From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.comp.sysutils.supervision.general/2656 Path: news.gmane.org!.POSTED.blaine.gmane.org!not-for-mail From: Oliver Schad Newsgroups: gmane.comp.sysutils.supervision.general Subject: Re: s6-linux-init: Actions after unmounting filesystems Date: Sun, 18 Aug 2019 22:36:06 +0200 Organization: Automatic Server AG Message-ID: <20190818223606.2d134a88@dickeberta> References: <20190818040925.yqy4nm7cwsnrtyjl@caspervector> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; boundary="Sig_/gsN5njPmb_bKSlIdS1CNsuU"; protocol="application/pgp-signature" Injection-Info: blaine.gmane.org; posting-host="blaine.gmane.org:195.159.176.226"; logging-data="5427"; mail-complaints-to="usenet@blaine.gmane.org" To: Supervision Original-X-From: supervision-return-2246-gcsg-supervision=m.gmane.org@list.skarnet.org Sun Aug 18 22:36:17 2019 Return-path: Envelope-to: gcsg-supervision@m.gmane.org Original-Received: from alyss.skarnet.org ([95.142.172.232]) by blaine.gmane.org with smtp (Exim 4.89) (envelope-from ) id 1hzRuS-0001II-JC for gcsg-supervision@m.gmane.org; Sun, 18 Aug 2019 22:36:16 +0200 Original-Received: (qmail 7889 invoked by uid 89); 18 Aug 2019 20:36:40 -0000 Mailing-List: contact supervision-help@list.skarnet.org; run by ezmlm Original-Sender: Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Original-Received: (qmail 7880 invoked from network); 18 Aug 2019 20:36:40 -0000 In-Reply-To: X-Mailer: Claws Mail 3.13.2 (GTK+ 2.24.30; x86_64-pc-linux-gnu) Xref: news.gmane.org gmane.comp.sysutils.supervision.general:2656 Archived-At: --Sig_/gsN5njPmb_bKSlIdS1CNsuU Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Sun, 18 Aug 2019 16:28:40 -0300 Guillermo wrote: > I know that there are people that have the rootfs on an LVM logical > volume or a LUKS encrypted volume, yes. However, those are specialized > setups. In some distributions it's a default AFAIR. I know a lot of people who do that on workstations and servers. More specialized are non-LUKS crypto setups which works with an external USB stick which is removed after start for plausible denial of knowledge of a crypto setup. I know some crypto setups which broke through systemd. BTW: a good sign to do it another way is that our systemd friends are thinking about it. ;-) Best Regards Oli --=20 Automatic-Server AG =E2=80=A2=E2=80=A2=E2=80=A2=E2=80=A2=E2=80=A2 Oliver Schad Gesch=C3=A4ftsf=C3=BChrer Turnerstrasse 2 9000 St. Gallen | Schweiz www.automatic-server.com | oliver.schad@automatic-server.com Tel: +41 71 511 31 11 | Mobile: +41 76 330 03 47 --Sig_/gsN5njPmb_bKSlIdS1CNsuU Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iEYEARECAAYFAl1ZtrYACgkQRilxUUuWlvBoAgCfeOYLVkOhUdgB917llt8zs453 E/MAmwQiXS+7Eyd4xptEU9ZwbtGDC+9o =TiMr -----END PGP SIGNATURE----- --Sig_/gsN5njPmb_bKSlIdS1CNsuU--