Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 20 Aug 2014 11:05:57 -0400
From:      "Michael W. Lucas" <mwlucas@michaelwlucas.com>
To:        questions@freebsd.org
Subject:   geli keyfile not loading at boot
Message-ID:  <20140820150557.GA90970@bewilderbeast.blackhelicopters.org>

next in thread | raw e-mail | index | archive | help
Hi,

I have a default FreeBSD 10.0/amd64 install.

I'm trying to make a GELI device attach at boot. I initialized the
partition with -b, and am prompted at boot. When I try to enter the
passphrase, I keep getting told that it's incorrect. Once I get into
multi-user mode and manually attach the device, it attaches just fine.

It seems that GELI isn't finding my key file.

My initial root partition is da0p2. The key is /boot/da1p1.key. The
GELI partition is da1p1. Here's my loader.conf:

geom_eli_load=YES
geli_da1p1_keyfile0_load="YES"
geli_da1p1_keyfile0_type="da0p2:geli_da1p1_keyfile0"
geli_da1p1_keyfile0_name="/boot/da1p1.key"
kern.geom.eli.debug=3

Any suggestions? What am I doing wrong here?

(Yes, I could just use the installer to do an encrypted install, but
then I wouldn't be able to write about this in a book...)

Thanks,
==ml

-- 
Michael W. Lucas  -  mwlucas@michaelwlucas.com, Twitter @mwlauthor 
http://www.MichaelWLucas.com/, http://blather.MichaelWLucas.com/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20140820150557.GA90970>