Talk:ECryptfs

From ArchWiki
Jump to: navigation, search

Automounting

Just a short remark which took me several hours to figure out:

I tried to follow 3.2 manual setup without ecryptfs-utils and it worked very well until I tried to get my encrypted directory mounted on login.

It is now working and two crucial steps seemed to be: 1. besides pam_mount.so use also pam_ecryptfs.so 2. put an empty file "auto-mount" into /home/USER/.ecryptfs

Especially figuring out 2. has taken a lot of time. It would be good if the article would mention this fact. If someone who really knows ecryptfs can verify that I have done the right things, then one should add remarks about this to the page.

Kind regards DaAlx (talk) 21:20, 25 March 2015 (UTC)

Hi, can you please put a link here which section you followed? Did you use the ecryptfs-simple package (section 3.2)? Section 3.1 mentions the points you make (ECryptfs#Auto-mounting). Sections 3.2 and 3.3 dont. I assume you refer to 3.3 ECryptfs#Without_ecryptfs-utils, please confirm. --Indigo (talk) 06:56, 26 March 2015 (UTC)
Hi, oh sorry for the imprecise section reference (must have been too tired) So I started my setup with 3.3.2 and followed up to 3.3.2.2. Ecryptfs#Auto-mounting_2 -- DaAlx (talk) 08:22, 26 March 2015 (UTC)
Thanks. I now re-tried the section 3.3.2 again. My results for the described pam_mount are different though, i.e. I did not need your points (1) and (2) above at all. It mounts like it should, but tor some reason the directory is user-mounted twice and does not unmount on logout.
Not sure what to make of that, maybe someone else has an idea. How do you login (console, gdm, kdm, slim,...)? Did you use the ecryptfs-utils default directory name (~/.Private,~/Private) or another one? Have you modified /etc/pam.d/system-auth for other reasons before? --Indigo (talk) 19:06, 26 March 2015 (UTC)
Edit: Now I figured why I had different results and was able to confirm yours. The reason was that I had an old /etc/modules-load.d autoload for ecryptfs and fuse (needed for other reasons) which I forgot about. Removing that I arrive at your results. The problems described above remain though. I have adjusted the section with [1], does it reflect your experience now correctly? --Indigo (talk) 20:06, 26 March 2015 (UTC)
Hi! Yes, your changes exactly make the right points. Thank you very much. By the way, in the pam mount article there is a remark that auto-umount does not work currently. I also noted the double mounting thing on login --DaAlx (talk) 22:20, 26 March 2015 (UTC)
Ok, good. Yes, the auto-umount does not work consistently with just pam_ecryptfs.so as well:[2] The double-mounting I only noticed with configured pam_mount. Let's keep this item open a bit, maybe someone has an idea about the cause. --Indigo (talk) 23:19, 26 March 2015 (UTC)