cryptsetup: add keyfile-offset= support
This is useful if your keyfile is a block device, and you want to use a specific part of it, such as an area between the MBR and the first partition. This feature is documented in the Arch wiki[0], and has been supported by the Arch initscripts, so would be nice to get this into systemd. This requires libcryptsetup >= 1.4.2 (released 12.4.2012). Acked-by: Paul Menzel <paulepanter@users.sourceforge.net> [0]: <https://wiki.archlinux.org/index.php/System_Encryption_with_LUKS# Storing_the_key_between_MBR_and_1st_partition>
This commit is contained in:
parent
2be7287b0e
commit
880a599e26
|
@ -333,7 +333,7 @@ AC_SUBST(AUDIT_LIBS)
|
||||||
have_libcryptsetup=no
|
have_libcryptsetup=no
|
||||||
AC_ARG_ENABLE(libcryptsetup, AS_HELP_STRING([--disable-libcryptsetup], [disable libcryptsetup tools]))
|
AC_ARG_ENABLE(libcryptsetup, AS_HELP_STRING([--disable-libcryptsetup], [disable libcryptsetup tools]))
|
||||||
if test "x$enable_libcryptsetup" != "xno"; then
|
if test "x$enable_libcryptsetup" != "xno"; then
|
||||||
PKG_CHECK_MODULES(LIBCRYPTSETUP, [ libcryptsetup ],
|
PKG_CHECK_MODULES(LIBCRYPTSETUP, [ libcryptsetup >= 1.4.2 ],
|
||||||
[AC_DEFINE(HAVE_LIBCRYPTSETUP, 1, [Define if libcryptsetup is available]) have_libcryptsetup=yes], have_libcryptsetup=no)
|
[AC_DEFINE(HAVE_LIBCRYPTSETUP, 1, [Define if libcryptsetup is available]) have_libcryptsetup=yes], have_libcryptsetup=no)
|
||||||
if test "x$have_libcryptsetup" = xno -a "x$enable_libcryptsetup" = xyes; then
|
if test "x$have_libcryptsetup" = xno -a "x$enable_libcryptsetup" = xyes; then
|
||||||
AC_MSG_ERROR([*** libcryptsetup support requested but libraries not found])
|
AC_MSG_ERROR([*** libcryptsetup support requested but libraries not found])
|
||||||
|
|
|
@ -130,6 +130,18 @@
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term><varname>keyfile-offset=</varname></term>
|
||||||
|
|
||||||
|
<listitem><para>Specifies the number
|
||||||
|
of bytes to skip at the start of
|
||||||
|
the keyfile; see
|
||||||
|
<citerefentry><refentrytitle>cryptsetup</refentrytitle><manvolnum>8</manvolnum></citerefentry>
|
||||||
|
for possible values and the default
|
||||||
|
value of this option.</para></listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><varname>hash=</varname></term>
|
<term><varname>hash=</varname></term>
|
||||||
|
|
||||||
|
|
|
@ -37,6 +37,7 @@
|
||||||
static const char *opt_type = NULL; /* LUKS1 or PLAIN */
|
static const char *opt_type = NULL; /* LUKS1 or PLAIN */
|
||||||
static char *opt_cipher = NULL;
|
static char *opt_cipher = NULL;
|
||||||
static unsigned opt_key_size = 0;
|
static unsigned opt_key_size = 0;
|
||||||
|
static unsigned opt_keyfile_offset = 0;
|
||||||
static char *opt_hash = NULL;
|
static char *opt_hash = NULL;
|
||||||
static unsigned opt_tries = 0;
|
static unsigned opt_tries = 0;
|
||||||
static bool opt_readonly = false;
|
static bool opt_readonly = false;
|
||||||
|
@ -79,6 +80,13 @@ static int parse_one_option(const char *option) {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
} else if (startswith(option, "keyfile-offset=")) {
|
||||||
|
|
||||||
|
if (safe_atou(option+15, &opt_keyfile_offset) < 0) {
|
||||||
|
log_error("keyfile-offset= parse failure, ignoring.");
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
} else if (startswith(option, "hash=")) {
|
} else if (startswith(option, "hash=")) {
|
||||||
char *t;
|
char *t;
|
||||||
|
|
||||||
|
@ -462,7 +470,8 @@ int main(int argc, char *argv[]) {
|
||||||
argv[3]);
|
argv[3]);
|
||||||
|
|
||||||
if (key_file)
|
if (key_file)
|
||||||
k = crypt_activate_by_keyfile(cd, argv[2], CRYPT_ANY_SLOT, key_file, keyfile_size, flags);
|
k = crypt_activate_by_keyfile_offset(cd, argv[2], CRYPT_ANY_SLOT, key_file, keyfile_size,
|
||||||
|
opt_keyfile_offset, flags);
|
||||||
else {
|
else {
|
||||||
char **p;
|
char **p;
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue