Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 31 Jan 2006 11:48:58 +0100 (CET)
From:      Christian Baer <christian.baer@informatik.uni-dortmund.de>
To:        freebsd-geom@freebsd.org
Subject:   Re: geli bugreport? fdisk error with non default sector size
Message-ID:  <drnfaq$23cb$1@nermal.rz1.convenimus.net>
References:  <000901c625b8$68954120$0201a8c0@oxy> <20060130192626.GA928@garage.freebsd.pl> <001001c6264a$f391eca0$0201a8c0@oxy>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, 31 Jan 2006 10:44:37 +0100 OxY wrote:

> i've got one question:
> is it neccesary to leave the /boot unencrypted or it has no effect
> that i get non system disk message during boot after encrypted the
> whole system disk..

I'm not sure what you are getting at, so I'll just put this in a general
statement:

You cannot boot the kernel from an encrypted file system. This would be
a little like the "chicken or the egg problem". Encrypted filesystems
cannot be read unless attached to the kernel. But without reading from
your encrypted file system, you can't boot the kernel - because it's on
there.

If you really want to encrypt *all* of your disk space, boot the kernel
from something else (CD-ROM, USB-Stick etc.).

Regards
Chris





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?drnfaq$23cb$1>