Cannot decrypt swap partition with Mandos inside a LV (LVM)

Olivier Molinete olivier at molinete.org
Thu May 29 11:13:36 CEST 2014


 

Hello All,

I've seen that 1.6.5 version has been released and I enjoyed very much
that I can install it directly from the Recompile.se's official
repository without having to renounce to the old (and good) sysvinit on
my Debian Wheezy 7.5. Thank you very much Teddy and Björn :)

My setup is an encrypted partition with 1 VG and 2 LVs inside it. One LV
for the root filesystem (except /boot which has to be in another
mini-partition unencrypted), and the other LV for the swap, both
encrypted.

I think that mandos-client and mandos(-server) are configured
correctly... When the server with the mandos-client reboots, it
automagically gets the passphrase from the mandos(-server) and the LV
with the root partition is decrypted instantly.

But the problem comes when the swap encrypted partition has to be
decrypted... It seems that mandos(-server) does not send the passphrase
in that case (to decrypt the swap partition), and the server with
mandos-client waits forever with the passphrase prompt till you enter
the passphrase manually through the console.

My question is: Am I doing something wrong? Am I missing something?
Maybe it is a Mandos limitation which I don't know, but I haven't found
any info related to that issue in the documentation or googlin'.

Could somebody help me, please?

Thanks in advance!
Olivier Molinete 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.recompile.se/pipermail/mandos-dev/attachments/20140529/cb6a89a8/attachment.html>


More information about the Mandos-Dev mailing list