If you need to reboot an encrypted box remotely AND have it automatically decrypt without you knowing the key, you've already lost the game.
If you need to reboot an encrypted box remotely AND have it automatically decrypt without you knowing the key, you've already lost the game.
Aside, this is a nice script that prompts for the LUKS password _before_ kexec: https://gist.github.com/webstrand/381307348e24c28d5c4c9a5981... it does assume you're using opensuse's naming convention of calling the root partition cr_root. I used this because my bootloader was also encrypted, so rebooting into an initramfs with ssh was impossible.
That way, it was impossible to access the data physically, but I was still able to reboot the box whenever I wanted without any problem.
Rebooting a box is often the easiest way to get something done if you can't be bothered with exotic configs, I just don't believe that remotely rebooting a encrypted box for which you dont have the key is ever a reasonable thing to do, and that's the assumptuon this article is based on.
(Disclosure: I am a co-author of Mandos.)
Even cosmic rays flipping bits in your RAM in a way that can't be recovered from?
It's not a normal thing for release-based distributions where userspace<>userspace compatibility is nearly assured during a release.