Re: Getting GELI Keys from Floppy



--- Jack Barnett <jackbarnett@xxxxxxxxx> wrote:
One idea is having 1 server with a CD-ROM drive and exporting it via NFS.
When a server boots it mounts the remote CD-ROM drive and looks for key
"$HOSTNAME.key".

But then u would have the problem with network security...

On 9/6/06, Barkley Vowk <bvowk@xxxxxxxxxxxxxxxx> wrote:
Get a usb flash drive, from there its a simple matter of changing the
geli
script to mount a specific usb device before starting. Look in
/etc/rc.d/geli and geli2. I'd put your mounting and checks between the
kldstat and the "if [ -z" in the geli_start() sub.

Oh... I just see Mr. Barkley V. gave an important and helpful hint in this
thread, too... I just wanted to point that out, because it is quite astonishing
after the first few words...

-Arne


__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"