Wednesday, December 29, 2021

full disk encryption with keydisk

Hello,

I'm using full disk encryption via the softraid subsystem and bioctl
with a keydisk. I have a second drive that I'm backing up the root
filesystem to via ROOTBACKUP=1 and the proper fstab entry.

I'd like to be able to reuse the same keydisk to decrypt the second
drive. It appears there is no way to inform bioctl to reuse a correctly
formatted keydisk, so it overwrites it each time. Right now I've opted
to use a passfile for the second drive and confirmed I could boot to it
by entering the passphrase via 'boot sr1a:/bsd -a' -- but I'd prefer to
simply let it pickup the keydisk. Is there something I'm missing?

Cheers

No comments:

Post a Comment