Re: Encrypted Root with F11

2009-06-30 Thread Brian Mearns
No, I didn't have a custom kernel, it was the one that shipped with
F11, though I also tried with the first kernel update after that, not
sure what version it was. Like I said, I reinstalled and started with
encrypted root, so I can't reproduce the issue anymore.

-Brian

On Mon, Jun 29, 2009 at 2:37 PM, davide wrote:
> Il Sun, 28 Jun 2009 11:07:36 -0400, Brian Mearns ha scritto:
>
>> Thanks for the continued assistance, Davide. My cipher is the same as
>> yours. I'm going to try making my initrd module order match yours, and
>> see if that helps.
>
> Hi, Brian.
> I'm interested in crypto and software issues, and I'm new in fedora
> world, so I really enjoy your problem ;-)
>
> A question: do you have a custom kernel? if so, try with a fedora one,
> I'm using it and it has all the stuff needed by this crypto setup.
>
> Let me know.
>
> --
> fedora-list mailing list
> fedora-list@redhat.com
> To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
> Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines
>



-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-29 Thread Brian Mearns
Well, thanks for the efforts to assist on this, I decided to just bite
the bullet over the weekend, and re-installed F11 from the Live-CD,
starting right off the bat with an encrypted root, and it works fine.
Hopefully the tools will exist in the near future to more easily
introduce root-drive encryption after installation, but now that it's
re-installed, it's working fine.

-Brian

On Sun, Jun 28, 2009 at 11:07 AM, Brian Mearns wrote:
> On Fri, Jun 26, 2009 at 11:04 AM, davide wrote:
>> davide  gmail.com> writes:
>>
>>> choosed
>>
>> oh my gosh! sorry!
>>
>>
>>
>>
>> --
>> fedora-list mailing list
>> fedora-list@redhat.com
>> To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
>> Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines
>>
>
>
> Thanks for the continued assistance, Davide. My cipher is the same as
> yours. I'm going to try making my initrd module order match yours, and
> see if that helps.
>
> -Brian
>
> --
> Feel free to contact me using PGP Encryption:
> Key Id: 0x3AA70848
> Available from: http://keys.gnupg.net
>



-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-28 Thread Brian Mearns
On Fri, Jun 26, 2009 at 11:04 AM, davide wrote:
> davide  gmail.com> writes:
>
>> choosed
>
> oh my gosh! sorry!
>
>
>
>
> --
> fedora-list mailing list
> fedora-list@redhat.com
> To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
> Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines
>


Thanks for the continued assistance, Davide. My cipher is the same as
yours. I'm going to try making my initrd module order match yours, and
see if that helps.

-Brian

-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: [was (no subject)] Wireless in F11

2009-06-26 Thread Brian Mearns
On Fri, Jun 26, 2009 at 9:30 AM, Timothy Murphy wrote:
> Brian Mearns wrote:
>
>> In my experience, Linux is still somewhat immature in the wireless
>> area, but does seem to be catching up rapidly (this is obviously a
>> pretty high demand area). As with most linux-hardware issues, the real
>> problem is vendor support for the Linux kernel.
>
> That does not seem to me to be relevant
> unless you intend to use vendor-supplied drivers.
> In my experience this is bound to cause problems sooner or later,
> unless you have decided you will never update your system.
>
>
> --
> Timothy Murphy
> e-mail: gayleard /at/ eircom.net
> tel: +353-86-2336090, +353-1-2842366
> s-mail: School of Mathematics, Trinity College Dublin
[clipped]

I didn't specifically mean vendor-supplied drivers, I meant vendor
support of the Linux community so that proper drivers can be written.
Like HP, for instance, has a pretty good connection to the Linux/Unix
community and has apparently been pretty forthcoming with information
in support of linux drivers for HP printers. But, as far as I know,
the drivers are not actually written by HP.

-Brian

-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-26 Thread Brian Mearns
On Thu, Jun 25, 2009 at 8:47 PM, Robert L Cochran wrote:
> Umm, you know the /boot partition has to be ext3? Grub cannot handle an ext4
> /boot. I know this has not a thing to do with encryption, but I thought I'd
> ask just to be sure.
>
> Bob

Thanks, Bob. I'm not positive off hand what my /boot partition is (not
at home right now), but I'm fairly sure it's ext3. Specifically, I
/am/ able to boot this system using the same /boot as long as I don't
try to load the kernel with an encrypted root.

-Brian

-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-26 Thread Brian Mearns
On Thu, Jun 25, 2009 at 8:23 PM, Brian Mearns wrote:
> On Thu, Jun 25, 2009 at 5:20 PM, davide wrote:
>> Il Thu, 25 Jun 2009 11:28:14 -0400, Brian Mearns ha scritto:
>>
>>> On Thu, Jun 25, 2009 at 11:03 AM, davide wrote:
>>>> Brian Mearns  ieee.org> writes:
>>>>
>>>>
>>>>> Thanks for the response, Davide. /boot is a seperate, non-LVM
>>>>> partition with its own ext3 fs. I know F11 has options for encrypting
>>>>> during setup, but I've already got it set up, and would now like to go
>>>>> back and switch over to an excrypted root filesystem without having to
>>>>> reinstall. I think your suggestion of using a Live CD implies that I
>>>>> would reinstall Fedora, which I don't want to do.
>>>>
>>>> have you all the needed modules compiled into the kernel or into the
>>>> initrd? otherwise I would give a look at /etc/crypttab and /etc/fstab
>>>>
>>>>
>>>>
>>>>> Also, it's not grub asking for the root, I'm referring to the "root"
>>>>> parameter for the kernel.
>>>>
>>>> Yes, I think you mean the root parameter into the grub config, it is a
>>>> parameter for the kernel. I would suppose is used by the kernel to find
>>>> out where are modules and filesystem.
>>> [clipped]
>>>
>>> Thanks, again, Davide.
>>>
>>> crypttab and fstab should be fine, as init is able to mount the device
>>> correctly. I'm not sure if I have all the correct modules: I ran
>>> mkinitrd with "--with=aes --with=sha256" and tried to boot using the
>>> generated initrd.img, but perhaps there are additional modules I need?
>>>
>>> Thanks,
>>
>> thanks to Robert, I opened the init, I copy here the relevant part.
>> tell me if it helps, or I can try to investigate more deeply.
>>
>>
>> echo Creating block device nodes.
>> mkblkdevs
>> echo Creating character device nodes.
>> mkchardevs
>> echo "Loading dm-crypt module"
>> modprobe -q dm-crypt
>> echo "Loading aes module"
>> modprobe -q aes
>> echo "Loading cbc module"
>> modprobe -q cbc
>> echo "Loading sha256 module"
>> modprobe -q sha256
>> echo "Loading pata_acpi module"
>> modprobe -q pata_acpi
>> echo "Loading ata_generic module"
>> modprobe -q ata_generic
>> echo Making device-mapper control node
>> mkdmnod
>> modprobe scsi_wait_scan
>> rmmod scsi_wait_scan
>> mkblkdevs
> [clipped]
>
> I'm back home and can get some additional information about this.
> Attempting to boot using the "crypto-initrd.img", which I generated
> with "mkinitrd --with=aes --with=sha256" and specifying the
> LUKS/cryptsetup encrypted drive for the kernel's "root" parameter, the
> boot process gets to the point of asking me for a password, then
> mentions a few things about an EXT4-fs (not sure which one, but no
> error's reported here), then gives the following messages before
> hanging:
>
> SELinux:  policydb magic number 0xe4f0 does not match expected
> magic number 0xf97cff8c
> request_module: runaway loop modprobe binfmt-
> request_module: runaway loop modprobe binfmt-
> request_module: runaway loop modprobe binfmt-
> request_module: runaway loop modprobe binfmt-
> request_module: runaway loop modprobe binfmt-
>
> I am able to restart the system uneventfully at this point by pressing
> ctrl-alt-del.
>
> Attempting to boot with the same initrd img, but specifying an
> unecrypted partition for the kernel's "root" parameter, it all comes
> up fine, but does still ask me for a password during boot.
>
> I'm going to attempt to debug my initrd img, as suggested, but I'm not
> sure how well I'll be able to understand the script. So if anyone has
> any additional advice, I'd really appreciate it.
>
> Thanks, again.
> -Brian
[clipped]

Well, I opened my initrd init-script, but very little of it means
anything to me. Davide indicated a certain section in his script as
relevant, so I've included that section of mine. It's a bit different,
but I'm not sure if that's relevant:

###
   echo Creating block device nodes.
   mkblkdevs
   echo Creating character device nodes.
   mkchardevs
   echo "Loading aes module"
   modprobe -q aes
   echo "Loading cbc module"
   modprobe -q cbc
   echo "Loadin

Re: [was (no subject)] Wireless in F11

2009-06-26 Thread Brian Mearns
On Fri, Jun 26, 2009 at 7:22 AM, z3...@libero.it wrote:
> Hi,
> i'm a new user of Fedora 'cause I was using another distribution of linux
>
> and i want to put F11 on my laptop (Hp 6735s) but I tryed the live version and
>
> the wifi is not working...i wanna jnow if is just a live problem and if is 
> like
>
> that installing F11 the problem will be solved or is a problem with the
>
> wireless hardware (Broadcom 802.11). Are just some months that i'm using linux
>
> and i'm not so good at it.
> thank's to everybody!
> ivan
[clipped]

In my experience, Linux is still somewhat immature in the wireless
area, but does seem to be catching up rapidly (this is obviously a
pretty high demand area). As with most linux-hardware issues, the real
problem is vendor support for the Linux kernel.

But I digress. I'm guessing the problem will not magically solve
itself just by installing F11, but I can't say for sure. I think
certain wireless devices just aren't supported in Linux yet, but if
you already had it working in another distro, then that's probably not
the issue. Personally, I've only tried a few different wireless
devices with linux, but the only one that I could get to work was the
Linksys WUSB54GC USB Wireless network adapter, but I think any device
that uses Ralink rt73 chipset has good support in Linux. Specifically,
the drivers for this chipset are part of the Fedora distro: I just
recently installed F11 and didn't have to do anything special, the USB
wireless adapter just worked. Info on what other chipsets/devices
currently enjoy Linux support are avaiable at this page:
http://linux-wless.passys.nl/query_hostif.php

Hope that helps some.
-Brian

-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-25 Thread Brian Mearns
On Thu, Jun 25, 2009 at 5:20 PM, davide wrote:
> Il Thu, 25 Jun 2009 11:28:14 -0400, Brian Mearns ha scritto:
>
>> On Thu, Jun 25, 2009 at 11:03 AM, davide wrote:
>>> Brian Mearns  ieee.org> writes:
>>>
>>>
>>>> Thanks for the response, Davide. /boot is a seperate, non-LVM
>>>> partition with its own ext3 fs. I know F11 has options for encrypting
>>>> during setup, but I've already got it set up, and would now like to go
>>>> back and switch over to an excrypted root filesystem without having to
>>>> reinstall. I think your suggestion of using a Live CD implies that I
>>>> would reinstall Fedora, which I don't want to do.
>>>
>>> have you all the needed modules compiled into the kernel or into the
>>> initrd? otherwise I would give a look at /etc/crypttab and /etc/fstab
>>>
>>>
>>>
>>>> Also, it's not grub asking for the root, I'm referring to the "root"
>>>> parameter for the kernel.
>>>
>>> Yes, I think you mean the root parameter into the grub config, it is a
>>> parameter for the kernel. I would suppose is used by the kernel to find
>>> out where are modules and filesystem.
>> [clipped]
>>
>> Thanks, again, Davide.
>>
>> crypttab and fstab should be fine, as init is able to mount the device
>> correctly. I'm not sure if I have all the correct modules: I ran
>> mkinitrd with "--with=aes --with=sha256" and tried to boot using the
>> generated initrd.img, but perhaps there are additional modules I need?
>>
>> Thanks,
>
> thanks to Robert, I opened the init, I copy here the relevant part.
> tell me if it helps, or I can try to investigate more deeply.
>
>
> echo Creating block device nodes.
> mkblkdevs
> echo Creating character device nodes.
> mkchardevs
> echo "Loading dm-crypt module"
> modprobe -q dm-crypt
> echo "Loading aes module"
> modprobe -q aes
> echo "Loading cbc module"
> modprobe -q cbc
> echo "Loading sha256 module"
> modprobe -q sha256
> echo "Loading pata_acpi module"
> modprobe -q pata_acpi
> echo "Loading ata_generic module"
> modprobe -q ata_generic
> echo Making device-mapper control node
> mkdmnod
> modprobe scsi_wait_scan
> rmmod scsi_wait_scan
> mkblkdevs
[clipped]

I'm back home and can get some additional information about this.
Attempting to boot using the "crypto-initrd.img", which I generated
with "mkinitrd --with=aes --with=sha256" and specifying the
LUKS/cryptsetup encrypted drive for the kernel's "root" parameter, the
boot process gets to the point of asking me for a password, then
mentions a few things about an EXT4-fs (not sure which one, but no
error's reported here), then gives the following messages before
hanging:

SELinux:  policydb magic number 0xe4f0 does not match expected
magic number 0xf97cff8c
request_module: runaway loop modprobe binfmt-
request_module: runaway loop modprobe binfmt-
request_module: runaway loop modprobe binfmt-
request_module: runaway loop modprobe binfmt-
request_module: runaway loop modprobe binfmt-

I am able to restart the system uneventfully at this point by pressing
ctrl-alt-del.

Attempting to boot with the same initrd img, but specifying an
unecrypted partition for the kernel's "root" parameter, it all comes
up fine, but does still ask me for a password during boot.

I'm going to attempt to debug my initrd img, as suggested, but I'm not
sure how well I'll be able to understand the script. So if anyone has
any additional advice, I'd really appreciate it.

Thanks, again.
-Brian


-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-25 Thread Brian Mearns
On Thu, Jun 25, 2009 at 11:03 AM, davide wrote:
> Brian Mearns  ieee.org> writes:
>
>
>> Thanks for the response, Davide. /boot is a seperate, non-LVM
>> partition with its own ext3 fs. I know F11 has options for
>> encrypting during setup, but I've already got it set up, and would
>> now like to go back and switch over to an excrypted root filesystem
>> without having to reinstall. I think your suggestion of using a Live
>> CD implies that I would reinstall Fedora, which I don't want to do.
>
> have you all the needed modules compiled into the kernel or into the initrd?
> otherwise I would give a look at /etc/crypttab and /etc/fstab
>
>
>>
>> Also, it's not grub asking for the root, I'm referring to the "root"
>> parameter for the kernel.
>
> Yes, I think you mean the root parameter into the grub config, it is a 
> parameter
> for the kernel. I would suppose is used by the kernel to find out where are
> modules and filesystem.
[clipped]

Thanks, again, Davide.

crypttab and fstab should be fine, as init is able to mount the device
correctly. I'm not sure if I have all the correct modules: I ran
mkinitrd with "--with=aes --with=sha256" and tried to boot using the
generated initrd.img, but perhaps there are additional modules I need?

Thanks,
-Brian

-- 
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-25 Thread Brian Mearns
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Sometime prior to 09:29 25 Jun 2009, davide
wrote:
> Brian Mearns  ieee.org> writes:
>
>
> > So can anyone help me get this set up properly? I have a basic
> > understanding of the boot process and I guess that something
> > needs to be changed in initrd to tell it to unlock the encrypted
> > root disk before mounting it. But I have no idea how to do that.
>
> you do not mention your /boot partition, where is it? is it on
> a clear (ext3) partition? grub cannot mount a encrypted partition.
>
> I set up a F11 recently with LVM-over-dm-crypt. To do it, I
> followed a nice guide found on the internet, basically you start
> with a live cd (the fedora one), create the dm-crypt volume,
> mount it, create the LVM setup, start the installation, mount
> all the stuff as it is supposed to be mount and it's done.
>
>
> (probably grub ask about the root partition just coz it need it
> for stuff like modules, logs, /dev and so on...)
[clipped]

Thanks for the response, Davide. /boot is a seperate, non-LVM
partition with its own ext3 fs. I know F11 has options for
encrypting during setup, but I've already got it set up, and would
now like to go back and switch over to an excrypted root filesystem
without having to reinstall. I think your suggestion of using a Live
CD implies that I would reinstall Fedora, which I don't want to do.

Also, it's not grub asking for the root, I'm referring to the "root"
parameter for the kernel.

Thanks,
- -Brian

- --
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net


-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJKQ3zCAAoJEHOUulIkSI7catQIALMaL4cqC6a40QJSpRwYbvL8
BSebgkXWGHYWAvBMyEyWDpzOwiY2+ZS821sdtZ4uiG/XIZeEDa8XP4vive1hGwm2
1A1F7AL7y7AwoTc4FZ2xKxDfFsn/Tr45r7TUoYfml/7IaVkUuR9KXYYkHbj1CYOb
055tMUWMYv/VonKLoqTiozfsh9V6QUdwvTqjyrVgJL+R0F84MMcB6uodB6/3+zcK
qpr8316xwySXk1r76Y0G6h+Q1DC8OQIJsLeBt8FK09iGM26ApcXgh3gpO9PrtV9B
a9w+xuHQz2Ampej2/Jun52cM/Ez19FpMqccT2HuHuOetPby9wBd4XKdCIEyHuAw=
=8D50
-END PGP SIGNATURE-

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Re: Encrypted Root with F11

2009-06-25 Thread Brian Mearns
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Sorry, I edited the message after signing it. The signature was
invalid, this was is correct.

On Thu, Jun 25, 2009 at 8:44 AM, Brian Mearns wrote:
> I apologize if this has been asked before, I checked the most recent
> archives and didn't find anything.
>
> I've successfully set up two separate LUKS encrypted logical-volumes,
> one for home and one for root. Everything appeared to be working
> fine, until I tried to delete my old root logical-volume and found
> out it was still in use: the kernel was using it as the root,
> even though mount had then replaced it at / with the encrypted
> one. So I tried simply changing the root parameter to the kernel
> (from grub.conf) so it points to the encrypted one, but when I
> boot, the startup routine stops after a little while and just
> hangs there until I ctrl-alt-del, and then it restarts. I don't
> think it's reaching init, because I haven't seen any of the usual
> "Starting some server... [OK]" messages. I guess that makes sense
> if it's failing to load the root device, it wouldn't get to init.
>
> So can anyone help me get this set up properly? I have a basic
> understanding of the boot process and I guess that something needs
> to be changed in initrd to tell it to unlock the encrypted root
> disk before mounting it. But I have no idea how to do that.
>
> On a related note, can anyone explain what's actually required
> of the root FS loaded by the kernel? I tried setting up just a
> 1GB empty ext3 filesystem to use as the root, and then let mount
> replace it with the encrypted one once init starts, but this also
> caused the startup process to hang: apparently having a filesystem
> alone is insufficient, there actually needs to be some stuff on it?
>
> I'm using Fedora 11 on a Compaq Presario laptop (x86).
>
> Many thanks for any help,
> - -Brian
>
> - --
> Feel free to contact me using PGP Encryption:
> Key Id: 0x3AA70848
> Available from: http://keys.gnupg.net

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJKQ3FxAAoJEHOUulIkSI7cA9AH/1MVKuxOg9udqRBDwxLOQwSM
6A+iEDWZVj5e+oCJg62RNeuh++oZLVpHx8EWvH7G5S5T1NvSvnQomim7kvJgoqei
1+TEhc9iy99isZJ6Qqc+e2CTljXIsb48/nddTc+oWa2LSN1wnRR0x/cBW9tUopro
K4wRwzwa/UcPh/wRPEWFDHXM6Pgbdq/3PVJZR2s0VG9HZAz4hGfxRNSdJeFFcsOz
xvAoOtCifp5ssr2p/+JYKtjTw7e63LVUHh5/ALjCHo89ILcnjos3549b3AOI7MeJ
8kp73u3c6z99TB7+LjydenIRc2l25WYEEkhVFWLRFKJwDYvK/G61l4epde05FF8=
=4Qhh
-END PGP SIGNATURE-

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines


Encrypted Root with F11

2009-06-25 Thread Brian Mearns
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

I apologize if this has been asked before, I checked the most recent
archives and didn't find anything.

I've successfully set up two separate LUKS encrypted logical-volumes,
one for home and one for root. Everything appeared to be working
fine, until I tried to delete my old root logical-volume and found
out it was still in use: the kernel was using it as the root,
even though mount had then replaced it at / with the encrypted
one. So I tried simply changing the root parameter to the kernel
(from grub.conf) so it points to the encrypted one, but when I
boot, the startup routine stops after a little while and just
hangs there until I ctrl-alt-del, and then it restarts. I don't
think it's reaching init, because I haven't seen any of the usual
"Starting some server... [OK]" messages. I guess that makes sense
if it's failing to load the root device, it wouldn't get to init.

So can anyone help me get this set up properly? I have a basic
understanding of the boot process and I guess that something needs
to be changed in initrd to tell it to unlock the encrypted root
disk before mounting it. But I have no idea how to do that.

On a related note, can anyone explain what's actually required
of the root FS loaded by the kernel? I tried setting up just a
1GB empty ext3 filesystem to use as the root, and then let mount
replace it with the encrypted one once init starts, but this also
caused the startup process to hang: apparently having a filesystem
alone is insufficient, there actually needs to be some stuff on it?

I'm using Fedora 11 on a Compaq Presario laptop (x86).

Many thanks for any help,
- -Brian

- --
Feel free to contact me using PGP Encryption:
Key Id: 0x3AA70848
Available from: http://keys.gnupg.net


-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJKQ3DgAAoJEHOUulIkSI7cJQgH/0V4qxE9hMJaLK/79tsczNmP
sDf48rhd0dJGhF+cvHtQg+57F3j0GX6nHYvD6810xApd5eTzALJ2/Ug6BOgC2aL5
dw+kw6rebquyXDCrknsAavxWZNkRJYooTguOSSPIwP2815aAG7wWoecqR+ESzaO3
yQfLM5tUPo+xVkBdlC8NS+UO9+nKFXlfTTO1qCexutwxsJdwSvXJvZ4Hiu2r68jz
7PAtr4QkR1PSUyxpTY08wcZV39s1F+X9WzE99lKoz/KjHymLvSOrkW8kS7OSAyoH
EK5AfujeZ85HMu1Hf2bw4D6OgSq9l2yHTZ8yZpQEIPNrv0+/36JijmN/2MLz4Xs=
=1Na5
-END PGP SIGNATURE-

-- 
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines