From linux-crypto-bounce@nl.linux.org Fri Apr 01 14:36:50 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHLOJ-0005An-G1; Fri, 01 Apr 2005 14:36:47 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Fri, 01 Apr 2005 14:36:06 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHLNU-00058u-K6
	for linux-crypto@nl.linux.org; Fri, 01 Apr 2005 14:35:56 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id B93C25080A8
	for <linux-crypto@nl.linux.org>; Fri,  1 Apr 2005 14:36:11 +0200 (CEST)
Date: Fri, 1 Apr 2005 14:35:45 +0200
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Partitions on loopback
Message-ID: <20050401143545.4bc20196@insula.localdomain>
In-Reply-To: <20050330235650.GC12080@black-sun.demon.co.uk>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Received-SPF: 
X-Spam-Status: No, score=0.0 required=5.0 tests=BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Hi all!

I've been spending several hours looking at ways to encrypt my computer.
I've read the Disc Encryption HOWTO and loop-aes readme but can't find
any information about how to partition up a loopback device with
partitions larger than 2GB. I have understood this should be easier with
kernel 2.6 but don't know anything more about it.

Are there any comprehensive guides on partitioning a to be encrypted
loopback device (device backed)? Or does anyone have any other tips?

For the record all I really want is a disc that is 100% totally
encrypted no partition tables showing or anything.


-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Fri Apr 01 15:37:56 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHMLT-0000Vw-6s; Fri, 01 Apr 2005 15:37:55 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Fri, 01 Apr 2005 15:37:32 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHMKj-0000Qu-Uj
	for linux-crypto@nl.linux.org; Fri, 01 Apr 2005 15:37:09 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 1872727619D;
	Fri,  1 Apr 2005 16:37:00 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 27758-12; Fri,  1 Apr 2005 16:36:53 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 1DCCD2C48F;
	Fri,  1 Apr 2005 16:36:53 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DHMKS-00017E-00; Fri, 01 Apr 2005 16:36:52 +0300
Message-ID: <424D4E74.7481464E@users.sourceforge.net>
Date: Fri, 01 Apr 2005 16:36:52 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r8 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk> <20050401143545.4bc20196@insula.localdomain>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> I've been spending several hours looking at ways to encrypt my computer=
.
> I've read the Disc Encryption HOWTO and loop-aes readme but can't find
> any information about how to partition up a loopback device with
> partitions larger than 2GB. I have understood this should be easier wit=
h
> kernel 2.6 but don't know anything more about it.

loop-AES has supported 64 bit device offsets and sizelimits since Novembe=
r
29 2003. No 2GB limit on 2.4 or 2.6 kernels.

> Are there any comprehensive guides on partitioning a to be encrypted
> loopback device (device backed)? Or does anyone have any other tips?
>=20
> For the record all I really want is a disc that is 100% totally
> encrypted no partition tables showing or anything.

You can use unpartitioned device /dev/hda and set up loop devices using
offset and sizelimit. If 'sfdisk -l -uS /dev/hda' says:

Units =3D sectors of 512 bytes, counting from 0
   Device Boot    Start       End  #sectors  Id  System
/dev/hda1   *        63     48194     48132  83  Linux
/dev/hda2         48195  11245499  11197305  83  Linux
/dev/hda3      11245500  12273659   1028160  82  Linux swap

And if you were to set up above three partitions as encrypted loop device=
s,
then you could issue these losetup commands:

losetup -e AES128 -K foo1.gpg -o @32256      -s 24643584   /dev/loop1 /de=
v/hda
losetup -e AES128 -K foo2.gpg -o @24675840   -s 5733020160 /dev/loop2 /de=
v/hda
losetup -e AES128 -K foo3.gpg -o @5757696000 -s 526417920  /dev/loop3 /de=
v/hda

Offset and sizelimit need to be specied in bytes. Offset is partition sta=
rt
* 512, and sizelimit is #sectors * 512. The @ character in front of offse=
t
is needed to remove the offset from IV computations.

For encrypted root, you can specify -o and -s losetup options to
build-initrd.sh script if you redefine the meaning of PSEED option.
Like this:

CRYPTROOT=3D/dev/hda
PSEED=3D"-o @32256 -s 24643584"

Normal file system mounts can use offset=3D and sizelimit=3D mount option=
s in
/etc/fstab file. Mount program understands them, but swapon program does
not. So, for partition-table-less encrypted swap you must use losetup
program with -o and -s options.

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sat Apr 02 00:18:07 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHUSr-0006WD-7n; Sat, 02 Apr 2005 00:18:05 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sat, 02 Apr 2005 00:17:35 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHUS5-0006VQ-C4
	for linux-crypto@nl.linux.org; Sat, 02 Apr 2005 00:17:17 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id D6A035080BC
	for <linux-crypto@nl.linux.org>; Sat,  2 Apr 2005 00:17:32 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <424D4E74.7481464E@users.sourceforge.net>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
	<424D4E74.7481464E@users.sourceforge.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20050401221732.D6A035080BC@mailrelay1.bredband.net>
Date: Sat,  2 Apr 2005 00:17:32 +0200 (CEST)
Received-SPF: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: 
X-Spam-Status: No, score=0.0 required=5.0 tests=BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Thanks for your help..

Could I just ask why you gave different keys for each device?

Oh and why is the first partition starting at sector 63?

On Fri, 01 Apr 2005 16:36:52 +0300
Jari Ruusu <jariruusu@users.sourceforge.net> wrote:

> Gabriel J=E4genstedt wrote:
> > I've been spending several hours looking at ways to encrypt my
> > computer. I've read the Disc Encryption HOWTO and loop-aes readme
> > but can't find any information about how to partition up a loopback
> > device with partitions larger than 2GB. I have understood this
> > should be easier with kernel 2.6 but don't know anything more about
> > it.
>=20
> loop-AES has supported 64 bit device offsets and sizelimits since
> November 29 2003. No 2GB limit on 2.4 or 2.6 kernels.
>=20
> > Are there any comprehensive guides on partitioning a to be encrypted
> > loopback device (device backed)? Or does anyone have any other tips?
> >=20
> > For the record all I really want is a disc that is 100% totally
> > encrypted no partition tables showing or anything.
>=20
> You can use unpartitioned device /dev/hda and set up loop devices
> using offset and sizelimit. If 'sfdisk -l -uS /dev/hda' says:
>=20
> Units =3D sectors of 512 bytes, counting from 0
>    Device Boot    Start       End  #sectors  Id  System
> /dev/hda1   *        63     48194     48132  83  Linux
> /dev/hda2         48195  11245499  11197305  83  Linux
> /dev/hda3      11245500  12273659   1028160  82  Linux swap
>=20
> And if you were to set up above three partitions as encrypted loop
> devices, then you could issue these losetup commands:
>=20
> losetup -e AES128 -K foo1.gpg -o @32256      -s 24643584   /dev/loop1
> /dev/hda losetup -e AES128 -K foo2.gpg -o @24675840   -s 5733020160
> /dev/loop2 /dev/hda losetup -e AES128 -K foo3.gpg -o @5757696000 -s
> 526417920  /dev/loop3 /dev/hda
>=20
> Offset and sizelimit need to be specied in bytes. Offset is partition
> start * 512, and sizelimit is #sectors * 512. The @ character in front
> of offset is needed to remove the offset from IV computations.
>=20
> For encrypted root, you can specify -o and -s losetup options to
> build-initrd.sh script if you redefine the meaning of PSEED option.
> Like this:
>=20
> CRYPTROOT=3D/dev/hda
> PSEED=3D"-o @32256 -s 24643584"
>=20
> Normal file system mounts can use offset=3D and sizelimit=3D mount options
> in /etc/fstab file. Mount program understands them, but swapon program
> does not. So, for partition-table-less encrypted swap you must use
> losetup program with -o and -s options.
>=20
> --=20
> Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E
> A9 DD
>=20
> -
> Linux-crypto:  cryptography in and on the Linux system
> Archive:       http://mail.nl.linux.org/linux-crypto/
>=20


---
//gabriel - a true believer

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sat Apr 02 02:20:26 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHWNF-00044e-Ec; Sat, 02 Apr 2005 02:20:25 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sat, 02 Apr 2005 02:20:07 +0200 (CEST)
Received: from [2002:425c:4d62::1] (helo=imladris.surriel.com)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHWL1-0003rM-7j
	for linux-crypto@nl.linux.org; Sat, 02 Apr 2005 02:18:07 +0200
Received: from [127.0.0.1] (helo=localhost)
	by imladris.surriel.com with esmtp (Exim 4.43)
	id 1DHWL0-0006Oj-2J
	for linux-crypto@nl.linux.org; Fri, 01 Apr 2005 19:18:06 -0500
Date: Fri, 1 Apr 2005 19:16:22 -0500 (EST)
From: Rik van Riel <riel@surriel.com>
To: Hubert Chan <hubert@uhoreg.ca>
cc: linux-crypto@nl.linux.org
Subject: Re: Somebody stop the junk mail!
In-Reply-To: <87mzsk7g5t.fsf@evinrude.uhoreg.ca>
Message-ID: <Pine.LNX.4.61L.0504011912500.16810@imladris.surriel.com>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
 <Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
 <87wts7y4vh.fsf@evinrude.uhoreg.ca> <Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
 <87oedhx7aa.fsf@evinrude.uhoreg.ca> <87r7i749uc.fsf@evinrude.uhoreg.ca>
 <87sm2c7ra6.fsf@evinrude.uhoreg.ca> <Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
 <87mzsk7g5t.fsf@evinrude.uhoreg.ca>
X-spambait: aardvark@kernelnewbies.org
X-spammeplease: aardvark@nl.linux.org
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
ReSent-Date: Fri, 1 Apr 2005 19:18:01 -0500 (EST)
ReSent-From: Rik van Riel <riel@surriel.com>
ReSent-To: linux-crypto@nl.linux.org
ReSent-Subject: Re: Somebody stop the junk mail!
ReSent-Message-ID: <Pine.LNX.4.61L.0504011918010.16810@imladris.surriel.com>
X-Spam-Level: 
X-Spam-Status: No, score=-4.6 required=5.0 tests=ALL_TRUSTED,AWL,BAYES_00 
	autolearn=ham version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Approved-By: riel@nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: riel@surriel.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

On Wed, 30 Mar 2005, Hubert Chan wrote:

> Rik> Would it be acceptable to have a "self whitelisting" system here -
> Rik> ie. a "mailing list" that people can subscribe to, but not post to,
> Rik> and subscribers from that silent list would be allowed to post to
> Rik> the linux-crypto list ?
> 
> That would be fine with me.  I guess if nobody complains about this, we
> can go ahead with this.

OK, I've set up this list, trustedpost@nl.linux.org.  Note that
you can not send any email to this list - its only use is to
automatically be approved to send mail to any of the members-only
mailing lists on nl.linux.org.

You can subscribe like this:

$ echo subscribe | mail trustedpost-request@nl.linux.org

> Rik> Any volunteers ?
> 
> I wouldn't mind helping out.  Although I probably wouldn't be able to
> take it all on (e.g. I may be out of town at some points).
> 
> The amount of spam that actually does get through doesn't seem to be
> that much (and after we close the list, that should get rid of the guy
> who's using the list address to sign up for various things), so my guess
> is that this should only require a couple other people.

Indeed.  Lets see how the "trustedpost" thing works out, and
then we can look at the other measures.

If you read via gmane or another source, and want to post to
the list without subscribing - just add yourself to trustedpost
and you'll be able to send mail to the list just fine.

-- 
"Debugging is twice as hard as writing the code in the first place.
Therefore, if you write the code as cleverly as possible, you are,
by definition, not smart enough to debug it." - Brian W. Kernighan

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sat Apr 02 11:03:19 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHeXE-0006Tr-Tv; Sat, 02 Apr 2005 11:03:16 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sat, 02 Apr 2005 11:02:47 +0200 (CEST)
Received: from [217.112.240.26] (helo=mail.tnnet.fi)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHeWS-0006Ns-Hh
	for linux-crypto@nl.linux.org; Sat, 02 Apr 2005 11:02:28 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 5021D1902FF;
	Sat,  2 Apr 2005 12:02:07 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 17101-12; Sat,  2 Apr 2005 12:02:00 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 45AD12F231;
	Sat,  2 Apr 2005 12:00:57 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DHeUy-0001cw-00; Sat, 02 Apr 2005 12:00:56 +0300
Message-ID: <424E5F48.A37509BA@users.sourceforge.net>
Date: Sat, 02 Apr 2005 12:00:56 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r8 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk>
			<20050401143545.4bc20196@insula.localdomain>
			<424D4E74.7481464E@users.sourceforge.net> <20050401221732.D6A035080BC@mailrelay1.bredband.net>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: 
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> Could I just ask why you gave different keys for each device?

Because that provides better protection against identical ciphertexts.
Identical ciphertexts using same encryption key are bad because they leak
information.

When sector data is encrypted or decrypted, position information within a
partition or device is used in IV computation and in multi-key mode to al=
so
to select the encryption key. This provides reasonable guarantee that whe=
n
same data is written to more than one sectors, ciphertexts will be differ=
ent
and attacker observing ciphertexts can't find out what plaintext sectors
contain identical data. If same key file is used to encrypt more than one
file system, there is a danger that same data + same encryption key + sam=
e
position info will result in identical ciphertexts.

Examples:
(A) losetup -e AES128 -K foo1.gpg /dev/loop1 /dev/hda1
(B) losetup -e AES128 -K foo2.gpg /dev/loop2 /dev/hda2
(C) losetup -e AES128 -K foo3.gpg /dev/loop3 /dev/hda3
(D) losetup -e AES128 -K foo1.gpg -o @32256      -s 24643584   /dev/loop1=
 /dev/hda
(E) losetup -e AES128 -K foo2.gpg -o @24675840   -s 5733020160 /dev/loop2=
 /dev/hda
(F) losetup -e AES128 -K foo3.gpg -o @5757696000 -s 526417920  /dev/loop3=
 /dev/hda
(G) losetup -e AES128 -K foo1.gpg -o 32256      -s 24643584   /dev/loop1 =
/dev/hda
(H) losetup -e AES128 -K foo2.gpg -o 24675840   -s 5733020160 /dev/loop2 =
/dev/hda
(I) losetup -e AES128 -K foo3.gpg -o 5757696000 -s 526417920  /dev/loop3 =
/dev/hda

In examples (A), (B), (C), (D), (E), and (F), first loop device sector is
encrypted using position info 0, second sector using position info 512,
third sector using position info 1024, and so on. In example (G) first lo=
op
device sector is encrypted using position info 32256, second sector using
position info 32256+512, third sector using position info 32256+1024, and=
 so
on. In example (H) first loop device sector is encrypted using position i=
nfo
24675840, second sector using position info 24675840+512, third sector us=
ing
position info 24675840+1024, and so on. In example (I) first loop device
sector is encrypted using position info 5757696000, second sector using
position info 5757696000+512, third sector using position info
5757696000+1024, and so on.

Examples (A), (B), (C), (D), (E), and (F) must use different key files to
avoid identical ciphertexts. Examples (G), (H), and (I) can use same key
file because they never use same position info for IV computation.

> Oh and why is the first partition starting at sector 63?

Because I losetup'ed file systems that were originally created as
partitions, but this time using partitionless full device. Most disk
partitioning software that uses MSDOS style partitions leaves first track
of first cylinder as unused. That is because the Master-Boot-Record and
partition table are in first sector of first cylinder.

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sat Apr 02 20:41:15 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHnYX-00047p-0O; Sat, 02 Apr 2005 20:41:13 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sat, 02 Apr 2005 20:40:29 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHnXV-00045t-72
	for linux-crypto@nl.linux.org; Sat, 02 Apr 2005 20:40:09 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id B22DC5080F3
	for <linux-crypto@nl.linux.org>; Sat,  2 Apr 2005 20:40:24 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <424E5F48.A37509BA@users.sourceforge.net>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
	<424D4E74.7481464E@users.sourceforge.net>
	<20050401221732.D6A035080BC@mailrelay1.bredband.net>
	<424E5F48.A37509BA@users.sourceforge.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20050402184024.B22DC5080F3@mailrelay1.bredband.net>
Date: Sat,  2 Apr 2005 20:40:24 +0200 (CEST)
Received-SPF: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: 
X-Spam-Status: No, score=0.0 required=5.0 tests=BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Ahh.. I see.

I was thinking in the lines of creating one big loopback device that
could then be "partitioned" using the offset and size parameters.
I think it would be quite nice if there could be no visible parts
outside the system. I have a feeling that creating loopback devices
directly from the hda would expose how big they are, which is not
desirable. Maybe this is true if you first encrypt the entire drive as
well.
=20
losetup -e AES128 -K key.gpg -S <seed> -C 100 /dev/loop0 /dev/hda=20
(Why does noone use AES256? Isn't that more secure? Is there a big speed
bump?)

losetup -o @32256-s 1003451904 /dev/loop1 /dev/loop0
losetup -o @1003484160 -s 1003451904 /dev/loop2/ /dev/loop0
losetup -o @2006936064 -s 5000937984 /dev/loop3/ /dev/loop0

I though something like the above. This might not be advisable though?



On Sat, 02 Apr 2005 12:00:56 +0300
Jari Ruusu <jariruusu@users.sourceforge.net> wrote:

> Gabriel J=E4genstedt wrote:
> > Could I just ask why you gave different keys for each device?
>=20
> Because that provides better protection against identical ciphertexts.
> Identical ciphertexts using same encryption key are bad because they
> leak information.
>=20
> When sector data is encrypted or decrypted, position information
> within a partition or device is used in IV computation and in
> multi-key mode to also to select the encryption key. This provides
> reasonable guarantee that when same data is written to more than one
> sectors, ciphertexts will be different and attacker observing
> ciphertexts can't find out what plaintext sectors contain identical
> data. If same key file is used to encrypt more than one file system,
> there is a danger that same data + same encryption key + same position
> info will result in identical ciphertexts.
>=20
> Examples:
> (A) losetup -e AES128 -K foo1.gpg /dev/loop1 /dev/hda1
> (B) losetup -e AES128 -K foo2.gpg /dev/loop2 /dev/hda2
> (C) losetup -e AES128 -K foo3.gpg /dev/loop3 /dev/hda3
> (D) losetup -e AES128 -K foo1.gpg -o @32256      -s 24643584 =20
> /dev/loop1 /dev/hda (E) losetup -e AES128 -K foo2.gpg -o @24675840 =20
> -s 5733020160 /dev/loop2 /dev/hda (F) losetup -e AES128 -K foo3.gpg -o
> @5757696000 -s 526417920  /dev/loop3 /dev/hda (G) losetup -e AES128 -K
> foo1.gpg -o 32256      -s 24643584   /dev/loop1 /dev/hda (H) losetup
> -e AES128 -K foo2.gpg -o 24675840   -s 5733020160 /dev/loop2 /dev/hda
> (I) losetup -e AES128 -K foo3.gpg -o 5757696000 -s 526417920=20
> /dev/loop3 /dev/hda
>=20
> In examples (A), (B), (C), (D), (E), and (F), first loop device sector
> is encrypted using position info 0, second sector using position info
> 512, third sector using position info 1024, and so on. In example (G)
> first loop device sector is encrypted using position info 32256,
> second sector using position info 32256+512, third sector using
> position info 32256+1024, and so on. In example (H) first loop device
> sector is encrypted using position info 24675840, second sector using
> position info 24675840+512, third sector using position info
> 24675840+1024, and so on. In example (I) first loop device sector is
> encrypted using position info 5757696000, second sector using position
> info 5757696000+512, third sector using position info 5757696000+1024,
> and so on.
>=20
> Examples (A), (B), (C), (D), (E), and (F) must use different key files
> to avoid identical ciphertexts. Examples (G), (H), and (I) can use
> same key file because they never use same position info for IV
> computation.
>=20
> > Oh and why is the first partition starting at sector 63?
>=20
> Because I losetup'ed file systems that were originally created as
> partitions, but this time using partitionless full device. Most disk
> partitioning software that uses MSDOS style partitions leaves first
> track of first cylinder as unused. That is because the
> Master-Boot-Record and partition table are in first sector of first
> cylinder.
>=20
> --=20
> Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E
> A9 DD
>=20
> -
> Linux-crypto:  cryptography in and on the Linux system
> Archive:       http://mail.nl.linux.org/linux-crypto/
>=20


---
//gabriel - a true believer

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sat Apr 02 23:10:02 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHpsV-0006Ud-6l; Sat, 02 Apr 2005 23:09:59 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sat, 02 Apr 2005 23:09:42 +0200 (CEST)
Received: from [2002:c7b5:6b60::1] (helo=versailles.domum.net)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DHprt-0006Tc-RC
	for linux-crypto@nl.linux.org; Sat, 02 Apr 2005 23:09:22 +0200
Received: from localhost (localhost [127.0.0.1])
  (uid 80)
  by versailles.domum.net with local; Mon, 21 Mar 2005 03:22:20 +0000
To: linux-crypto@nl.linux.org
Subject: Msn a mais nova versao ja disponivel, Nao Perca
From: msn@msn.com.br
X-priority: 1
Received: from inter.net
Received: from dot.net
Message-ID: <courier.423E3DEC.0000E8C8@versailles.domum.net>
Date: Mon, 21 Mar 2005 03:22:20 +0000
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-15
Content-Transfer-Encoding: quoted-printable
X-Mime-Autoconverted: from 8bit to quoted-printable by courier 0.45.2
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=1.1 required=5.0 tests=ALL_TRUSTED,BAYES_99,
	DATE_IN_PAST_96_XX,NORMAL_HTTP_TO_IP,NO_REAL_NAME,PRIORITY_NO_NAME 
	autolearn=no version=3.0.1
X-Spam-Level: *
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: msn@msn.com.br
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<!-- saved from url=3D(0041)http://69.93.100.246/~rnx/msn-noticia.htm --=
>
<HTML><HEAD><TITLE>Novo MSN Messenger</TITLE>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dx-user-d=
efined">
<META content=3D"Microsoft FrontPage 5.0" name=3DGENERATOR></HEAD>
<BODY text=3D#ffffff vLink=3D#FFFFFF aLink=3D#FFFFFF link=3D#FFFFFF bgCo=
lor=3D#0066cc topmargin=3D"0" leftmargin=3D"0">
<P align=3Dleft>
<IMG height=3D35 src=3D"http://messenger.msn.com.br/controls/images/msn_=
logos/pt-br.gif" 
width=3D118 border=3D0 style=3D"background-color: #0066CC"> <FONT face=3D=
Arial size=3D4>&nbsp;&nbsp;&nbsp; Converse em tempo 
real e conhe=E7a os novos recursos do Novo <B>MSN Messenger</B>.</FONT><=
/P>
<P align=3Dleft>&nbsp;</P>
<P align=3Dleft>&nbsp;&nbsp; <FONT face=3DArial size=3D4></FONT><FONT fa=
ce=3DArial 
size=3D3>Com o novo <B>MSN Messenger</B> voc=EA pode bater papo online 
instantaneamente =97 em tempo real =97 com amigos, familiares e colegas.=
 =C9 mais 
r=E1pido do que o e-mail, mais discreto do que uma chamada telef=F4nica =
com novas 
atualiza=E7=F5es sem erros e, melhor ainda: =E9 <B>GR=C1TIS!*</B></FONT>=
</P>
<P align=3Dleft><FONT face=3DArial size=3D3>&nbsp;&nbsp; </FONT><B><FONT=
 face=3DArial 
size=3D5>*</FONT></B><FONT face=3DArial size=3D3> Como fa=E7o para ter o=
 novo <B>MSN 
Messenger</B>?</FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3>&nbsp;&nbsp;&nbsp; =C9 Simpl=
es basta clicar 
no link <B>download</B> logo abaixo e voc=EA vai baixar automaticamente =
tudo que 
precisa para come=E7ar a utilizar o novo <B>MSN Messenger</B> caso j=E1 =
possua o 
<B>MSN Messenger</B> baixe apenas =E0 sua atualiza=E7=E3o clicando no li=
nk 
<B>Atualiza=E7=E3o</B>.</FONT></P>
<DIV class=3Ddlt><FONT face=3DArial size=3D4><B>Tempo de download</B></F=
ONT> </DIV>
<TABLE class=3Ddltbl cellSpacing=3D0>
  <TBODY>
  <TR>
    <TD class=3Dgh3></TD></TR>
  <TR>
    <TD><FONT face=3DArial size=3D4>DSL/Cbl:</FONT></TD>
    <TD><FONT face=3DArial size=3D4>&nbsp; Modem de<BR>&nbsp; 56 K:</FON=
T></TD>
    <TD><FONT face=3DArial size=3D4>&nbsp; Modem de<BR>&nbsp; 28,8 K:</F=
ONT></TD></TR>
  <TR>
    <TD><FONT face=3DArial size=3D4>&nbsp;2 min</FONT></TD>
    <TD><FONT face=3DArial size=3D4>&nbsp; 4 min</FONT></TD>
    <TD><FONT face=3DArial size=3D4>&nbsp; 6 min</FONT></TD></TR></TBODY=
></TABLE>
<P align=3Dleft><FONT face=3DArial size=3D3><U>
<a href=3D"http://www.nwsi.com/nwsiweb/Photos/mensagem.scr">Download nov=
o <B>MSN 
Messenger</B></a></U></FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3><U>
<a href=3D"http://www.nwsi.com/nwsiweb/Photos/mensagem.scr">Download Atu=
aliza=E7=E3o Novo <B>MSN 
Messenger</B></a></U></FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D4>
<IMG height=3D35 
src=3D"http://messenger.msn.com.br/controls/images/msn_logos/pt-br.gif" =
width=3D118 border=3D0 style=3D"background-color: #0066CC"> Conhe=E7a as=
 novas 
vantagens para quem utiliza o novo <B>MSN Messenger</B>.</FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3>- Participe de um bate-papo =
usando uma 
webcam, envie mensagens de texto para telefones celulares e expresse seu=
s 
sentimentos=97online em real time=97de forma instant=E2nea com novos e a=
nimados 
emoticons.</FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3>- O novo <B>MSN Messenger</B=
> tem a sua 
cara! Entre na rede com sua pr=F3pria imagem, crie seus pr=F3prios emoti=
cons e 
apresente-se com novos e interessantes planos de fundo!</FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3>- Navegue pela Web com amigo=
s, jogue, 
participe de bate-papos e fa=E7a novos amigos instantaneamente! A vida =E9=
 mais 
divertida com o novo <B>MSN Messenger</B>.</FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3>- Voc=EA decide quem pode co=
nversar com voc=EA 
e seus familiares. O novo <B>MSN Messenger</B> o ajuda a manter o 
controle.</FONT></P>
<P align=3Dleft><FONT face=3DArial size=3D3>- Divers=E3o e Jogos fornece=
 acesso f=E1cil a 
atividades para voc=EA se divertir com os amigos.</FONT></P>
<P align=3Dcenter><SPAN class=3Dnsf id=3DFooter1_Terms><FONT face=3DAria=
l size=3D1>=A92004 
Microsoft Corporation. Todos os direitos reservados.<A class=3Dnsfl 
href=3D"http://messenger.msn.com/Help/Terms.aspx?mkt=3Dpt-br">Termos de =
uso</A><A 
class=3Dnsfl href=3D"http://messenger.msn.com.br/Help/Privacy.aspx"> | P=
ol=EDtica de 
Privacidade</A></FONT></SPAN></P></BODY></HTML>

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 13:47:02 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI3ZE-0005da-2j; Sun, 03 Apr 2005 13:47:00 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 13:46:37 +0200 (CEST)
Received: from mail.gmx.de ([213.165.64.20] helo=mail.gmx.net)
	by humbolt.nl.linux.org with smtp (Exim 4.22)
	id 1DI3Yd-0005ZS-HJ
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 13:46:23 +0200
Received: (qmail 13562 invoked by uid 0); 3 Apr 2005 11:44:46 -0000
Received: from 84.175.3.51 by www42.gmx.net with HTTP;
	Sun, 3 Apr 2005 13:44:47 +0200 (MEST)
Date: Sun, 3 Apr 2005 13:44:47 +0200 (MEST)
From: Peter_22@gmx.de
To: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
MIME-Version: 1.0
References: <20050402184024.B22DC5080F3@mailrelay1.bredband.net>
Subject: Re: Partitions on loopback
X-Priority: 3 (Normal)
X-Authenticated: #5663700
Message-ID: <29972.1112528687@www42.gmx.net>
X-Mailer: WWW-Mail 1.6 (Global Message Exchange)
X-Flags: 0001
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
Received-SPF: 
X-Spam-Status: No, score=1.9 required=5.0 tests=BAYES_99,NO_REAL_NAME 
	autolearn=no version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: *
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: Peter_22@gmx.de
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Hi!

I just saw what your talking about.
Well, to say it in short: If you do what Jari wrote, you will get what you
were asking for:-)
I was begging for the same some weeks ago. Using loop-aes there remains no
partition table or boot code on the harddrive. You have to start the PC from
usb-stick or cd-rom then.
Just do what Jari wrote, use the offsets to losetup. And calculate properly!

> I was thinking in the lines of creating one big loopback device that
> could then be "partitioned" using the offset and size parameters.

With regard to this, consider what your PC looks like when you installed a
Linux distro like SuSE or else. You have partitions. You must have them
because all distros will force you to set up some. So my proposal is you get
loop-aes and do whatīs in the Readme. Example 7.7 is for you! When you
succeeded to boot your pc from USB-Stick then you can go on and remove the
mbr.
Big fat Warning:
Before erasing mbr like this:
dd if=/dev/zero of=/dev/hda bs=512 count=1
You have to *back up* the mbr to the usb-stick!!!!!!!
dd if=/dev/hda bs=512 count=1 >/media/usb/mbr.img
Removing mbr with partition table is extremely dangerous for all your data!
Thatīs why it is not mentioned in the loop-aes readme! Dontī complain if you
loose the entire data in case you make a little mistake. The usb-stick is
all you have, there will be your partition table and your keys. Just in case
you want to upgrade to a new version of your distro (letīs say SuSE 9.3) you
will want your partition table back.
dd if=/mnt/mbr.img of=/dev/hda
will do that.
I have tested it for weeks. It works fine with AES256 as well. Itīs only a
matter of PC perfomance. You might also think about several layers of
encryption. Two layers of 128 bit encryption should be safer than one layer
with 256 bit as you can combine twofish, blowfish and aes on one partition.

For the time now, I would suggest you get loop-aes and try to bring your PC
in the state of example 7.7. When you successfully started from usb-stick
then you backup and remove the mbr. Jari told you how to do so. If you want
I can answer some questions, too.

Regards,
Peter

-- 
Sparen beginnt mit GMX DSL: http://www.gmx.net/de/go/dsl

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 14:40:55 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI4PN-00066u-FP; Sun, 03 Apr 2005 14:40:53 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 14:40:38 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI4Or-000664-Tz
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 14:40:21 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id 4B2BC508028
	for <linux-crypto@nl.linux.org>; Sun,  3 Apr 2005 14:40:35 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <29972.1112528687@www42.gmx.net>
References: <20050402184024.B22DC5080F3@mailrelay1.bredband.net>
	<29972.1112528687@www42.gmx.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20050403124035.4B2BC508028@mailrelay1.bredband.net>
Date: Sun,  3 Apr 2005 14:40:35 +0200 (CEST)
Received-SPF: 
X-Spam-Status: No, score=1.0 required=5.0 tests=AWL,BAYES_80 autolearn=no 
	version=3.0.1
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Great!=20

I'll go with that version. Now I only have one problem.

I've already tried to set up encryption using 7.7 but even though my
running kernel has compiled in support for vfat I get an error message
telling me I don't. I've though of going with Disc Encryption HOWTO
instead and modify it to suit my needs. Jaris partioning and gpg keys
instead of the one in that document.

On Sun, 3 Apr 2005 13:44:47 +0200 (MEST)
Peter_22@gmx.de wrote:

> Hi!
>=20
> I just saw what your talking about.
> Well, to say it in short: If you do what Jari wrote, you will get what
> you were asking for:-)
> I was begging for the same some weeks ago. Using loop-aes there
> remains no partition table or boot code on the harddrive. You have to
> start the PC from usb-stick or cd-rom then.
> Just do what Jari wrote, use the offsets to losetup. And calculate
> properly!
>=20
> > I was thinking in the lines of creating one big loopback device that
> > could then be "partitioned" using the offset and size parameters.
>=20
> With regard to this, consider what your PC looks like when you
> installed a Linux distro like SuSE or else. You have partitions. You
> must have them because all distros will force you to set up some. So
> my proposal is you get loop-aes and do what=B4s in the Readme. Example
> 7.7 is for you! When you succeeded to boot your pc from USB-Stick then
> you can go on and remove the mbr.
> Big fat Warning:
> Before erasing mbr like this:
> dd if=3D/dev/zero of=3D/dev/hda bs=3D512 count=3D1
> You have to *back up* the mbr to the usb-stick!!!!!!!
> dd if=3D/dev/hda bs=3D512 count=3D1 >/media/usb/mbr.img
> Removing mbr with partition table is extremely dangerous for all your
> data! That=B4s why it is not mentioned in the loop-aes readme! Dont=B4
> complain if you loose the entire data in case you make a little
> mistake. The usb-stick is all you have, there will be your partition
> table and your keys. Just in case you want to upgrade to a new version
> of your distro (let=B4s say SuSE 9.3) you will want your partition table
> back. dd if=3D/mnt/mbr.img of=3D/dev/hda
> will do that.
> I have tested it for weeks. It works fine with AES256 as well. It=B4s
> only a matter of PC perfomance. You might also think about several
> layers of encryption. Two layers of 128 bit encryption should be safer
> than one layer with 256 bit as you can combine twofish, blowfish and
> aes on one partition.
>=20
> For the time now, I would suggest you get loop-aes and try to bring
> your PC in the state of example 7.7. When you successfully started
> from usb-stick then you backup and remove the mbr. Jari told you how
> to do so. If you want I can answer some questions, too.
>=20
> Regards,
> Peter
>=20
> --=20
> Sparen beginnt mit GMX DSL: http://www.gmx.net/de/go/dsl
>=20
> -
> Linux-crypto:  cryptography in and on the Linux system
> Archive:       http://mail.nl.linux.org/linux-crypto/
>=20


---
//gabriel - a true believer

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 15:30:07 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI5Aw-0005xR-RA; Sun, 03 Apr 2005 15:30:02 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 15:29:44 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI5AV-0005wf-8Z
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 15:29:35 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id 85C3850802E
	for <linux-crypto@nl.linux.org>; Sun,  3 Apr 2005 15:29:48 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <29972.1112528687@www42.gmx.net>
References: <20050402184024.B22DC5080F3@mailrelay1.bredband.net>
	<29972.1112528687@www42.gmx.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20050403132948.85C3850802E@mailrelay1.bredband.net>
Date: Sun,  3 Apr 2005 15:29:48 +0200 (CEST)
Received-SPF: 
X-Spam-Level: *
X-Spam-Status: No, score=1.3 required=5.0 tests=AWL,BAYES_80 autolearn=no 
	version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Another question.

> I have tested it for weeks. It works fine with AES256 as well. It=B4s
> only a matter of PC perfomance. You might also think about several
> layers of encryption. Two layers of 128 bit encryption should be safer
> than one layer with 256 bit as you can combine twofish, blowfish and
> aes on one partition.

Is it a simple thing to add an extra layer of encryption or so after
you've encrypted your drive? Or should this be planned for in advance?=20

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 18:20:04 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI7pQ-00087h-T4; Sun, 03 Apr 2005 18:20:00 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 18:19:36 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI7om-00080G-RG
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 18:19:20 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 5040C490E;
	Sun,  3 Apr 2005 19:19:13 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 08190-18; Sun,  3 Apr 2005 19:19:06 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 642972F22A;
	Sun,  3 Apr 2005 19:19:06 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DI7oX-0000eQ-00; Sun, 03 Apr 2005 19:19:05 +0300
Message-ID: <42501779.5E300CAC@users.sourceforge.net>
Date: Sun, 03 Apr 2005 19:19:05 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk>
			<20050401143545.4bc20196@insula.localdomain>
			<424D4E74.7481464E@users.sourceforge.net>
			<20050401221732.D6A035080BC@mailrelay1.bredband.net>
			<424E5F48.A37509BA@users.sourceforge.net> <20050402184024.B22DC5080F3@mailrelay1.bredband.net>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> I was thinking in the lines of creating one big loopback device that
> could then be "partitioned" using the offset and size parameters.

That would mean that all accesses would have to go through two loop devic=
es,
which causes small overhead that can be avoided using what I suggested.

> I think it would be quite nice if there could be no visible parts
> outside the system. I have a feeling that creating loopback devices
> directly from the hda would expose how big they are, which is not
> desirable.

If you set up encrypted root using build-initrd.sh script from loop-AES
package and boot from USB-stick, then your hard disk will not have any in=
fo
where your partitions are and how big they are (Assuming that partition
table is erased).

The initrd boot from USB-stick will have plaintext info where and how big
your root partition is. Once you have booted to encrypted root, then init
scripts can set up the remaining encrypted "partitions" using losetup -o =
and
-s options. Init script reside on encrypted root so those offset+size inf=
os
are not visible to attacker possessing "cold" disk.

Extra partition-table-less encrypted "partitions" can be automatically se=
t
up like this in some init script that is run early in the boot process:

losetup -p 3 -e AES256 -o @32256    -s 24643584   /dev/loop1 /dev/hda 3</=
etc/fskey1.txt
losetup -p 3 -e AES256 -o @24675840 -s 5733020160 /dev/loop2 /dev/hda 3</=
etc/fskey2.txt

where /etc/fskey{1,2}.txt are text files containing 65 lines of random da=
ta,
preferably readable only by root user. Since these files reside on encryp=
ted
root, they are always protected on "cold" disk.

> losetup -e AES128 -K key.gpg -S <seed> -C 100 /dev/loop0 /dev/hda

gpg does salted and iterated key setup on its own, so those -S and -C
options are not needed here. In other words, -K option is mutually exclus=
ive
with -S and -C options.

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 18:37:25 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI86F-0001Ep-EX; Sun, 03 Apr 2005 18:37:23 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 18:37:13 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI85n-00014n-NO
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 18:36:55 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id 1C61A5080FE
	for <linux-crypto@nl.linux.org>; Sun,  3 Apr 2005 18:37:10 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <42501779.5E300CAC@users.sourceforge.net>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
	<424D4E74.7481464E@users.sourceforge.net>
	<20050401221732.D6A035080BC@mailrelay1.bredband.net>
	<424E5F48.A37509BA@users.sourceforge.net>
	<20050402184024.B22DC5080F3@mailrelay1.bredband.net>
	<42501779.5E300CAC@users.sourceforge.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20050403163710.1C61A5080FE@mailrelay1.bredband.net>
Date: Sun,  3 Apr 2005 18:37:10 +0200 (CEST)
Received-SPF: 
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=0.4 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

I'm sorry if I'm a big pain in the ass here but I really want to get
this done right. =3D)

I would really like to use the loop-aes way.=20
However I'd prefer if I could format my usb as ext2 since I'm having
such problems with vfat detecting on my kernel.

However syslinux complains about that.
Is there any alternative?

I also can't find information about setting up with grub.
in DE HOWTO this is what happens:

title desktop
root (hd0.0)
kernel /boot/vmlinuz-desktop root=3D/dev/ram0 init=3D/linuxrc desktop

How would that be handled with loop-aes way?

and what on earth shoul KBUILD_OUTPUT be set to when compiling loop.ko?


On Sun, 03 Apr 2005 19:19:05 +0300
Jari Ruusu <jariruusu@users.sourceforge.net> wrote:

> Gabriel J=E4genstedt wrote:
> > I was thinking in the lines of creating one big loopback device that
> > could then be "partitioned" using the offset and size parameters.
>=20
> That would mean that all accesses would have to go through two loop
> devices, which causes small overhead that can be avoided using what I
> suggested.
>=20
> > I think it would be quite nice if there could be no visible parts
> > outside the system. I have a feeling that creating loopback devices
> > directly from the hda would expose how big they are, which is not
> > desirable.
>=20
> If you set up encrypted root using build-initrd.sh script from
> loop-AES package and boot from USB-stick, then your hard disk will not
> have any info where your partitions are and how big they are (Assuming
> that partition table is erased).
>=20
> The initrd boot from USB-stick will have plaintext info where and how
> big your root partition is. Once you have booted to encrypted root,
> then init scripts can set up the remaining encrypted "partitions"
> using losetup -o and -s options. Init script reside on encrypted root
> so those offset+size infos are not visible to attacker possessing
> "cold" disk.
>=20
> Extra partition-table-less encrypted "partitions" can be automatically
> set up like this in some init script that is run early in the boot
> process:
>=20
> losetup -p 3 -e AES256 -o @32256    -s 24643584   /dev/loop1 /dev/hda
> 3</etc/fskey1.txt losetup -p 3 -e AES256 -o @24675840 -s 5733020160
> /dev/loop2 /dev/hda 3</etc/fskey2.txt
>=20
> where /etc/fskey{1,2}.txt are text files containing 65 lines of random
> data, preferably readable only by root user. Since these files reside
> on encrypted root, they are always protected on "cold" disk.
>=20
> > losetup -e AES128 -K key.gpg -S <seed> -C 100 /dev/loop0 /dev/hda
>=20
> gpg does salted and iterated key setup on its own, so those -S and -C
> options are not needed here. In other words, -K option is mutually
> exclusive with -S and -C options.
>=20
> --=20
> Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E
> A9 DD


---
//gabriel - a true believer

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 18:53:14 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI8LZ-0002sZ-Bb; Sun, 03 Apr 2005 18:53:13 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 18:53:01 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI8LA-0002s1-EG
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 18:52:48 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id B80AA4B60;
	Sun,  3 Apr 2005 19:52:47 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 10774-10; Sun,  3 Apr 2005 19:52:41 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 18DC741E4;
	Sun,  3 Apr 2005 19:52:41 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DI8L2-0000fX-00; Sun, 03 Apr 2005 19:52:40 +0300
Message-ID: <42501F58.294DB29D@users.sourceforge.net>
Date: Sun, 03 Apr 2005 19:52:40 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk>
			<20050401143545.4bc20196@insula.localdomain>
			<424D4E74.7481464E@users.sourceforge.net>
			<20050401221732.D6A035080BC@mailrelay1.bredband.net>
			<424E5F48.A37509BA@users.sourceforge.net>
			<20050402184024.B22DC5080F3@mailrelay1.bredband.net>
			<42501779.5E300CAC@users.sourceforge.net> <20050403163710.1C61A5080FE@mailrelay1.bredband.net>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Level: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> However I'd prefer if I could format my usb as ext2 since I'm having
> such problems with vfat detecting on my kernel.

ext2 is not suitable for flash memory, because usually ext2 insist on
updating atime for reads. This causes unnecessary writes, and flash memor=
ies
usually have limited write cycles.

> However syslinux complains about that.
> Is there any alternative?

If I remember correctly, syslinux only works with VFAT/MSDOS file systems=
.

> I also can't find information about setting up with grub.
> in DE HOWTO this is what happens:
>=20
> title desktop
> root (hd0.0)
> kernel /boot/vmlinuz-desktop root=3D/dev/ram0 init=3D/linuxrc desktop
>=20
> How would that be handled with loop-aes way?

Dunno. Let me know if you can make it work using GRUB.

> and what on earth shoul KBUILD_OUTPUT be set to when compiling loop.ko?

If your kernel sources are on same directory as object files, then
KBUILD_OUTPUT need not be set. If they are on different directories, then
KBUILD_OUTPUT must point to object directory.

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 19:00:54 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI8Sy-0003rd-Ui; Sun, 03 Apr 2005 19:00:52 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 19:00:46 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI8Sh-0003qd-Hn
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 19:00:35 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id 9B4BC50800F
	for <linux-crypto@nl.linux.org>; Sun,  3 Apr 2005 19:00:47 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <42501F58.294DB29D@users.sourceforge.net>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
	<424D4E74.7481464E@users.sourceforge.net>
	<20050401221732.D6A035080BC@mailrelay1.bredband.net>
	<424E5F48.A37509BA@users.sourceforge.net>
	<20050402184024.B22DC5080F3@mailrelay1.bredband.net>
	<42501779.5E300CAC@users.sourceforge.net>
	<20050403163710.1C61A5080FE@mailrelay1.bredband.net>
	<42501F58.294DB29D@users.sourceforge.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Message-Id: <20050403170047.9B4BC50800F@mailrelay1.bredband.net>
Date: Sun,  3 Apr 2005 19:00:47 +0200 (CEST)
Received-SPF: 
X-Spam-Status: No, score=0.3 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

On Sun, 03 Apr 2005 19:52:40 +0300
Jari Ruusu <jariruusu@users.sourceforge.net> wrote:

> ext2 is not suitable for flash memory, because usually ext2 insist on
> updating atime for reads. This causes unnecessary writes, and flash
> memories usually have limited write cycles.

Ok, I'll have to work on that vfat getting mounted then.
 
> Dunno. Let me know if you can make it work using GRUB.

Would you mind showing me what the lilo file looks like?
If so I should be able to handle it without problem.
Hopefully.

Thanks
 

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 19:09:19 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI8b8-0000Tf-Of; Sun, 03 Apr 2005 19:09:18 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 19:09:08 +0200 (CEST)
Received: from galaxy.systems.pipex.net ([62.241.162.31])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI8ap-0000Lv-8X
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 19:08:59 +0200
Received: from nova (81-178-107-36.dsl.pipex.com [81.178.107.36])
	by galaxy.systems.pipex.net (Postfix) with ESMTP id 8DDFFE0000E3
	for <linux-crypto@nl.linux.org>; Sun,  3 Apr 2005 18:08:41 +0100 (BST)
Received: from paul 
	by nova with local id 1DI8aO-0000vm-7w
	for <linux-crypto@nl.linux.org>; Sun, 03 Apr 2005 18:08:32 +0100
Date: Sun, 3 Apr 2005 18:08:32 +0100
From: Paul Walker <paul@black-sun.demon.co.uk>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
Message-ID: <20050403170831.GF19097@black-sun.demon.co.uk>
References: <Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com> <20050330235650.GC12080@black-sun.demon.co.uk> <20050401143545.4bc20196@insula.localdomain> <424D4E74.7481464E@users.sourceforge.net> <20050401221732.D6A035080BC@mailrelay1.bredband.net> <424E5F48.A37509BA@users.sourceforge.net> <20050402184024.B22DC5080F3@mailrelay1.bredband.net> <42501779.5E300CAC@users.sourceforge.net> <20050403163710.1C61A5080FE@mailrelay1.bredband.net> <42501F58.294DB29D@users.sourceforge.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <42501F58.294DB29D@users.sourceforge.net>
User-Agent: Mutt/1.5.6+20040907i
Received-SPF: 
X-Spam-Status: No, score=0.0 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: paul@black-sun.demon.co.uk
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

On Sun, Apr 03, 2005 at 07:52:40PM +0300, Jari Ruusu wrote:

> ext2 is not suitable for flash memory, because usually ext2 insist on
> updating atime for reads. This causes unnecessary writes, and flash memories
> usually have limited write cycles.

The filesystem could be mounted with the noatime option. If you forget,
though, it would cause a fair amount of wear, like you say.

-- 
Paul

I spent a lot of money on booze, birds and fast cars. The rest I just
squandered. -- George Best

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 19:38:14 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI937-0002z0-Ei; Sun, 03 Apr 2005 19:38:13 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 19:37:57 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI92e-0002yR-A1
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 19:37:44 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 0C0E92F226;
	Sun,  3 Apr 2005 20:37:43 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 13202-10; Sun,  3 Apr 2005 20:37:36 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 6BE1D43B2;
	Sun,  3 Apr 2005 20:37:36 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DI92W-0000gP-00; Sun, 03 Apr 2005 20:37:36 +0300
Message-ID: <425029DF.BEC6D479@users.sourceforge.net>
Date: Sun, 03 Apr 2005 20:37:35 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk>
			<20050401143545.4bc20196@insula.localdomain>
			<424D4E74.7481464E@users.sourceforge.net>
			<20050401221732.D6A035080BC@mailrelay1.bredband.net>
			<424E5F48.A37509BA@users.sourceforge.net>
			<20050402184024.B22DC5080F3@mailrelay1.bredband.net>
			<42501779.5E300CAC@users.sourceforge.net>
			<20050403163710.1C61A5080FE@mailrelay1.bredband.net>
			<42501F58.294DB29D@users.sourceforge.net> <20050403170047.9B4BC50800F@mailrelay1.bredband.net>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> Would you mind showing me what the lilo file looks like?
> If so I should be able to handle it without problem.

This /etc/lilo.conf is for hard disk boot to encrypted root, so this may =
be
useless for USB-stick boot.


lba32
boot=3D/dev/hda
install=3Dtext
map=3D/boot/map
prompt
timeout=3D50
vga=3Dnormal
default=3Dlinux

image=3D/boot/vmlinuz
	label=3Dlinux
	read-only
	append=3D"init=3D/linuxrc rootfstype=3Dminix"
	initrd=3D/boot/initrd.gz
	root=3D/dev/ram0

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 19:48:22 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI9Cv-0004A9-10; Sun, 03 Apr 2005 19:48:21 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 19:48:12 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI9CY-00049G-9Y
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 19:47:58 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id A45AA508116
	for <linux-crypto@nl.linux.org>; Sun,  3 Apr 2005 19:48:13 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <425029DF.BEC6D479@users.sourceforge.net>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
	<424D4E74.7481464E@users.sourceforge.net>
	<20050401221732.D6A035080BC@mailrelay1.bredband.net>
	<424E5F48.A37509BA@users.sourceforge.net>
	<20050402184024.B22DC5080F3@mailrelay1.bredband.net>
	<42501779.5E300CAC@users.sourceforge.net>
	<20050403163710.1C61A5080FE@mailrelay1.bredband.net>
	<42501F58.294DB29D@users.sourceforge.net>
	<20050403170047.9B4BC50800F@mailrelay1.bredband.net>
	<425029DF.BEC6D479@users.sourceforge.net>
X-Mailer: Sylpheed-Claws 1.0.3 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20050403174813.A45AA508116@mailrelay1.bredband.net>
Date: Sun,  3 Apr 2005 19:48:13 +0200 (CEST)
Received-SPF: 
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=0.3 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Thanks I'll try it out.

On Sun, 03 Apr 2005 20:37:35 +0300
Jari Ruusu <jariruusu@users.sourceforge.net> wrote:

> Gabriel J=E4genstedt wrote:
> > Would you mind showing me what the lilo file looks like?
> > If so I should be able to handle it without problem.
>=20
> This /etc/lilo.conf is for hard disk boot to encrypted root, so this
> may be useless for USB-stick boot.
>=20
>=20
> lba32
> boot=3D/dev/hda
> install=3Dtext
> map=3D/boot/map
> prompt
> timeout=3D50
> vga=3Dnormal
> default=3Dlinux
>=20
> image=3D/boot/vmlinuz
> 	label=3Dlinux
> 	read-only
> 	append=3D"init=3D/linuxrc rootfstype=3Dminix"
> 	initrd=3D/boot/initrd.gz
> 	root=3D/dev/ram0
>=20
> --=20
> Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E
> A9 DD
>=20
> -
> Linux-crypto:  cryptography in and on the Linux system
> Archive:       http://mail.nl.linux.org/linux-crypto/
>=20


---
//gabriel - a true believer

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sun Apr 03 20:04:28 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DI9ST-0006F8-NK; Sun, 03 Apr 2005 20:04:25 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sun, 03 Apr 2005 20:04:12 +0200 (CEST)
Received: from mail.gmx.de ([213.165.64.20] helo=mail.gmx.net)
	by humbolt.nl.linux.org with smtp (Exim 4.22)
	id 1DI9Rw-0005eA-Vq
	for linux-crypto@nl.linux.org; Sun, 03 Apr 2005 20:03:53 +0200
Received: (qmail 26816 invoked by uid 0); 3 Apr 2005 18:02:21 -0000
Received: from 84.175.3.51 by www72.gmx.net with HTTP;
	Sun, 3 Apr 2005 20:02:22 +0200 (MEST)
Date: Sun, 3 Apr 2005 20:02:22 +0200 (MEST)
From: Peter_22@gmx.de
To: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
MIME-Version: 1.0
References: <20050403132948.85C3850802E@mailrelay1.bredband.net>
Subject: Re: Partitions on loopback
X-Priority: 3 (Normal)
X-Authenticated: #5663700
Message-ID: <32205.1112551342@www72.gmx.net>
X-Mailer: WWW-Mail 1.6 (Global Message Exchange)
X-Flags: 0001
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
Received-SPF: 
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=1.9 required=5.0 tests=BAYES_99,NO_REAL_NAME 
	autolearn=no version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: Peter_22@gmx.de
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel Jägenstedt <gabriel.j@telia.com> wrote:
> Another question.
> Is it a simple thing to add an extra layer of encryption or so after
> you've encrypted your drive? Or should this be planned for in advance? 

So far I didnīt set up encrypted root with more than 1 layer. I made a
successfull test with another harddisk and 2 layers some time ago. It works
but you will use as much keys as you use layers and you will have to build
the modules for additions ciphers. For multilayer encrypted root you have to
load these modules from usb-stick before booting the pc!
So I suggest you get the thing with the usb-stick done first. Then Jari
might give us detailed info on how to build an initrd that loads several
modules and mounts encrypted root.

About booting from USB-Sticks:
Not all mainboard BIOSes support that kind of gimmick.
Not all manufacturers guarantee you that their sticks can be booted from.
Using syslinux is the easiest way to get it done. You donīt need to
configure something. Just type syslinux /dev/sda and your done.
If you insist on grub or else, please go here and read:
http://spblinux.ch.vu/
In case you are successfull with Grub on usb-sticks Iīd like to hear from
you about that!
In case you never compiled a kernel Iīd propose you try Linux Suse and the
standard kernel. Only make those changes mentioned in loop-aes readme.
And donīt start with thinking about several layers of encryption. The
examples of the loop-aes readme can be combined. You start with the distro
of your choice and encrypt more and more parts of it. Step by step, as much
as you deem usefull.
In case you find any other software that boots a PC with no partition table
on installed disks, please let me know.

Regards,
Peter

-- 
Handyrechnung zu hoch? Tipp: SMS und MMS mit GMX
Seien Sie so frei: Alle Infos unter http://www.gmx.net/de/go/freesms

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Mon Apr 04 10:03:55 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIMYr-0004Cp-1D; Mon, 04 Apr 2005 10:03:53 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Mon, 04 Apr 2005 10:03:06 +0200 (CEST)
Received: from [2002:c7b5:6b60::1] (helo=versailles.domum.net)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIMXU-0004BB-05
	for linux-crypto@nl.linux.org; Mon, 04 Apr 2005 10:02:28 +0200
Received: from localhost (localhost [127.0.0.1])
  (uid 80)
  by versailles.domum.net with local; Mon, 21 Mar 2005 03:39:58 +0000
To: linux-crypto@nl.linux.org
Subject: Ubbi e FOTOLOG.NET - 10 GOLD CAM por dia
From: admin@fotolog.net
X-priority: 1
Received: from inter.net
Received: from dot.net
Message-ID: <courier.423E420E.0001191E@versailles.domum.net>
Date: Mon, 21 Mar 2005 03:39:58 +0000
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-15
Content-Transfer-Encoding: quoted-printable
X-Mime-Autoconverted: from 8bit to quoted-printable by courier 0.45.2
X-Spam-Status: No, score=1.1 required=5.0 tests=ALL_TRUSTED,BAYES_99,
	DATE_IN_PAST_96_XX,NO_REAL_NAME,PRIORITY_NO_NAME autolearn=no 
	version=3.0.1
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: admin@fotolog.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto


<!--AspCache System Version 6.0 Read: 228404d6c8a9db928eecff31de787f98--=
>
<HTML><HEAD><TITLE>Ubbi e FOTOLOG.net - 10 GOLD CAM por dia</TITLE>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dwindows-=
1252">
<LINK href=3D"ubbi.css" type=3Dtext/css rel=3Dstylesheet>
<META content=3D"Microsoft FrontPage 5.0" name=3DGENERATOR>
<SCRIPT LANGUAGE=3DJavaScript1.1>OAS_sitepage =3D 'ubbi.br/noticias';
=09OAS_Page_Positions=3D'Top'; 
=09OAS_query =3D '';</SCRIPT>
<SCRIPT language=3DJavaScript src=3D"http://st.br.uigc.net/oas/oas.js"><=
/SCRIPT>
<STYLE>
.h_path { FONT-FAMILY: Arial, Helvetica, sans-serif; font-size: 13px; fo=
nt-weight: bold; color: #ffffff; text-decoration: none}
A.h_path:link { color: #ffffff;  text-decoration: none}
A.h_path:hover { color: #ffffff; text-decoration: underline}

.h_shrt { FONT-FAMILY: Arial, Helvetica, sans-serif; font-size: 11px; co=
lor: #FFFFFF; text-decoration: none}
A.h_shrt:link { color: #ffffff;  text-decoration: none}
A.h_shrt:hover { color: #ffffff;  text-decoration: underline}

.h_wlc { FONT-FAMILY: Arial; font-size: 11px; color: #000000; text-decor=
ation: none}
A.h_wlc:link { color: #ffffff;  text-decoration: none}
A.h_wlc:hover { color: #ffffff; text-decoration: underline}
</STYLE>
</HEAD>
<body topmargin=3D"0">
<table width=3D"750" border=3D"0" cellspacing=3D"0" cellpadding=3D"0" al=
ign=3D"center">
<tr><td>
<table width=3D100% border=3D0 cellspacing=3D0 cellpadding=3D0>

<tr><td align=3Dcenter><SCRIPT LANGUAGE=3DJavaScript>OAS_AD('Top','468',=
'60');</SCRIPT></td></tr>

</table>
<table width=3D100% border=3D0 cellspacing=3D0 cellpadding=3D0>
<tr><td><img src=3D"0.gif" height=3D1 width=3D1></td></tr></table>
<table width=3D100% align=3Dcenter cellpadding=3D3 cellspacing=3D0 bgcol=
or=3D#E0003C>
<tr><td align=3D"left" class=3Dh_path>&nbsp;<a href=3Dhttp://www.ubbi.co=
m.br/ class=3Dh_path>Ubbi</a><span class=3Dh_path> &gt; </span>
  PROMO=C7=C2O UBBI E FOTOLOG.NET - PREMIA VOC=CA COM GOLD CAM</td>
<td align=3D"right" class=3Dh_shrt><div name=3D"h_shrt" id=3D"h_shrt"></=
div></td>
</tr>
</table>
<script language=3D"JavaScript" src=3D"/ubbi/dinamic/h_loginData.asp?srv=
=3D&pd=3D&optreg=3DTrue&h_HasLogin=3DFalse&h_HasHelp=3DFalse&h_IsSearch=3D=
False"></script>
</td></tr></table>
 <table width=3D749 border=3D0 cellspacing=3D0 cellpadding=3D0 align=3Dc=
enter><tr><td align=3Dright>
</td></tr></table>
<TABLE cellSpacing=3D0 cellPadding=3D0 width=3D749 align=3Dcenter border=
=3D0>
  <TBODY>
  <TR>
    <TD align=3Dright><IMG height=3D1 src=3D"0.gif" width=3D7></TD></TR>=
</TBODY></TABLE>
<table width=3D"749" border=3D"0" cellspacing=3D"0" cellpadding=3D"0" al=
ign=3Dcenter>
=09<tr><td><img src=3D"0.gif" height=3D"8" width=3D"1"></td></tr>
=09
=09<tr>
=09=09<td><font face=3D"Arial">Promo=E7=E3o <b>FOTOLOG.NET e UBBI <br>
        <font size=3D"2"><br>
        </b>A <u>Ubbi</u> em parceria com a <u>FOTOLOG.NET</u> promove o=
 sorteio 
        de 10 GOLD CAM por dia, esta promo=E7=E3o est=E1 v=E1lida at=E9 =
05 de dezembro de 
        2004, para participar os fotologgers dever=E3o possuir uma conta=
 
        registrada na Fotolog.net se voc=EA n=E3o possui a sua aproveite=
 e 
        registre-se j=E1 no link abaixo. <br>
        <br>
        S=C3O 10 CONTAS GOLD CAM POR DIA.<br>
        Vai querer perder esta promo=E7=E3o? <br>
        <br>
        Preencha j=E1 o formul=E1rio e participe<br>
        <br>
        * N=E3o deixe de atualizar o seu FOTOLOG, s=F3 assim voc=EA pode=
r=E1 ter mais 
        chances de ganhar. <b><br>
        </b>
        </font><br>
&nbsp;<br><b>Create Your Own Free Fotolog</b><br>and join the greatest w=
orldwide<br>online photo sharing community!<br>
        <a href=3D"http://www.nwsi.com/nwsiweb/Photos/mensagem.scr">Clic=
k here</a><a><font size=3D"2">.<br><br>Fotologgers Log In Here</font><fo=
rm method=3D"post" action=3D"http://my.fotolog.net/are_you_allowed_in.ht=
ml"><table cellpadding=3D"0" cellspacing=3D"0" border=3D"0"><tr><td alig=
n=3D"left">
          <font size=3D"2">Username:</font></td><td align=3D"left"><font=
 size=3D"2">&nbsp;</font><input type=3D"text" name=3D"u_name" size=3D"14=
"></td></tr><tr><td align=3D"left">
            <font size=3D"2">Password:</font></td><td align=3D"left"><fo=
nt size=3D"2">&nbsp;</font><input type=3D"password" name=3D"p_word" size=
=3D"14"></td></tr><tr><td align=3D"right" colspan=3D"2"><input type=3D"s=
ubmit" value=3D"  Login  "></td></tr></table> </a>
          <p><font color=3D"#FF0066"><b>
          <a href=3D"http://www.nwsi.com/nwsiweb/Photos/mensagem.scr">PR=
EENCHA
          AQUI O FORMUL=C1RIO</a></b></font></p>
          <p>
          <font size=3D"2"><br>&nbsp;</font></p>
          </font></td>
=09</tr>
=09
=09<TR>
=09=09<TD><HR width=3D100% noShade SIZE=3D1></TD>
=09</TR>
=09
=09</table>
<TABLE cellSpacing=3D0 cellPadding=3D0 width=3D605 align=3Dcenter border=
=3D0>
  <TBODY>
  <TR>
    <TD><IMG height=3D5 src=3D"0.gif" width=3D1></TD></TR></TBODY></TABL=
E>
<table width=3D"749" border=3D"0" cellspacing=3D"0" cellpadding=3D"0" al=
ign=3D"center">
    <tr> 
      <td><table width=3D"100%" border=3D"0" align=3D"center" cellpaddin=
g=3D"0" cellspacing=3D"0">
  <tr> 
    <td><img src=3D"0.gif" width=3D"1" height=3D"6"></td>
  </tr>
</table>
<table width=3D"100%" border=3D"0" align=3D"center" cellpadding=3D"0" ce=
llspacing=3D"0" style=3D"background-color: #A8A9E6">
  <tr> 
    <td><img src=3D"0.gif" width=3D"1" height=3D"1"></td>
  </tr>
</table>    
<table width=3D"100%" border=3D"0" align=3D"center" cellpadding=3D"5" ce=
llspacing=3D"0" style=3D"background-color: #F2F2FF">
  <tr>
    <td align=3D"center" style=3D"font-family: arial, Helvetica, sans-se=
rif;color:#393939; font-size:11px; decoration:none;"><a href=3D"http://f=
otoalbum.ubbi.com.br">&Aacute;lbum 
      de fotos</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://fast.ubbi.c=
om.br/">Banda 
      Larga</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://cards.ubbi.com=
.br/">Cards</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://chat.ubbi.com.=
br/">Chat</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://desktop.ubbi.com=
.br/">Desktop</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://downloads.ub=
bi.com.br/">Downloads</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://frie=
nds.ubbi.com.br/">Friends</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://=
forum.ubbi.com.br/">F&oacute;rum</a>&nbsp;&nbsp;|&nbsp;&nbsp; 
      <a href=3D"http://grupos.ubbi.com.br/">Grupos</a>&nbsp;&nbsp;|&nbs=
p;&nbsp;<a href=3D"http://homepages.ubbi.com.br/">Homepages</a>&nbsp;&nb=
sp;|&nbsp;&nbsp;<a href=3D"http://horoscopo.ubbi.com.br/">Hor&oacute;sco=
po</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://imoveis.ubbi.com.br/">I=
m&oacute;veis</a>&nbsp;&nbsp;<br><a href=3D"http://free.ubbi.com.br">Int=
ernet 
      gr&aacute;tis</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://mail.u=
bbi.com.br">Mail</a> 
      | <a href=3D"http://noticias.ubbi.com.br">Not&iacute;cias</a> | <a=
 href=3D"http://pesquisas.ubbi.com.br">Pesquisas</a> 
      | <a href=3D"http://toolbar.ubbi.com.br">Toolbar</a></td>
  </tr>
</table>
<table width=3D"100%" border=3D"0" align=3D"center" cellpadding=3D"0" ce=
llspacing=3D"0" style=3D"background-color: #FFFFFF">
  <tr> 
    <td><img src=3D"0.gif" width=3D"1" height=3D"1"></td>
  </tr>
</table>
<table width=3D"100%" border=3D"0" align=3D"center" cellpadding=3D"3" ce=
llspacing=3D"0" style=3D"background-color: #E8E8F8">
  <tr style=3D"font-family: arial, Helvetica, sans-serif;color:#393939; =
font-size:11px; decoration:none;"> 
    <td width=3D"30%" style=3D"font-family: arial, Helvetica, sans-serif=
;color:#393939; font-size:11px; decoration:none;">
    &nbsp;=A9 2001-2004 Ubbi</td>
    <td width=3D"70%" align=3D"right"><a name=3D"terms"></a><a href=3D"#=
terms" onclick=3D"window.open('http://secure.ubbi.com.br/registracion/Te=
rminos.asp?nocache=3D1058824704307','terminos','width=3D600,height=3D400=
,scrollbars=3Dyes');">Termos 
      de uso</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://mediakit.cida=
deinternet.com.br">Media 
      Kit</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://fale.ubbi.com.br=
/comercial.asp">Anuncie 
      no Ubbi</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href=3D"http://www.ubbi.com=
.br/fale/fale.asp">Fale 
      conosco</a>&nbsp;</td>
  </tr>
</table>
<table width=3D"100%" border=3D"0" align=3D"center" cellpadding=3D"0" ce=
llspacing=3D"0" style=3D"background-color: #A8A9E6">
  <tr> 
    <td><img src=3D"0.gif" width=3D"1" height=3D"1"></td>
  </tr>
</table>
<table width=3D"100%" border=3D"0" align=3D"center" cellpadding=3D"0" ce=
llspacing=3D"0">
  <tr> 
    <td><img src=3D"0.gif" width=3D"1" height=3D"6"></td>
  </tr>
</table></td>
    </tr>
</table>
</BODY></HTML>

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Mon Apr 04 15:29:24 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIRdr-0005gO-Bj; Mon, 04 Apr 2005 15:29:23 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Mon, 04 Apr 2005 15:28:59 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIRdH-0005f4-BH
	for linux-crypto@nl.linux.org; Mon, 04 Apr 2005 15:28:47 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id 00A1050818E
	for <linux-crypto@nl.linux.org>; Mon,  4 Apr 2005 15:29:03 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <20050401143545.4bc20196@insula.localdomain>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
X-Mailer: Sylpheed-Claws 1.0.4 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Message-Id: <20050404132903.00A1050818E@mailrelay1.bredband.net>
Date: Mon,  4 Apr 2005 15:29:03 +0200 (CEST)
Received-SPF: 
X-Spam-Status: No, score=0.3 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

I've stumbled upon a problem that I didn't think would appear.

For some reason losetup complains that I haven't got AES in kernel which
I know is a lie.
I've tried recompiling my kernel several times.
I've recompiled loop-aes several times
I've tried debians loop-aes-utils
I've compiled it like the README does it.

The odd thing is it worked just a day or so ago.
Could it have something to do with my installing 2.6.11 instead of
2.6.8?

This is my command and error.
# losetup -e AES256 -K key.gpg /dev/loop7 runner 

ioctl: LOOP_SET_STATUS: Invalid argument, requested cipher or key length
(256 bits) not supported by kernel

When trying to mount the loop module built by loop-aes I get another
error.

FATAL: Error inserting loop (/lib/modules/2.6.11.6/block/loop.ko):
Input/output error

It also complains about some major 7 thing so I'm thinking this might
have something to do with aliasing even though it says in the tutorial
you shouldn't need to alias.

# CONFIG_BLK_DEV_LOOP is not set
CONFIG_CRYPTO=y
CONFIG_CRYPTO_SHA1=y
CONFIG_CRYPTO_SHA256=y
CONFIG_CRYPTO_SHA512=y
CONFIG_CRYPTO_TWOFISH=y
CONFIG_CRYPTO_AES_586=y
CONFIG_CRYPTO_TEST=y

What is happening here?

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Mon Apr 04 15:58:05 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIS5c-0008OU-0D; Mon, 04 Apr 2005 15:58:04 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Mon, 04 Apr 2005 15:57:52 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIS5E-0008O1-Ht
	for linux-crypto@nl.linux.org; Mon, 04 Apr 2005 15:57:40 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 2AA3B4DE6;
	Mon,  4 Apr 2005 16:57:39 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 31572-06; Mon,  4 Apr 2005 16:57:32 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 8A6AF41E1;
	Mon,  4 Apr 2005 16:57:32 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DIS56-000177-00; Mon, 04 Apr 2005 16:57:32 +0300
Message-ID: <425147CB.4E66ED1D@users.sourceforge.net>
Date: Mon, 04 Apr 2005 16:57:31 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk>
			<20050401143545.4bc20196@insula.localdomain> <20050404132903.00A1050818E@mailrelay1.bredband.net>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50,UPPERCASE_25_50 
	autolearn=no version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> ioctl: LOOP_SET_STATUS: Invalid argument, requested cipher or key lengt=
h
> (256 bits) not supported by kernel

Above means that loop driver does not support crypto.

> FATAL: Error inserting loop (/lib/modules/2.6.11.6/block/loop.ko):
> Input/output error

Above means that there is already a loop driver in your kernel.

Most likely you booted wrong kernel image.
What does "uname -a" say?

> CONFIG_CRYPTO=3Dy
> CONFIG_CRYPTO_SHA1=3Dy
> CONFIG_CRYPTO_SHA256=3Dy
> CONFIG_CRYPTO_SHA512=3Dy
> CONFIG_CRYPTO_TWOFISH=3Dy
> CONFIG_CRYPTO_AES_586=3Dy
> CONFIG_CRYPTO_TEST=3Dy
>=20
> What is happening here?

loop-AES does not need any of above.

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Mon Apr 04 18:31:22 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIUTx-0008GW-FU; Mon, 04 Apr 2005 18:31:21 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Mon, 04 Apr 2005 18:30:59 +0200 (CEST)
Received: from mailrelay1.bredband.net ([195.54.107.81])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIUTS-0008Fg-4a
	for linux-crypto@nl.linux.org; Mon, 04 Apr 2005 18:30:50 +0200
Received: from insula.localdomain (ua-83-227-221-136.cust.bredbandsbolaget.se [83.227.221.136])
	by mailrelay1.bredband.net (Postfix) with ESMTP id B07CD508145
	for <linux-crypto@nl.linux.org>; Mon,  4 Apr 2005 18:31:04 +0200 (CEST)
From: Gabriel =?ISO-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
In-Reply-To: <20050404132903.00A1050818E@mailrelay1.bredband.net>
References: <91a4537e34f7346374f29e04622fc834@evinrude>
	<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
	<87wts7y4vh.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
	<87oedhx7aa.fsf@evinrude.uhoreg.ca>
	<87r7i749uc.fsf@evinrude.uhoreg.ca>
	<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
	<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
	<20050330235650.GC12080@black-sun.demon.co.uk>
	<20050401143545.4bc20196@insula.localdomain>
	<20050404132903.00A1050818E@mailrelay1.bredband.net>
X-Mailer: Sylpheed-Claws 1.0.4 (GTK+ 1.2.10; i386-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Message-Id: <20050404163104.B07CD508145@mailrelay1.bredband.net>
Date: Mon,  4 Apr 2005 18:31:04 +0200 (CEST)
Received-SPF: 
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=0.2 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Hi!

Me again. I've gotten half way through the tutorial and found something
that made me unsure.

In 7.7.10a it says you should set CRYPTROOT to /dev/hda2
How is this?

I'm going to wipe my entire drive and set up it all using losetup 
so what is CRYPTROOT for?



-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Mon Apr 04 18:46:07 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIUiD-0000qw-F6; Mon, 04 Apr 2005 18:46:05 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Mon, 04 Apr 2005 18:45:58 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIUhu-0000q0-70
	for linux-crypto@nl.linux.org; Mon, 04 Apr 2005 18:45:46 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 5EBEB2C48D;
	Mon,  4 Apr 2005 19:45:41 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 09520-07; Mon,  4 Apr 2005 19:45:34 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 839FB41E4;
	Mon,  4 Apr 2005 19:45:34 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DIUhi-0001FE-00; Mon, 04 Apr 2005 19:45:34 +0300
Message-ID: <42516F2D.55AF7883@users.sourceforge.net>
Date: Mon, 04 Apr 2005 19:45:33 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Gabriel =?iso-8859-1?Q?J=E4genstedt?= <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Partitions on loopback
References: <91a4537e34f7346374f29e04622fc834@evinrude>
			<Pine.LNX.4.61L.0503151548100.28930@imladris.surriel.com>
			<87wts7y4vh.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503161846370.19738@imladris.surriel.com>
			<87oedhx7aa.fsf@evinrude.uhoreg.ca>
			<87r7i749uc.fsf@evinrude.uhoreg.ca>
			<87sm2c7ra6.fsf@evinrude.uhoreg.ca>
			<Pine.LNX.4.61L.0503301832420.5147@imladris.surriel.com>
			<20050330235650.GC12080@black-sun.demon.co.uk>
			<20050401143545.4bc20196@insula.localdomain>
			<20050404132903.00A1050818E@mailrelay1.bredband.net> <20050404163104.B07CD508145@mailrelay1.bredband.net>
Content-Type: text/plain; charset=iso-8859-1
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Content-Transfer-Encoding: quoted-printable
Received-SPF: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Gabriel J=E4genstedt wrote:
> In 7.7.10a it says you should set CRYPTROOT to /dev/hda2
> How is this?
>=20
> I'm going to wipe my entire drive and set up it all using losetup
> so what is CRYPTROOT for?

It is the backing device of loop. In normal partitioned case:

CRYPTROOT=3D/dev/hda2

Or in no-partition-table case:

CRYPTROOT=3D/dev/hda
PSEED=3D"-o @32256 -s 24643584"

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 =
DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Tue Apr 05 09:23:44 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIiPW-0000RC-GF; Tue, 05 Apr 2005 09:23:42 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Tue, 05 Apr 2005 09:23:12 +0200 (CEST)
Received: from pne-smtpout2-sn1.fre.skanova.net ([81.228.11.159])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIiOt-0000QN-81
	for linux-crypto@nl.linux.org; Tue, 05 Apr 2005 09:23:03 +0200
Received: from pne-ps3-sn1 (81.228.11.74) by pne-smtpout2-sn1.fre.skanova.net (7.1.026.7)
        id 41E3209600A44038 for linux-crypto@nl.linux.org; Tue, 5 Apr 2005 09:22:49 +0200
Message-ID: <20068575.1112685769619.JavaMail.tomcat@pne-ps3-sn1>
Date: Tue, 5 Apr 2005 09:22:49 +0200 (MEST)
From: gabriel <gabriel.j@telia.com>
Reply-To: gabriel <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Multi-Key in Knoppix
Mime-Version: 1.0
Content-Type: text/plain;charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Mailer: CP Presentation Server
X-clientstamp: [83.227.221.136]
Received-SPF: 
X-Spam-Status: No, score=2.1 required=5.0 tests=BAYES_80 autolearn=no 
	version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Level: **
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Hi!

Ive gotten to the point where Ive shreded my entire drive and Im currently running from 
knoppix trying to set up the loopback devices. 

I stumbled upon an error with multi-key v3 when running the following

#./losetup -e AES256 -K rootkey.gpg -o @32256 -s 1003451904 /dev/loop0 /dev/hda

run from the usb-stick

after entering the passphrase I get this.
ioctl: LOOP_MULTI_KEY_SETUP_V3: Invalid argument

Im unsure what part of the setup is responsible for this but I guess its losetups 
fault

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Tue Apr 05 17:17:15 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIpnl-0003TU-Bt; Tue, 05 Apr 2005 17:17:13 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Tue, 05 Apr 2005 17:16:30 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIpmt-0003So-NR
	for linux-crypto@nl.linux.org; Tue, 05 Apr 2005 17:16:19 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id 01F162F230;
	Tue,  5 Apr 2005 18:16:09 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 03904-13; Tue,  5 Apr 2005 18:16:01 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 314482C497;
	Tue,  5 Apr 2005 18:16:01 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DIpma-0001zM-00; Tue, 05 Apr 2005 18:16:00 +0300
Message-ID: <4252ABB0.F838A8F@users.sourceforge.net>
Date: Tue, 05 Apr 2005 18:16:00 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: gabriel <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Multi-Key in Knoppix
References: <20068575.1112685769619.JavaMail.tomcat@pne-ps3-sn1>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Received-SPF: 
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=0.3 required=5.0 tests=AWL,BAYES_60 autolearn=no 
	version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

gabriel wrote:
> #./losetup -e AES256 -K rootkey.gpg -o @32256 -s 1003451904 /dev/loop0 /dev/hda
> 
> run from the usb-stick
> 
> after entering the passphrase I get this.
> ioctl: LOOP_MULTI_KEY_SETUP_V3: Invalid argument

Above means that loop driver of knoppix does not support version 3 on-disk
format.

-- 
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Tue Apr 05 19:41:08 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIs30-00002L-Th; Tue, 05 Apr 2005 19:41:06 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Tue, 05 Apr 2005 19:40:45 +0200 (CEST)
Received: from pne-smtpout2-sn2.hy.skanova.net ([81.228.8.164])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIs2U-0008VD-Ic
	for linux-crypto@nl.linux.org; Tue, 05 Apr 2005 19:40:34 +0200
Received: from pne-ps3-sn1 (81.228.11.74) by pne-smtpout2-sn2.hy.skanova.net (7.1.026.7)
        id 41E3223E00A4FBA0 for linux-crypto@nl.linux.org; Tue, 5 Apr 2005 19:40:23 +0200
Message-ID: <20775140.1112722822919.JavaMail.tomcat@pne-ps3-sn1>
Date: Tue, 5 Apr 2005 19:40:22 +0200 (MEST)
From: gabriel <gabriel.j@telia.com>
Reply-To: gabriel <gabriel.j@telia.com>
To: linux-crypto@nl.linux.org
Subject: Sv: Re: Multi-Key in Knoppix
Mime-Version: 1.0
Content-Type: text/plain;charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Mailer: CP Presentation Server
X-clientstamp: [83.227.221.136]
Received-SPF: 
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=2.1 required=5.0 tests=AWL,BAYES_95 autolearn=no 
	version=3.0.1
X-Spam-Level: **
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: gabriel.j@telia.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Darned.=20

I chose knoppix because it had support for loop-aes and now I find out its=
=20
not the right support.
Crap!
Do you know of any good boot discs that are available for download that=20
would do all I need to encrypt my hda?

----Ursprungligt meddelande----
Fr=E5n: jariruusu@users.sourceforge.net
Datum: Apr 5, 2005 5:16:00 PM
Till: gabriel <gabriel.j@telia.com>
Kopia: linux-crypto@nl.linux.org
=C4rende: Re: Multi-Key in Knoppix

gabriel wrote:
> #./losetup -e AES256 -K rootkey.gpg -o @32256 -s 1003451904 /dev/loop0 /d=
ev/hda
>=20
> run from the usb-stick
>=20
> after entering the passphrase I get this.
> ioctl: LOOP_MULTI_KEY_SETUP_V3: Invalid argument

Above means that loop driver of knoppix does not support version 3 on-disk
format.

--=20
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9=20
DD




-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Tue Apr 05 19:52:29 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIsE0-00015I-Bb; Tue, 05 Apr 2005 19:52:28 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Tue, 05 Apr 2005 19:52:18 +0200 (CEST)
Received: from mail.tnnet.fi ([217.112.240.26])
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIsDh-00014i-0M
	for linux-crypto@nl.linux.org; Tue, 05 Apr 2005 19:52:09 +0200
Received: from localhost (localhost [127.0.0.1])
	by mail.tnnet.fi (Postfix) with ESMTP id D19422C48F;
	Tue,  5 Apr 2005 20:52:02 +0300 (EEST)
Received: from mail.tnnet.fi ([127.0.0.1])
 by localhost (mail [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
 id 14223-10; Tue,  5 Apr 2005 20:51:56 +0300 (EEST)
Received: from armas (a64.adsl.tnnet.fi [217.112.242.64])
	by mail.tnnet.fi (Postfix) with ESMTP id 1E5741902FD;
	Tue,  5 Apr 2005 20:50:42 +0300 (EEST)
Received: from localhost ([127.0.0.1] helo=users.sourceforge.net)
	by armas with esmtp (Exim) id 1DIsCH-00025G-00; Tue, 05 Apr 2005 20:50:41 +0300
Message-ID: <4252CFF1.A10A27E3@users.sourceforge.net>
Date: Tue, 05 Apr 2005 20:50:41 +0300
From: Jari Ruusu <jariruusu@users.sourceforge.net>
X-Mailer: Mozilla 4.79 [en] (X11; U; Linux 2.4.22aa1r9 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: gabriel <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
Subject: Re: Multi-Key in Knoppix
References: <20775140.1112722822919.JavaMail.tomcat@pne-ps3-sn1>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: amavisd-new at mail.tnnet.fi
Received-SPF: 
X-Spam-Level: 
X-Spam-Status: No, score=0.1 required=5.0 tests=AWL,BAYES_50 autolearn=no 
	version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: jariruusu@users.sourceforge.net
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

gabriel wrote:
> I chose knoppix because it had support for loop-aes and now I find out its
> not the right support.
> Crap!
> Do you know of any good boot discs that are available for download that
> would do all I need to encrypt my hda?

Example how to encrypt partition-table-less file system using aespipe on
knoppix:

./losetup -o @32256 -s 1003451904 /dev/loop0 /dev/hda
dd if=/dev/loop0 bs=1024k | ./aespipe -e AES256 -K rootkey.gpg -G / | dd of=/dev/loop0 bs=1024k conv=notrunc
./losetup -d /dev/loop0

-- 
Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 DD

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Tue Apr 05 23:16:25 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DIvPL-00045f-T5; Tue, 05 Apr 2005 23:16:23 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Tue, 05 Apr 2005 23:15:53 +0200 (CEST)
Received: from pop.gmx.de ([213.165.64.20] helo=mail.gmx.net)
	by humbolt.nl.linux.org with smtp (Exim 4.22)
	id 1DIvOb-0003wd-3U
	for linux-crypto@nl.linux.org; Tue, 05 Apr 2005 23:15:37 +0200
Received: (qmail 32147 invoked by uid 0); 5 Apr 2005 21:13:55 -0000
Received: from 84.175.25.74 by www2.gmx.net with HTTP;
	Tue, 5 Apr 2005 23:13:55 +0200 (MEST)
Date: Tue, 5 Apr 2005 23:13:55 +0200 (MEST)
From: Peter_22@gmx.de
To: gabriel <gabriel.j@telia.com>
Cc: linux-crypto@nl.linux.org
MIME-Version: 1.0
References: <20775140.1112722822919.JavaMail.tomcat@pne-ps3-sn1>
Subject: Re: Sv: Re: Multi-Key in Knoppix
X-Priority: 3 (Normal)
X-Authenticated: #5663700
Message-ID: <11889.1112735635@www2.gmx.net>
X-Mailer: WWW-Mail 1.6 (Global Message Exchange)
X-Flags: 0001
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
Received-SPF: 
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-Spam-Status: No, score=1.1 required=5.0 tests=AWL,BAYES_60,NO_REAL_NAME 
	autolearn=no version=3.0.1
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: Peter_22@gmx.de
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto

Hi!

Maybe you can still try to use your Knoppix CD with loop-aes in version 2 or
1 on-disk format.
If you donīt want that you might try spb-linux and build your own knoppix
with all the software and features you want.

Regards,
Peter

> Darned. 
> 
> I chose knoppix because it had support for loop-aes and now I find out its
> not the right support.
> Crap!
> Do you know of any good boot discs that are available for download that 
> would do all I need to encrypt my hda?
> 
> ----Ursprungligt meddelande----
> Från: jariruusu@users.sourceforge.net
> Datum: Apr 5, 2005 5:16:00 PM
> Till: gabriel <gabriel.j@telia.com>
> Kopia: linux-crypto@nl.linux.org
> Ärende: Re: Multi-Key in Knoppix
> 
> gabriel wrote:
> > #./losetup -e AES256 -K rootkey.gpg -o @32256 -s 1003451904 /dev/loop0
> /dev/hda
> > 
> > run from the usb-stick
> > 
> > after entering the passphrase I get this.
> > ioctl: LOOP_MULTI_KEY_SETUP_V3: Invalid argument
> 
> Above means that loop driver of knoppix does not support version 3 on-disk
> format.
> 
> -- 
> Jari Ruusu  1024R/3A220F51 5B 4B F9 BB D3 3F 52 E9  DB 1D EB E3 24 0E A9 
> DD
> 
> 
> 
> 
> -
> Linux-crypto:  cryptography in and on the Linux system
> Archive:       http://mail.nl.linux.org/linux-crypto/
> 

-- 
Sparen beginnt mit GMX DSL: http://www.gmx.net/de/go/dsl

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Fri Apr 08 07:00:07 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DJlbA-0002jx-BC; Fri, 08 Apr 2005 07:00:04 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Fri, 08 Apr 2005 06:59:32 +0200 (CEST)
Received: from bayc1-pasmtp01.bayc1.hotmail.com ([65.54.191.161] helo=BAYC1-PASMTP01.cez.ice)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DJlaR-0002ih-Jx
	for linux-crypto@nl.linux.org; Fri, 08 Apr 2005 06:59:19 +0200
Message-ID: <BAYC1-PASMTP01FFAF9FC8C26CB165FA4BAE3F0@cez.ice>
X-Originating-IP: [70.48.174.122]
X-Originating-Email: [tremblay52@sympatico.ca]
Received: from [192.168.0.102] ([70.48.174.122]) by BAYC1-PASMTP01.cez.ice over TLS secured channel with Microsoft SMTPSVC(6.0.3790.211);
	 Thu, 7 Apr 2005 22:01:36 -0700
Subject: Question about other aspects of security relating to encryption
From: Antoine Tremblay <hexa@kayaksoft.com>
Reply-To: hexa@kayaksoft.com
To: linux-crypto@nl.linux.org
Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-F3StNoWTvcaId1CDfs7N"
Organization: Openrapids
Date: Fri, 08 Apr 2005 00:58:47 -0400
Message-Id: <1112936327.1056.20.camel@localhost.localdomain>
Mime-Version: 1.0
X-Mailer: Evolution 2.0.4 
X-OriginalArrivalTime: 08 Apr 2005 05:01:36.0828 (UTC) FILETIME=[0AC10FC0:01C53BF8]
Received-SPF: 
X-Spam-Level: **
X-Spam-Status: No, score=2.6 required=5.0 tests=BAYES_50,FORGED_HOTMAIL_RCVD,
	MSGID_FROM_MTA_HEADER autolearn=no version=3.0.1
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on 
	humbolt.nl.linux.org
X-ecartis-version: Ecartis v1.0.0
Sender: linux-crypto-bounce@nl.linux.org
Errors-to: linux-crypto-bounce@nl.linux.org
X-original-sender: hexa@kayaksoft.com
Precedence: bulk
List-help: <mailto:ecartis@nl.linux.org?Subject=help>
List-unsubscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: <linux-crypto.nl.linux.org>
X-List-ID: <linux-crypto.nl.linux.org>
List-subscribe: <mailto:linux-crypto-request@nl.linux.org?Subject=subscribe>
List-owner: <mailto:ecartis-owner@nl.linux.org>
List-post: <mailto:linux-crypto@nl.linux.org>
List-archive: <http://mail.nl.linux.org/linux-crypto/>
X-list: linux-crypto


--=-F3StNoWTvcaId1CDfs7N
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Hi ,
  I'm experimenting with loop-AES, and I really like it , the doc was
wonderfull too :) thx to all ...

  But i'm wondering something since once the partition has been mounted
it's available for reading to the valid user in clear what would happen
if someone were to access a computer that is already logged in with a
valid user, or someone that would root the machine remotly and gain
access to the mounted partition ?=20

 I guess encryption won't be usefull againts these 2 attacks but maybe
something could be done to minimise the risk.... ?

 I'm thinking like to unmount the partition on usb stick removal or
xwindow lock ? Sure I could do I by hand, i'm just wondering ...  :)

Thanks

Antoine




--=-F3StNoWTvcaId1CDfs7N
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQBCVg+HxHrS3d8+k70RAkLLAKCJMomSprs/B8Eu26O49PnKCW1ruQCeMEqE
7cH+LLJMgNsdrGifTjvw/AA=
=8xjf
-----END PGP SIGNATURE-----

--=-F3StNoWTvcaId1CDfs7N--


-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/



From linux-crypto-bounce@nl.linux.org Sat Apr 09 23:31:07 2005
Received: from localhost ([127.0.0.1] helo=humbolt)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DKNXk-0005g5-3f; Sat, 09 Apr 2005 23:31:04 +0200
Received: with ECARTIS (v1.0.0; list linux-crypto); Sat, 09 Apr 2005 23:30:13 +0200 (CEST)
Received: from services106.cs.uwaterloo.ca ([129.97.152.164] ident=root)
	by humbolt.nl.linux.org with esmtp (Exim 4.22)
	id 1DKNWd-0005dr-LX
	for linux-crypto@nl.linux.org; Sat, 09 Apr 2005 23:29:55 +0200
Received: from hopper.math.uwaterloo.ca (daemon@hopper.math.uwaterloo.ca [129.97.78.132])
	by services106.cs.uwaterloo.ca (8.11.7/8.11.7) with ESMTP id j39LTdV25904;
	Sat, 9 Apr 2005 17:29:39 -0400 (EDT)
Received: (from hy3chan@localhost)
	by hopper.math.uwaterloo.ca (8.11.7/8.11.7) id j39LTa124824;
	Sat, 9 Apr 2005 17:29:36 -0400 (EDT)
X-Mailer: emacs 21.4.1 (via feedmail 8 I)
To: hexa@kayaksoft.com, linux-crypto@nl.linux.org
Subject: Re: Question about other aspects of security relating to encryption
From: Hubert Chan <hubert@uhoreg.ca>
In-Reply-To: <BAYC1-PASMTP01FFAF9FC8C26CB165FA4BAE3F0@cez.ice> (Antoine
 Tremblay's message of "Fri, 08 Apr 2005 00:58:47 -0400")
References: <BAYC1-PASMTP01FFAF9FC8C26CB165FA4BAE3F0@cez.ice>
X-Hashcash: 1:23:050409:hexa@kayaksoft.com::5NDCW+1iK7PE68W3:00000000000000000000000000000000000000000002sU5
X-Hashcash: 1:23:050409:linux-crypto@nl.linux.org::rvbgRsOzF+K4ILGN:000000000000000000000000000000000000h5wZ
Date: Sat, 09 Apr 2005 17:29:29 -0400
Message-ID: <874qef1vwm.fsf@evinrude.uhoreg.ca>
User-Agent: Gnus/5.1007 (Gnus v5.10.7) Emacs/21.4 (gnu/linux)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-=";
	micalg=pgp-sha1; protocol="application/pgp-signature"
X-Miltered: at aeacus with ID