No reason to support two ssh daemons when you can do it with one.
The difference in size on your init image is minimal and you probably aren't even trying to optimize for space there.
If you don't know the size of your rd off the top of your head then it almost certainly doesn't matter.
https://wiki.archlinux.org/title/dm-crypt/Specialties#Remote...
At some point I wanted to do something with utrablue [1], to work over network rather than Bluetooth, but then it was in go and I got lazy suddenly :)
In my case, I can't. This is a NAS in my house and this is mostly to prevent me from having to go to another room and plug in a monitor and keyboard. (Also, I've done this from across the country after a power outage.)
The threat vectors I'm protecting against are I guess mostly theft of the entire machine, or forgetting to wipe the drives when I eventually toss them out. Mostly, it's just fun practice because I'm a nerd and every drive should be encrypted.
For my use-case, the auto-unlock-by-polling-a-specific-LAN-IP linked in this thread would probably be fine, for example.
If the booting machine has been compromised and i use my usb connected keyboard to enter the full disk encryption key I would run into the exact same issues, no?
The server itself may have been physically breached, and if so you can’t trust anything. But, if your host key matches, you should be confident that at least you’re logging into the correct machine (there was no IP takeover).
(Without a physical breach... if that happens, all bets are off).
This is for my personal hosting which if someone wants to take over, I guess I'd be more curious than upset.
The idea is that you should configure the timeout to be long enough to allow for a normal kernel panic and reboot, but hopefully short enough that it would be hard for anyone to compromise the server in that time. It’s not a perfect solution, but it’s the best anyone has come up with as far as I know.
(Disclosure: I am a co-author of Mandos.)
https://packages.debian.org/bookworm/dropbear-initramfs https://packages.ubuntu.com/jammy/dropbear-initramfs
(Obligatory disclaimer: I am a co-author of Mandos)
https://access.redhat.com/documentation/en-us/red_hat_enterp...
It's fully automated and supposed to be much more secure.
Has anyone got experience with it?
Clevis+Tang is good. There's also Keylime which takes a different approach to the same[1].
AFAICT, systemd-cryptenroll requires that you have a USB key plugged into the machine, so someone with physical access would have to insert them at the start and remove when you're done with the server. With Clevis+Tang everything is software.
Or am I missing something?
Reboot your server while you sleep!
Disclosure: I am a co-author of Mandos.
(Again, disclosure: I am the co-author of Mandos.)
Agreed.
A static tinysshd works well for the small userlands I create.