<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Automatic encryption of home directories using TrueCrypt 6.0a</title>
	<atom:link href="http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/</link>
	<description>Things that have more than zero impact (on my live)</description>
	<pubDate>Sun, 05 Feb 2012 00:03:53 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Little Impact &#187; Blog Archive &#187; Automatic encryption of home directories using TrueCrypt 6.2 and pam_exec</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-4745</link>
		<dc:creator>Little Impact &#187; Blog Archive &#187; Automatic encryption of home directories using TrueCrypt 6.2 and pam_exec</dc:creator>
		<pubDate>Mon, 14 Sep 2009 21:06:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-4745</guid>
		<description>[...] Linux with the help of TrueCrypt and PAM using the login-password as encryption key. I wrote about Automatic encryption of home directories using TrueCrypt before. This time we&#8217;ll use TrueCrypt 6.2. Futhermore we&#8217;ll use Ubuntu 9.04 Jaunty [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux with the help of TrueCrypt and PAM using the login-password as encryption key. I wrote about Automatic encryption of home directories using TrueCrypt before. This time we&#039;ll use TrueCrypt 6.2. Futhermore we&#039;ll use Ubuntu 9.04 Jaunty [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henryk</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3875</link>
		<dc:creator>Henryk</dc:creator>
		<pubDate>Fri, 24 Jul 2009 20:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3875</guid>
		<description>@Jor

Did you do this step (see above)?

root@mybox:~# chown bart.users /mnt/</description>
		<content:encoded><![CDATA[<p>@Jor</p>
<p>Did you do this step (see above)?</p>
<p>root@mybox:~# chown bart.users /mnt/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jor</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3865</link>
		<dc:creator>Jor</dc:creator>
		<pubDate>Fri, 24 Jul 2009 00:45:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3865</guid>
		<description>Nice guide.

However my volume is mounted in a way only accesible by 'sudo'. What can I change to amend this and that the user can access the volume freely.

Thanks.</description>
		<content:encoded><![CDATA[<p>Nice guide.</p>
<p>However my volume is mounted in a way only accesible by &#039;sudo&#039;. What can I change to amend this and that the user can access the volume freely.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: berkus</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3711</link>
		<dc:creator>berkus</dc:creator>
		<pubDate>Mon, 22 Jun 2009 13:57:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3711</guid>
		<description>jpmcc: i think html ate your brackets.</description>
		<content:encoded><![CDATA[<p>jpmcc: i think html ate your brackets.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cnyk</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3551</link>
		<dc:creator>cnyk</dc:creator>
		<pubDate>Tue, 12 May 2009 02:10:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3551</guid>
		<description>jpmcc: and if you happen to mistype the password, it will go into an endless loop.</description>
		<content:encoded><![CDATA[<p>jpmcc: and if you happen to mistype the password, it will go into an endless loop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jpmcc</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3524</link>
		<dc:creator>jpmcc</dc:creator>
		<pubDate>Mon, 04 May 2009 15:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3524</guid>
		<description>acid: pam_mount by default uses the standard 'mount' command to mount disks. However, if the fstype is one of a list of exceptions hard-coded into pam_mmount, it will use the matching  entry in the xml file instead.

What appears to have happened is that "truecrypt" has been dropped from the exceptions list.

The trick is to edit ‘/etc/security/pam_mount.conf.xml’ as per the original instructions above, but use an fstype of "crypt" instead of "truecrypt" ("crypt" is still in the exceptions list):

truecrypt-nl --text --protect-hidden=no --keyfiles="" %(VOLUME) %(MNTPT)


A nasty kludge, but it works for me

John</description>
		<content:encoded><![CDATA[<p>acid: pam_mount by default uses the standard &#039;mount&#039; command to mount disks. However, if the fstype is one of a list of exceptions hard-coded into pam_mmount, it will use the matching  entry in the xml file instead.</p>
<p>What appears to have happened is that &#034;truecrypt&#034; has been dropped from the exceptions list.</p>
<p>The trick is to edit ‘/etc/security/pam_mount.conf.xml’ as per the original instructions above, but use an fstype of &#034;crypt&#034; instead of &#034;truecrypt&#034; (&#034;crypt&#034; is still in the exceptions list):</p>
<p>truecrypt-nl &#8211;text &#8211;protect-hidden=no &#8211;keyfiles=&#034;" %(VOLUME) %(MNTPT)</p>
<p>A nasty kludge, but it works for me</p>
<p>John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: acid</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3521</link>
		<dc:creator>acid</dc:creator>
		<pubDate>Mon, 04 May 2009 04:20:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3521</guid>
		<description>Can you give some more details on this issue? How to use crypt in order to mount truecrypt volume in Jaunty? Thanks in advance. :-)</description>
		<content:encoded><![CDATA[<p>Can you give some more details on this issue? How to use crypt in order to mount truecrypt volume in Jaunty? Thanks in advance. :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jpmcc</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3498</link>
		<dc:creator>jpmcc</dc:creator>
		<pubDate>Wed, 29 Apr 2009 20:32:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3498</guid>
		<description>It looks as though the developers of pam_mount have lost patience with the broken scripting interface of Truecrypt and have removed support for it. As a result, pam_mount in Jaunty no longer recognises "truecrypt" as a special fstype (see man pam_mount.conf). This means it does not use the commands in truecrypt %(VOLUME) %(MNTPT), but just tries to use the regular 'mount' command - which fails.

A horrible workround is to use one of the other special fstypes, e.g. crypt, with Truecrypt:

truecrypt-nl --text --protect-hidden=no --keyfiles="" %(VOLUME) %(MNTPT)


which seems to do the trick.

John</description>
		<content:encoded><![CDATA[<p>It looks as though the developers of pam_mount have lost patience with the broken scripting interface of Truecrypt and have removed support for it. As a result, pam_mount in Jaunty no longer recognises &#034;truecrypt&#034; as a special fstype (see man pam_mount.conf). This means it does not use the commands in truecrypt %(VOLUME) %(MNTPT), but just tries to use the regular &#039;mount&#039; command - which fails.</p>
<p>A horrible workround is to use one of the other special fstypes, e.g. crypt, with Truecrypt:</p>
<p>truecrypt-nl &#8211;text &#8211;protect-hidden=no &#8211;keyfiles=&#034;" %(VOLUME) %(MNTPT)</p>
<p>which seems to do the trick.</p>
<p>John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jpmcc</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3480</link>
		<dc:creator>jpmcc</dc:creator>
		<pubDate>Sun, 26 Apr 2009 19:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-3480</guid>
		<description>Just replaced Ubuntu 8.10 with 9.04 Netbook Remix and this no longer works. Only clue I have is an error message 'unknown pam_mount option "use_first_pass"'. I'll do some digging and see if I can track it down ... has anyone else seen this?

Upgrades :-(</description>
		<content:encoded><![CDATA[<p>Just replaced Ubuntu 8.10 with 9.04 Netbook Remix and this no longer works. Only clue I have is an error message &#039;unknown pam_mount option &#034;use_first_pass&#034;&#039;. I&#039;ll do some digging and see if I can track it down &#8230; has anyone else seen this?</p>
<p>Upgrades :-(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iupsilon</title>
		<link>http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-2791</link>
		<dc:creator>iupsilon</dc:creator>
		<pubDate>Mon, 16 Feb 2009 16:13:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.littleimpact.de/index.php/2008/08/19/automatic-encryption-of-home-directories-using-truecrypt-60a/#comment-2791</guid>
		<description>Nice howto.
Il mounts correctly the volume at login time but I have some problem when I logoff.
I would the volume to be unmounted but as the mount is done with root privileges the unmount fails because it doesn't find the mounted volume. I know, just because it tries to unmount it with user privileges but there is no truecrypt volume mounted for the user, in fact root has mounted and still holds it.

I've verified it by typing "truecrypt -l" once successful logged in
As root it says that /home/luser/private is mounted and mapped on /media/truecrypt1
As luser i see no truecrypt volumes mounted.

As you can see from log when I log off:
-------------------------------------------------------------------------
pam_mount(mount.c:107) ♦pam_mount(mount.c:139) waiting for lsof
pam_mount(misc.c:285) command: truecrypt [-d] [/home/luser/private]
pam_mount(misc.c:56) set_myuid: (uid=0, euid=0, gid=1001, egid=1001)
pam_mount(misc.c:56) set_myuid: (uid=0, euid=0, gid=1001, egid=1001)
pam_mount(mount.c:104) umount errors:
pam_mount(mount.c:107) Error: No such volume is mounted.
pam_mount(mount.c:596) waiting for umount
pam_mount(pam_mount.c:624) unmount of /home/luser.tc failed
pam_mount(pam_mount.c:635) pam_mount execution complete
-------------------------------------------------------------------------

Any suggestions?

Thanks!

Cheers</description>
		<content:encoded><![CDATA[<p>Nice howto.<br />
Il mounts correctly the volume at login time but I have some problem when I logoff.<br />
I would the volume to be unmounted but as the mount is done with root privileges the unmount fails because it doesn&#039;t find the mounted volume. I know, just because it tries to unmount it with user privileges but there is no truecrypt volume mounted for the user, in fact root has mounted and still holds it.</p>
<p>I&#039;ve verified it by typing &#034;truecrypt -l&#034; once successful logged in<br />
As root it says that /home/luser/private is mounted and mapped on /media/truecrypt1<br />
As luser i see no truecrypt volumes mounted.</p>
<p>As you can see from log when I log off:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
pam_mount(mount.c:107) ♦pam_mount(mount.c:139) waiting for lsof<br />
pam_mount(misc.c:285) command: truecrypt [-d] [/home/luser/private]<br />
pam_mount(misc.c:56) set_myuid: (uid=0, euid=0, gid=1001, egid=1001)<br />
pam_mount(misc.c:56) set_myuid: (uid=0, euid=0, gid=1001, egid=1001)<br />
pam_mount(mount.c:104) umount errors:<br />
pam_mount(mount.c:107) Error: No such volume is mounted.<br />
pam_mount(mount.c:596) waiting for umount<br />
pam_mount(pam_mount.c:624) unmount of /home/luser.tc failed<br />
pam_mount(pam_mount.c:635) pam_mount execution complete<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Any suggestions?</p>
<p>Thanks!</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
</channel>
</rss>

