In previous Arch/kernel versions, the network device speed was automatically set to the lowest possible upon poweroff when WoL was enabled. Latest versions do keep the network device to its standard speed (1000M for example), which consumes some useless power when computer is powered off and WoL enabled. Force speed lowering for WoL. But restore it before continuing boot, when devices are unlocked, otherwise it remains as-is. Make it an option, to select the wanted speed, or leave it as-is.
4.5 KiB
Personal ArchLinux package combining dropbear and cryptsetup in initramfs for unlocking LUKS-encrypted devices either locally (boot console) or remotely over SSH.
The code was reworked from legacy dropbear_initrd_encrypt AUR package.
Installation
After cloning the repo, installation is done as for an AUR package, e.g.:
makepkg -sri
Dropbear
SSH server key need to be generated for dropbear.
Either a new key can be generated with dropbearkey, e.g.:
dropbearkey -t ecdsa -f /etc/dropbear/dropbear_ecdsa_host_key
Or an existing OpenSSH key can be converted with dropbearconvert (useful so that the server fingerprint is the same with both), e.g.:
dropbearconvert openssh dropbear /etc/ssh/ssh_host_ecdsa_key /etc/dropbear/dropbear_ecdsa_host_key
Notes:
rsaanded25519types are also handled- OpenSSH keys must be in
PEMformat fordropbearconvertto properly work
If necessary an existing key file can be converted to PEM format using ssh-keygen:
ssh-keygen -A -p -m PEM -f /etc/ssh/ssh_host_ecdsa_key
Configuration
As explained upon installation, the following things need to be done:
- add the authorized SSH public key to
/etc/dropbear/initrd.authorized_keys - add the
ip=kernel command parameter to the bootloader configuration (see https://wiki.archlinux.org/index.php/Mkinitcpio#Using_net)- e.g. with
grub: addip=:::::eth0:dhcptoGRUB_CMDLINE_LINUX_DEFAULTin/etc/default/grub, and re-generate the configuration withgrub-mkconfig -o /boot/grub/grub.cfg - also see https://git.kernel.org/pub/scm/libs/klibc/klibc.git/tree/usr/kinit/ipconfig/README.ipconfig
- e.g. with
- in the
HOOKSsection of/etc/mkinitcpio.conf, addssh-cryptsetupbeforefilesystems; then rebuild the initramfs:mkinitcpio -p linux- when using a non-standard keyboard layout, it is also useful to add the
keymaphook beforessh-cryptsetup, and also movekeyboardbeforekeymap
- when using a non-standard keyboard layout, it is also useful to add the
The LUKS-encrypted devices to unlock are derived from /etc/crypttab.
Some options can be set in /etc/initcpio/sshcs_env (file is sourced in initramfs shell):
sshcs_opt_log_kmsg: whether to log (debug, info, error) messages to kmsg too- default:
1 - many messages are only printed on console and are not concerned
- by default (debug disabled), only useful messages are concerned
- set
0to disable
- default:
sshcs_opt_debug: whether to be more verbose about ongoing actions- default:
0 - any non-zero value to enable
- default:
sshcs_opt_net_wol: Wake-on-LAN option to set on network device- default:
g(MagicPacket™) - usually WoL is disabled once in initramfs shell
- set empty to not change network device WoL setting
- default:
sshcs_opt_net_speed: speed to set on network device- default:
10 - full duplex is enabled, and auto-negociation disabled
- latest Arch/kernel tend to keep the speed at 1000M even during WoL
- this only applies to boot phase and persists for WoL: when unlocking devices, the network is reconfigured before the OS is fully ready
- set
0to not change network device speed
- default:
sshcs_opt_timeout_ipconfig: time (in seconds) to configure IP- default:
10
- default:
sshcs_opt_listen: SSH listening port- default:
22
- default:
sshcs_opt_timeout_poweroff: time (in seconds) to unlock devices before automatic powering off- default (and minimum value):
120(2 minutes) - negative value to deactivate
- default (and minimum value):
sshcs_opt_use_shell: whether to start a fullashshell- default:
0 1to enable- when disabled (the default), a script to unlock devices is executed instead
- default:
For example:
sshcs_opt_timeout_ipconfig=30
sshcs_opt_listen=2222
sshcs_opt_timeout_poweroff=-1
sshcs_opt_use_shell=1
Building notes
- Modify the sources (features in
src, and/or package building files) - If
srcwas modified- bump
pkgver, orpkgrel, inPKGBUILD - archive the
srcfolder in$pkgname-$pkgver-$pkgrel.tar.xzfile; e.g.:tar -cJf initrd-ssh-cryptsetup-$(grep "^pkgver=" PKGBUILD | cut -d'=' -f2)-$(grep "^pkgrel=" PKGBUILD | cut -d'=' -f2).tar.xz src - upload the archive on the online repository (pointed by
PKGBUILD)
- bump
- Update ChangeLog
- Update
PKGBUILD- bump
pkgrelif only building files were modified - refresh
sha256sumswithupdpkgsumsif necessary- or manually, based on
sha256sum initrd-ssh-cryptsetup-*.tar.xz initrd-ssh-cryptsetup.installoutput
- or manually, based on
- bump
- Delete generated archive file if any