<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Boot encrypted root file system from sd card in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715291#M111158</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;Dunno if you seen something like this guide :&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://wiki.archlinux.org/index.php/Dm-crypt/Encrypting_an_entire_system#Simple_partition_layout_with_LUKS" title="https://wiki.archlinux.org/index.php/Dm-crypt/Encrypting_an_entire_system#Simple_partition_layout_with_LUKS"&gt;dm-crypt/Encrypting an entire system - ArchWiki&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that you likely need to create a custom initrd/initramfs&amp;nbsp; and setup/hookup your encrypted root from there, before Linux can use it and jump into it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Feb 2018 00:47:18 GMT</pubDate>
    <dc:creator>dry</dc:creator>
    <dc:date>2018-02-06T00:47:18Z</dc:date>
    <item>
      <title>Boot encrypted root file system from sd card</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715289#M111156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to boot from an encrypted sd card but it's not possible. What have I missed?&lt;/P&gt;&lt;P&gt;Main setup was done as shown here:&amp;nbsp;&lt;A href="https://community.nxp.com/docs/DOC-330147"&gt;Installing Ubuntu Rootfs on NXP i.MX6 boards&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first partition is vfat and the second one ext4 with LUKS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On boot I get "Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's necessary for booting? Unfortunately I found hundreds of tutorial how to sign uboot but nothing related encrypting root fs of Linux and booting into it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Storing the key will be a separate question. For the moment I would be happy if key file is stored on vfat partition (partition one on sd card)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Alexander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 14:29:14 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715289#M111156</guid>
      <dc:creator>alampret</dc:creator>
      <dc:date>2018-02-05T14:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Boot encrypted root file system from sd card</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715290#M111157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alexander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as starting point one can try with uboot:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.nxp.com/thread/468663"&gt;Use HAB API from u-boot to decrypt Linux image&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://boundarydevices.com/high-assurance-boot-hab-dummies/" title="https://boundarydevices.com/high-assurance-boot-hab-dummies/"&gt;High Assurance Boot (HAB) for dummies - Boundary Devices&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AN4581 Secure Boot&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN4581.pdf" title="https://www.nxp.com/docs/en/application-note/AN4581.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN4581.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 23:05:20 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715290#M111157</guid>
      <dc:creator>igorpadykov</dc:creator>
      <dc:date>2018-02-05T23:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Boot encrypted root file system from sd card</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715291#M111158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;Dunno if you seen something like this guide :&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://wiki.archlinux.org/index.php/Dm-crypt/Encrypting_an_entire_system#Simple_partition_layout_with_LUKS" title="https://wiki.archlinux.org/index.php/Dm-crypt/Encrypting_an_entire_system#Simple_partition_layout_with_LUKS"&gt;dm-crypt/Encrypting an entire system - ArchWiki&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that you likely need to create a custom initrd/initramfs&amp;nbsp; and setup/hookup your encrypted root from there, before Linux can use it and jump into it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 00:47:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/715291#M111158</guid>
      <dc:creator>dry</dc:creator>
      <dc:date>2018-02-06T00:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Boot encrypted root file system from sd card</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/1281057#M174447</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to do the exact same thing but with another board.&lt;/P&gt;&lt;P&gt;So there is no way to carry out this task without adding an initrd/initramfs?&lt;/P&gt;&lt;P&gt;If is it so, could you kindly link me to any guide to do it?&lt;/P&gt;&lt;P&gt;Thank you and Regards&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 10:00:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/1281057#M174447</guid>
      <dc:creator>EliteHawk</dc:creator>
      <dc:date>2021-05-24T10:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Boot encrypted root file system from sd card</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/1281462#M174467</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/163070"&gt;@alampret&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;use app note "i.MX Encrypted Storage Using CAAM Secure Keys"&lt;/P&gt;
&lt;P&gt;&lt;A class="result__url js-result-extras-url" href="https://www.nxp.com/webapp/Download?colCode=AN12714&amp;amp;location=null" rel="noopener" target="_blank"&gt;&lt;SPAN class="result__url__domain"&gt;https://www.nxp.com&lt;/SPAN&gt;&lt;SPAN class="result__url__full"&gt;/webapp/Download?colCode=AN12714&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 03:42:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/1281462#M174467</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2021-05-25T03:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Boot encrypted root file system from sd card</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/1281529#M174472</link>
      <description>&lt;P&gt;I may be wrong, but isn't this one a guide to creating a generic new partition on the board instead of a root ("/") partition one? I think that there should be some hooks in initramfs/initrd to do so&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:41:10 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-encrypted-root-file-system-from-sd-card/m-p/1281529#M174472</guid>
      <dc:creator>EliteHawk</dc:creator>
      <dc:date>2021-05-25T06:41:10Z</dc:date>
    </item>
  </channel>
</rss>

