Re: Feedback on default partitioning and encryption

2020-04-28 Thread Chris Murphy
On Tue, Apr 28, 2020 at 1:52 PM Simo Sorce wrote: > > On Tue, 2020-04-28 at 13:18 -0600, Chris Murphy wrote: > > Long term, many solutions need to be considered. And not only > > technical, but their impact on release engineering. > > What is the goal ? > > If the goal is just making it easy later

Re: Feedback on default partitioning and encryption

2020-04-28 Thread Simo Sorce
On Tue, 2020-04-28 at 16:23 -0500, Michael Catanzaro wrote: > On Tue, Apr 28, 2020 at 1:18 pm, Chris Murphy > wrote: > > This is the dilemma. It necessarily needs a single schema, there is > > only one default. Customizations aren't going away. > > We're not trying to come up with something that

Re: Feedback on default partitioning and encryption

2020-04-28 Thread David Kaufmann
On Tue, Apr 28, 2020 at 03:51:57PM -0400, Simo Sorce wrote: > If the threat model is just stolen/lost laptop/disk then encrypting the > user data only would be sufficient. Strictly speaking I'd say /etc/shadow, /var/lib/{pgsql,mysql}/, /etc/sysconfig/network-scripts/ and /etc/NetworkManager/ are a

Re: Feedback on default partitioning and encryption

2020-04-28 Thread Michael Catanzaro
On Tue, Apr 28, 2020 at 1:18 pm, Chris Murphy wrote: This is the dilemma. It necessarily needs a single schema, there is only one default. Customizations aren't going away. We're not trying to come up with something that works perfectly for everyone. We're just trying to come up with a defaul

Re: Feedback on default partitioning and encryption

2020-04-28 Thread Matthew Miller
On Tue, Apr 28, 2020 at 12:36:22PM -0400, Simo Sorce wrote: > So in the end I do not believe you can come up with a single schema for > "workstation" unless you narrow down the scope of workstation to a > smaller set of use cases to the exclusion of the others. I think it's okay to do just that. W

Re: Feedback on default partitioning and encryption

2020-04-28 Thread Simo Sorce
On Tue, 2020-04-28 at 13:18 -0600, Chris Murphy wrote: > On Tue, Apr 28, 2020 at 10:37 AM Simo Sorce wrote: > > I have a hard time commenting over the next 2 becuse it seem like the > > probelm is not just technical, but there is no clear vision of whether > > there is one and only one solution or

Re: Feedback on default partitioning and encryption

2020-04-28 Thread Chris Murphy
On Tue, Apr 28, 2020 at 10:37 AM Simo Sorce wrote: > > I have a hard time commenting over the next 2 becuse it seem like the > probelm is not just technical, but there is no clear vision of whether > there is one and only one solution or if multiple solutions need to be > considered. The short te

Re: Feedback on default partitioning and encryption

2020-04-28 Thread Simo Sorce
On Tue, 2020-04-28 at 10:18 -0500, Michael Catanzaro wrote: > Hi, > > The Workstation Working Group would like to solicit feedback on three > outstanding Workstation issues: > > * fedora-workstation#54, "Default disk partitioning layout for > Workstation" [1][2] > * fedora-workstation#82, "en

Feedback on default partitioning and encryption

2020-04-28 Thread Michael Catanzaro
Hi, The Workstation Working Group would like to solicit feedback on three outstanding Workstation issues: * fedora-workstation#54, "Default disk partitioning layout for Workstation" [1][2] * fedora-workstation#82, "encryption of user data (excludes system)" [3][4] * fedora-workstation#136, "