Yeah I’ve done encrypted OS partitions myself and it’s worked fine - it’s asked for the password. This was a bit different because I was needing something unlocked that - as far as the boot loader was concerned - was not needed for boot. I did find the solution though - see my edit in OP above.

    • printf("%s", name);@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Ah, my bad. Cool that you got it working! And while it could be the “right” way, I wonder if crypttab is the only way to do this, or if it’s possible to do decryption of a non boot volume as an option in a boot loader entry or in the kernel command line. Just thinking out loud. 🤣