启动时自动挂载加密的 USB 磁盘

启动时自动挂载加密的 USB 磁盘

我已经关注这些步骤在 Lubuntu 13.10 上设置加密的 USB 硬盘,以及这些使用密钥文件而不是密码来解锁。我现在有一个磁盘 /dev/disk/by-uuid/32f692ec-e22c-49d3-b6cf-f90e605a5b48,它是原始加密设备,/dev/backup/backup 是纯文本磁盘,以及挂载文件系统的 /mnt/backup。该磁盘是通过 USB3 适配器连接的普通 SATA 硬盘。

我使用或安装磁盘没有遇到任何问题;问题出现在尝试在启动时自动安装它时。我按照文章的建议将其添加到我的 fstab 和 crypttab 中:

$ cat /etc/fstab
# /etc/fstab: static file system information.
#
# Use 'blkid' to print the universally unique identifier for a
# device; this may be used with UUID= as a more robust way to name devices
# that works even if disks are added and removed. See fstab(5).
#
# <file system> <mount point>   <type>  <options>       <dump>  <pass>
/dev/mapper/sda2_crypt /               ext4    errors=remount-ro 0       1
# /boot was on /dev/sda1 during installation
UUID=8afa992c-9174-4a70-b9a0-1ac25b42dbaf /boot           ext2    defaults        0       2
/dev/mapper/sdb2_crypt /home           ext4    defaults        0       2
/dev/mapper/sdb1_crypt /var            ext4    defaults        0       2
/dev/backup/backup     /mnt/backup     ext4    defaults        0       3

$ cat /etc/crypttab
sda2_crypt UUID=6450d0e6-539b-4fa0-a9e1-f06edfbb5ba9 none luks
sdb1_crypt UUID=f30e6efe-8e58-42b6-aed0-dc7999510744 /root/keyfile luks
sdb2_crypt UUID=17f1f107-8f05-4dbd-8172-4d595411d874 /root/keyfile luks
backup     UUID=32f692ec-e22c-49d3-b6cf-f90e605a5b48 /root/keyfile luks

(也许“备份”不是 /etc/crypttab 中的正确名称?我没有 /dev/sda2_crypt。)

这样,它就会在启动时挂起,并显示“/mnt/backup 的磁盘尚未准备好或不存在”。

我想也许磁盘还没有准备好,所以我尝试将其安装在 /etc/rc.local 中:

$ cat /etc/rc.local 
#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will "exit 0" on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.

logger Mounting backup disk...
ls -l /dev/disk/by-uuid/ > /home/rena/disk-uuid.txt
stat /root/keyfile >> /home/rena/disk-uuid.txt
whoami >> /home/rena/disk-uuid.txt
cryptsetup --verbose --key-file=/root/keyfile luksOpen /dev/disk/by-uuid/32f692ec-e22c-49d3-b6cf-f90e605a5b48 backup
logger Unlocked OK.
mount /dev/backup/backup /mnt/backup/
logger Mounted OK.

exit 0

我从 syslog 输出中看到它解锁正常,但从未挂载。看来整个 rc.local 脚本在到达该行时就死了。我还可以从 ls、stat 和 whoami 中看到磁盘确实存在于列表中,密钥文件可访问,并且脚本以 root 身份运行。所以我不知道为什么挂载会失败。

最奇怪的是,如果我从 rc,local 中删除所有这些,然后在启动后在终端中输入命令:

sudo cryptsetup --verbose --key-file=/root/keyfile luksOpen /dev/disk/by-uuid/32f692ec-e22c-49d3-b6cf-f90e605a5b48 backup
sudo mount /dev/backup/backup /mnt/backup/

它安装得很好。那么为什么它在 rc.local 和 fstab/crypttab 中失败了?

相关内容