mirror of
https://github.com/suikan4github/kaiten-yaki.git
synced 2025-12-20 02:21:17 -03:00
44 lines
1.6 KiB
Bash
44 lines
1.6 KiB
Bash
#!/bin/bash
|
|
|
|
# Include configuration. This sript file have to be executed at Kaiten-yaki/script dir
|
|
# shellcheck disable=SC1091
|
|
source config.sh
|
|
|
|
# Create a key file for LUKS and register it as contents of the initramfs image
|
|
function chrooted_job() {
|
|
# Mount the rest of partitions by target /etc/fstab
|
|
mount -a
|
|
|
|
# Set up the kernel hook of encryption
|
|
echo "...Installing cryptsetup-initramfs package."
|
|
apt -qq install -y cryptsetup-initramfs
|
|
|
|
# Prepare a key file to embed in to the ramfs.
|
|
echo "...Prepairing key file."
|
|
mkdir /etc/luks
|
|
dd if=/dev/urandom of=/etc/luks/boot_os.keyfile bs=4096 count=1 status=none
|
|
chmod u=rx,go-rwx /etc/luks
|
|
chmod u=r,go-rwx /etc/luks/boot_os.keyfile
|
|
|
|
# Add a key to the key file. Use the passphrase in the environment variable.
|
|
echo "...Adding a key to the key file."
|
|
printf %s "${PASSPHRASE}" | cryptsetup luksAddKey --iter-time "${ITERTIME}" -d - "${DEV}${CRYPTPARTITION}" /etc/luks/boot_os.keyfile
|
|
|
|
# Add the LUKS volume information to /etc/crypttab to decrypt by kernel.
|
|
echo "...Adding LUKS volume info to /etc/crypttab."
|
|
echo "${CRYPTPARTNAME} UUID=$(blkid -s UUID -o value ${DEV}${CRYPTPARTITION}) /etc/luks/boot_os.keyfile luks,discard" >> /etc/crypttab
|
|
|
|
# Putting key file into the ramfs initial image
|
|
echo "...Registering key file to the ramfs"
|
|
echo "KEYFILE_PATTERN=/etc/luks/*.keyfile" >> /etc/cryptsetup-initramfs/conf-hook
|
|
echo "UMASK=0077" >> /etc/initramfs-tools/initramfs.conf
|
|
|
|
# Finally, update the ramfs initial image with the key file.
|
|
echo "...Upadting initramfs."
|
|
update-initramfs -uk all
|
|
|
|
# Leave chroot
|
|
}
|
|
|
|
# Execute job
|
|
chrooted_job
|