个人工具
登录
查看“UbuntuHelp:FeistyLUKSTwoFormFactor”的源代码 - Ubuntu中文
UbuntuHelp
讨论
查看源代码
历史
搜索
导航
首页
最近更改
随机页面
页面分类
帮助
编辑
编辑指南
沙盒
新闻动态
字词处理
工具
链入页面
相关更改
特殊页面
页面信息
查看“UbuntuHelp:FeistyLUKSTwoFormFactor”的源代码
来自Ubuntu中文
←
UbuntuHelp:FeistyLUKSTwoFormFactor
跳转至:
导航
,
搜索
因为以下原因,你没有权限编辑本页:
您所请求的操作仅限于该用户组的用户使用:
用户
您可以查看与复制此页面的源代码。
== FINALIZE with True Two Form Factor == If satisfied with the startup using the USB Crypt``Key remove the passphrase that was initially used for `/dev/sda3` on Slot0. If you remove the initial passphrase from Slot0 and rely on the random generated key stored on the USB Crypt``Key this affords some small plausable deniability. Once your remove the slot0 key form `/dev/sda3` the ''ONLY'' key which will unlock the luks device is the 256bit random keyfile located on the USB Crypt``Key device! You can add a passphrase back if you need/want to later but that somewhat defeats the whole purpose. === Mount USB cryptKey and Remove /dev/sda3 Slot0 Key === '''BE CONFIDENT THAT THE SYSTEM BOOTS FROM THE USB CRYPTKEY DEVICE BEFORE PROCEEDING!!''' With the USB Crypt``Key still inserted proceed with the Slot0 removal from `/dev/sda3`. After login... <pre><nowiki> usbcryptkey /dev/cryptKey cryptsetup --key-file=/mnt/cryptkeys/#PATH#FILENAME.luks luksDelKey /dev/sda3 0 </nowiki></pre> If command successfull then you can unmount the cryptKey. <pre><nowiki> usbcryptkey /dev/cryptKey </nowiki></pre> ---------------------
返回至
UbuntuHelp:FeistyLUKSTwoFormFactor
。