I have a file system on LVM inside LUKS on a 2nd SSD that I’d like to mount at boot time. The OS boots fine on the main (non-LUKS) SSD.

/etc/crypttab contains a line mapping a UUID to a name, with no keyfile.

/etc/fstab contains a line mapping /dev/LVMvg/volume to /home/special

But I’m not asked for the passphrase at boot.

I can do it manually once booted (cryptdisks_start asks for the passphrase, decrypts it, and then LVM picks up the volumes enabling me to mount /home/special.) But I’d like all this to happen early in the boot.

How can I make the early processes ask me for the crypt password?

Thanks!

EDIT: Solved!

Thanks (blush) to man crypttab … Add initramfs to the options field in crypttab does the trick. I was a bit confused though because man crypttab tells me that Systemd’s crypttab is different and doesn’t support the initramfs option… but I’m using systemd and it worked. Anyway, it did work. Phew.

Thanks for answers though!

  • BillibusMaximus@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    1 day ago

    Caveat: I’ve used LUKS quite a bit, but never to do exactly what you’re trying to do, so the following is a guess.

    If the root disk was the encrypted one, the tooling would add scripts to your initramfs to handle the prompting and unlocking at boot.

    Since it’s not the root, those scripts may not be getting added.

    I’m not sure about the “right” way to force it to add them, but you should be able to manually tweak your initramfs setup to add them.