Re: Full disk encryption (including /boot) Luks2+argon2 ( No Libreboot )
Reply #32 –
Here's what it roughly looks like:
user@host> blkid ~
/dev/mapper/crypt-root: UUID="3eabad26-a765-414c-bd79-fc3bf66f58ac" BLOCK_SIZE="4096" TYPE="ext4"
/dev/sdb: UUID="115e9912-9109-4849-918f-4d6fd78559d4" TYPE="crypto_LUKS"
/dev/mapper/crypt-home: UUID="e27d6f5a-2bc9-43cf-81a2-bd901624479a" BLOCK_SIZE="4096" TYPE="ext4"
/dev/mapper/luks: UUID="HPamLZ-12fZ-olvN-MGyI-9VDA-LUwz-HFB8ii" TYPE="LVM2_member"
/dev/sda2: UUID="d3412596-7138-4392-b6d9-2d0d3c433900" TYPE="crypto_LUKS" PARTUUID="b4e5ca50-68ab-5c41-a726-c8282f22504c"
/dev/sda1: UUID="7FF8-F409" BLOCK_SIZE="512" TYPE="vfat" PARTUUID="0ee62557-8f14-6d41-8d41-bf0376a84db0"
GRUB_CMDLINE_LINUX_DEFAULT="cryptdevice=UUID=d3412596-7138-4392-b6d9-2d0d3c433900:luks:allow-discards root=UUID=3eabad26-a765-414c-bd79-fc3bf66f58ac cryptkey=rootfs:/root/secrets/ssd.bin loglevel=3 quiet net.ifnames=0 ipv6.disable=1"
Where d3412596-7138-4392-b6d9-2d0d3c433900 is /dev/sda2, and 3eabad26-a765-414c-bd79-fc3bf66f58ac is /dev/mapper/crypt-root.