Save your Linux machine – Recovering your root password and more
medium.com
medium.com
Redhat documentation is pretty decent and access is free via their developer program [2]. The program gives one free bare metal license for a system with up to 8 sockets that can host unlimited VMs. [3]
I realize HN is all about open source and free software but for people looking to work in a corporate environment that uses RHEL, Redhat does try to make entry at least possible for those who can self study.
[1] https://access.redhat.com/solutions/1192 [2] https://developers.redhat.com/ [3] https://developers.redhat.com/articles/faqs-no-cost-red-hat-...
The choice is yours. You can deploy disc encryption, BIOS passwords etc but be prepared for being locked out.
No! Even for me as a non native speaker this is obvious since I have worked in the field for a few years.
A car is a vehicle but saying that "a vehicle means a car is wrong".
In the same way recovering access to the root account might give you the same effect as recovering the password, but often not.
This is a situation were correct wording isn't hard and a situation where it matters in my opinion. People come here to learn and we shouldn't mislead them especially when the cost of fixing it is trivial.
If I recover the access to root, fine, I have access to that machine.
If I recover the root password I have access to all that the root password gives me access to.
On systems where for example home or certain configuration files are encrypted using the password as a key (yes, a bit simplified), this is the difference between getting access to the data or not.
> this is just splitting hair anyway.
No. This is trying to avoid potentially costly misunderstandings.
> If I recover the root password I have access to all that the root password gives me access to.
In POSIX that's the same thing.
Now I cannot say for sure that this is possible on the root account as well - I've hardly used the actual root account since Ubuntu taught me otherwise in 2006 - but I see no obvious reason why you shouldn't be able to encrypt roots home folder the same way we encrypt other home folders.
I'm interested in knowing though in case I'm missing something.
So that guide basically assumes you either already know your decryption passphrase or you don’t have full disk encryption. In either case, changing roots password wouldn’t lock you out of the root file system
Not what I am talking about.
I'm talking about encrypted home folders.
I had no interest to dig deeper, so I am not sure.
Thus if an attacker has root access then it’s literally everything else apart from /root that you need to be worried about. Hence why I discuss disk encryption.
It's seriously hard creating useful content and I really do feel like your negativity towards this is excessive compared to the faux pas in question.
Don't tell me how to be.
This is why I say it’s hard creating useful content for the web. Everyone is quick to attack but very few people are there to support. It’s a problem we should be even more accurately aware of during these difficult times of being on lockdown.
Obviously there will be times when constructive criticisms need to be raised but use of language is important — which I know is the same point you were making at the start but it’s just as relevant to you as it is the author. In fact HNs own policies ask that people write their corrections politely and constructively too.
Btw konboot-cd is awesome for resetting/bypassing windows passwords (not free tho).
Any tips?
If concerns about losing data are a roadblock, then you need a good backup strategy. You're already rolling the dice that you'll never have a hardware failure, human error, natural disaster, theft...
I can't speak to your SSD wear concern or potential issues during password changes.
The master encryption key in the LUKS header is still encrypted by your passphrase, so don't use this as an alternative to remembering your passphrase!