Hi,
Just installed a new FreeBSD server. GELI encrypted ZFS-on-root. FreeBSD 15.0-RELEASE.
loader.conf
Upon boot I get asked to enter passphrase for a lot of partitions -- how can I make this stop so that it only asks about the partitions that I have specified in loader.conf?
Here is an example how it might look:
Just installed a new FreeBSD server. GELI encrypted ZFS-on-root. FreeBSD 15.0-RELEASE.
loader.conf
Code:
geom_mirror_load="YES"
geom_eli_load="YES"
geli_gpt_beastie-sysroot0_keyfile0_load="YES"
geli_gpt_beastie-sysroot0_keyfile0_type="gpt/beastie-sysroot0:geli_keyfile0"
geli_gpt_beastie-sysroot0_keyfile0_name="/boot/keys/beastie-sysroot_encryption.key"
geli_gpt_beastie-sysroot1_keyfile0_load="YES"
geli_gpt_beastie-sysroot1_keyfile0_type="gpt/beastie-sysroot1:geli_keyfile0"
geli_gpt_beastie-sysroot1_keyfile0_name="/boot/keys/beastie-sysroot_encryption.key"
Upon boot I get asked to enter passphrase for a lot of partitions -- how can I make this stop so that it only asks about the partitions that I have specified in loader.conf?
Here is an example how it might look:
Code:
EOM_ELI: Wrong key for ada1p2. Tries left: 2.
Enter passphrase for ada1p2: GEOM_ELI: Wrong key for ada1p2. Tries left: 1.
Enter passphrase for ada1p2: GEOM_ELI: Wrong key for ada1p2. No tries left.
GEOM_MIRROR: Device mirror/swap launched (1/2).
Enter passphrase for ada1p3: GEOM_ELI: Wrong key for ada1p3. Tries left: 2.
Enter passphrase for ada1p3: GEOM_ELI: Wrong key for ada1p3. Tries left: 1.
Enter passphrase for ada1p3: GEOM_ELI: Wrong key for ada1p3. No tries left.
Enter passphrase for ada3p2: GEOM_ELI: Wrong key for ada3p2. Tries left: 2.
Enter passphrase for ada3p2: GEOM_ELI: Wrong key for ada3p2. Tries left: 1.
Enter passphrase for ada3p2: GEOM_ELI: Wrong key for ada3p2. No tries left.
Enter passphrase for ada3p3: GEOM_ELI: Wrong key for ada3p3. Tries left: 2.
Enter passphrase for ada3p3: GEOM_ELI: Wrong key for ada3p3. Tries left: 1.
Enter passphrase for ada3p3: GEOM_ELI: Wrong key for ada3p3. No tries left.
Enter passphrase for gpt/beastie-sysroot0:
GEOM_ELI: Device gpt/beastie-sysroot0.eli created.
GEOM_ELI: Encryption: AES-XTS 256
GEOM_ELI: Crypto: accelerated software
Enter passphrase for gpt/beastie-storage0:
GEOM_ELI: Wrong key for gpt/beastie-storage0. Tries left: 2.
Enter passphrase for gpt/beastie-storage0:
GEOM_ELI: Wrong key for gpt/beastie-storage0. Tries left: 1.
Enter passphrase for gpt/beastie-storage0:
GEOM_ELI: Wrong key for gpt/beastie-storage0. No tries left.
Enter passphrase for gptid/006a0905-5f70-11f0-9df8-941882376644:
GEOM_ELI: Wrong key for gptid/006a0905-5f70-11f0-9df8-941882376644. Tries left: 2.
Enter passphrase for gptid/006a0905-5f70-11f0-9df8-941882376644:
GEOM_ELI: Wrong key for gptid/006a0905-5f70-11f0-9df8-941882376644. Tries left: 1.
Enter passphrase for gptid/006a0905-5f70-11f0-9df8-941882376644:
GEOM_ELI: Wrong key for gptid/006a0905-5f70-11f0-9df8-941882376644. No tries left.
Enter passphrase for gpt/beastie-sysroot1:
GEOM_ELI: Device gpt/beastie-sysroot1.eli created.
GEOM_ELI: Encryption: AES-XTS 256
GEOM_ELI: Crypto: accelerated software
Enter passphrase for gpt/beastie-storage1: GEOM_ELI: Wrong key for gpt/beastie-storage1. Tries left: 2.
Enter passphrase for gpt/beastie-storage1: GEOM_ELI: Wrong key for gpt/beastie-storage1. Tries left: 1.
Enter passphrase for gpt/beastie-storage1: GEOM_ELI: Wrong key for gpt/beastie-storage1. No tries left.
Enter passphrase for gptid/2d1a05c3-5f70-11f0-9df8-941882376644:
GEOM_ELI: Wrong key for gptid/2d1a05c3-5f70-11f0-9df8-941882376644. Tries left: 2.
Enter passphrase for gptid/2d1a05c3-5f70-11f0-9df8-941882376644:
GEOM_ELI: Wrong key for gptid/2d1a05c3-5f70-11f0-9df8-941882376644. Tries left: 1.
Enter passphrase for gptid/2d1a05c3-5f70-11f0-9df8-941882376644:
GEOM_ELI: Wrong key for gptid/2d1a05c3-5f70-11f0-9df8-941882376644. No tries left.
GEOM_ELI: Device mirror/swap.eli created.
GEOM_ELI: Encryption: AES-XTS 128
GEOM_ELI: Crypto: accelerated software