dm-crypt.saout.de archive mirror
 help / color / mirror / Atom feed
* Re: [dm-crypt] cryptsetup Yubikey challenge-response support
@ 2020-04-08  8:37 7heo
  2020-04-08 10:07 ` Nikolay Kichukov
  0 siblings, 1 reply; 23+ messages in thread
From: 7heo @ 2020-04-08  8:37 UTC (permalink / raw)
  To: dm-crypt

Hello,

I believe this is a very good idea, but the implementation should not be limited to yubikey. There are other solutions out there (nitrokey is one) that would also need to be supported IMHO.

In addition, I would favor the implementation support of bare usb keys (mass storage), for those of us who wish to use their already-owned encrypted mass storage keys in order to unlock their drive.

I had started to implement this (the latter part) in the Alpine Linux initramfs some years ago but given the complexity of the task and the lack of public interest, coupled with FOSS politics, I gave up on it.

If you start working on an implementation, I'd be curious to see that and I could eventually participate.

Also, your email looks just fine to me :)

Cheers,
7heo

On Apr 8, 2020 09:54, Dan Farrell <djfarrell@gmail.com> wrote:
>
> Hi, 
>
> Hopefully this email comes through without HTML and property wrapped, 
> sorry if it doesn't. 
>
> I am wondering if any group has started or is interested in adding 
> Yubikey challenge-response support to cryptsetup? 
>
> The idea would be to add the option to insert a USB key to (optionally 
> automagically) unlock at boot time (or whenever cryptsetup is 
> running). There would be a backup password of course. 
>
> I'm interested in doing this for myself if it's not underway at the 
> moment. I have some basic ideas on how to do this. I do realise this 
> could be done external to cryptsetup with distro support, but doing 
> that messing around with initramfs etc sounds painful, let alone each 
> distro would need be supported individually. 
>
> If it's of no interest, that's ok, I'll do it for myself. But if there 
> is interest I would be willing to work with maintainers to find the 
> best way to do this and contribute the effort. 
>
> Regards, 
>
> Dan Farrell 
> _______________________________________________ 
> dm-crypt mailing list 
> dm-crypt@saout.de 
> https://www.saout.de/mailman/listinfo/dm-crypt 

^ permalink raw reply	[flat|nested] 23+ messages in thread
* [dm-crypt] cryptsetup Yubikey challenge-response support
@ 2020-04-08  7:54 Dan Farrell
  0 siblings, 0 replies; 23+ messages in thread
From: Dan Farrell @ 2020-04-08  7:54 UTC (permalink / raw)
  To: dm-crypt

Hi,

Hopefully this email comes through without HTML and property wrapped,
sorry if it doesn't.

I am wondering if any group has started or is interested in adding
Yubikey challenge-response support to cryptsetup?

The idea would be to add the option to insert a USB key to (optionally
automagically) unlock at boot time (or whenever cryptsetup is
running). There would be a backup password of course.

I'm interested in doing this for myself if it's not underway at the
moment. I have some basic ideas on how to do this. I do realise this
could be done external to cryptsetup with distro support, but doing
that messing around with initramfs etc sounds painful, let alone each
distro would need be supported individually.

If it's of no interest, that's ok, I'll do it for myself. But if there
is interest I would be willing to work with maintainers to find the
best way to do this and contribute the effort.

Regards,

Dan Farrell

^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2020-04-16 10:36 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <233063842.2717340.1586366160963.ref@mail.yahoo.com>
2020-04-08 17:16 ` [dm-crypt] cryptsetup Yubikey challenge-response support JT Morée
2020-04-10  3:01   ` Dan Farrell
2020-04-11 14:49     ` JT Moree
2020-04-11 16:09       ` Milan Broz
2020-04-11 19:56         ` Arno Wagner
2020-04-11 21:05           ` JT Moree
2020-04-11 22:23             ` Arno Wagner
2020-04-12 13:00               ` [dm-crypt] LUKS FAQ separate for LUKS1/LUKS2, or combined? Was: " Michael Kjörling
2020-04-14 10:56                 ` Milan Broz
2020-04-15 22:25                   ` Arno Wagner
2020-04-14 11:35           ` [dm-crypt] " Milan Broz
2020-04-15 21:47             ` Arno Wagner
2020-04-15  6:37         ` Dan Farrell
2020-04-15  6:48           ` Dan Farrell
2020-04-15  7:08             ` Dan Farrell
2020-04-15 19:38           ` Milan Broz
2020-04-16  2:03             ` Dan Farrell
2020-04-16 10:36               ` Milan Broz
2020-04-08  8:37 7heo
2020-04-08 10:07 ` Nikolay Kichukov
2020-04-08 16:31   ` Tim Steiner
2020-04-08 22:18     ` Dan Farrell
  -- strict thread matches above, loose matches on Subject: below --
2020-04-08  7:54 Dan Farrell

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).