[Pkg-rust-maintainers] Bug#1083292: gpg-from-sq: Unknown argument --card-status causes cryptsetup cannot decrypt disk during boot time

ChangZhuo Chen (陳昌倬) czchen at debian.org
Mon Oct 14 15:00:25 BST 2024


On Mon, Oct 14, 2024 at 11:31:22AM +0000, Holger Levsen wrote:
> 
> One question, which will be obvious to you, but it's not 100% clear to me: do you
> use a smart card here? :)

Yes, I use YubiKey 5 Nano in this case.


I think it shall be some way to info user about the problem in the
combination of cryptsetup + gpg-from-sq since The problem happens only
when all the following conditions meet:

* Use cryptsetup to encrypt disk with LUK
* Use gpg-from-sq to replace gpg
* Install new kernel and run update-initramfs during the installation
  process. The gpg from Sequoia will be used to create initramfs, and
  decrypt_gnupg-sc does not support gpg from Sequoia.

User cannot find the problem immediately, and when the problem happen,
they cannot decrypt disk and boot. They need to use previous kernel,
which might be removed already.


-- 
ChangZhuo Chen (陳昌倬) czchen@{czchen,debian}.org
Key fingerprint = BA04 346D C2E1 FE63 C790  8793 CC65 B0CD EC27 5D5B
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-rust-maintainers/attachments/20241014/f0d3caf2/attachment.sig>


More information about the Pkg-rust-maintainers mailing list