mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Phillip Hellewell <phillip@hellewell.homeip.net>
To: akpm@osdl.org
Cc: linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org,
	viro@ftp.linux.org.uk, mike@halcrow.us, mhalcrow@us.ibm.com,
	mcthomps@us.ibm.com, yoder1@us.ibm.com
Subject: [PATCH 2/12: eCryptfs] Documentation
Date: Fri, 18 Nov 2005 21:16:15 -0700	[thread overview]
Message-ID: <20051119041615.GB15747@sshock.rn.byu.edu> (raw)
In-Reply-To: <20051119041130.GA15559@sshock.rn.byu.edu>

This patch provides documentation for using eCryptfs.

Signed-off-by: Phillip Hellewell <phillip@hellewell.homeip.net>
Signed-off-by: Michael Halcrow <mhalcrow@us.ibm.com>

---

 ecryptfs.txt |   81 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 files changed, 81 insertions(+)
--- linux-2.6.15-rc1-mm1/Documentation/ecryptfs.txt	1969-12-31 18:00:00.000000000 -0600
+++ linux-2.6.15-rc1-mm1-ecryptfs/Documentation/ecryptfs.txt	2005-11-18 11:46:12.000000000 -0600
@@ -0,0 +1,81 @@
+eCryptfs: A stacked cryptographic filesystem for Linux
+Maintainer: Phillip Hellewell
+Lead developer: Michael A. Halcrow <mhalcrow@us.ibm.com>
+Developers: Michael C. Thompson
+            Kent Yoder
+Current Release Version: 0.1
+
+This software is currently undergoing development. Make sure to
+maintain a backup copy of any data you write into eCryptfs.
+
+eCryptfs requires the userspace tools downloadable from the
+SourceForge site:
+
+http://sourceforge.net/projects/ecryptfs/
+
+Requirements include:
+ - Kernel version 2.6.15-rc1-mm1 or higher
+  - eCryptfs will work with 2.6.14, but you will need the
+    export_user_type.patch applied
+ - David Howells' userspace keyring headers and libraries, obtainable
+   from http://people.redhat.com/~dhowells/keyutils/
+  - (You will need to apply the keyutil_h_fix.diff patch to version 0.3)
+ - GnuPG Made Easy (GPGME)
+ - Building the kernel with:
+  - Cryptographic API
+  - Blowfish cipher
+  - Key retention support
+  - Filesystems->Miscellaneous filesystems->eCryptfs
+
+
+BUILD AND INSTALL INSTRUCTIONS
+
+If you are installing from the patch set:
+1) Apply export_user_type.patch to the kernel if you are running
+   kernel version 2.6.14
+2) Apply all patches in the patches/ directory to the kernel
+
+Once eCryptfs is already in the kernel:
+3) Select build options (see Requirements) and build kernel
+4) Apply keyutil_h_fix.diff to the keyutils if you are running version
+   0.3
+5) Run make and make install from the request-key/ directory.
+
+
+MOUNT-WIDE PASSPHRASE
+
+Create a new directory into which eCryptfs will write its encrypted
+files (i.e., /root/crypt).  Then, create the mount point directory
+(i.e., /mnt/crypt).  Now it's time to mount eCryptfs:
+
+mount -t ecryptfs /root/crypt /mnt/crypt
+
+You should be prompted for a passphrase and a salt (the salt may be
+blank).
+
+Try writing a new file:
+
+echo "Hello, World" > /mnt/crypt/hello.txt
+
+The operation will complete.  Notice that there is a new file in
+/root/crypt that is 3 pages (12288 bytes) in size.  This is the
+encrypted underlying file for what you just wrote.  To test reading,
+from start to finish, you need to clear the user session keyring:
+
+keyctl clear @u
+
+Then umount /mnt/crypt and mount again per the instructions given
+above.
+
+cat /mnt/crypt/hello.txt
+
+
+NOTES
+
+eCryptfs should only be mounted on (1) empty directories or (2)
+directories containing files only created by eCryptfs. If you mount a
+directory that has pre-existing files not created by eCryptfs, then
+behavior is undefined.
+
+Mike Halcrow
+mhalcrow@us.ibm.com

  parent reply	other threads:[~2005-11-19  4:16 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-11-19  4:11 [PATCH 0/12: eCryptfs] eCryptfs version 0.1 Phillip Hellewell
2005-11-19  4:14 ` [PATCH 1/12: eCryptfs] Makefile and Kconfig Phillip Hellewell
2005-11-19  4:16 ` Phillip Hellewell [this message]
2005-11-19  4:16 ` [PATCH 3/12: eCryptfs] Makefile Phillip Hellewell
2005-11-19  4:17 ` [PATCH 4/12: eCryptfs] Main module functions Phillip Hellewell
2005-11-19 10:47   ` Pekka Enberg
2005-11-20 15:34     ` Anton Altaparmakov
2005-11-20 19:06       ` Pekka Enberg
2005-11-21 16:10     ` Michael Thompson
2005-11-21 16:12       ` Michael Thompson
2005-11-21 16:21       ` Pekka Enberg
2005-11-19  4:18 ` [PATCH 5/12: eCryptfs] Header declarations Phillip Hellewell
2005-11-19 10:37   ` Pekka Enberg
2005-11-21 15:50     ` Michael Thompson
2005-11-19  4:19 ` [PATCH 6/12: eCryptfs] Superblock operations Phillip Hellewell
2005-11-19 10:50   ` Pekka Enberg
2005-11-21 15:57     ` Michael Thompson
2005-11-21 16:01       ` Pekka Enberg
2005-11-21 16:13         ` Michael Thompson
2005-11-21 16:15           ` Michael Thompson
2005-11-21 16:20             ` Pekka Enberg
2005-11-19  4:20 ` [PATCH 7/12: eCryptfs] File operations Phillip Hellewell
2005-11-19 10:53   ` Pekka Enberg
2005-11-21 15:58     ` Michael Thompson
2005-11-19  4:20 ` [PATCH 8/12: eCryptfs] Dentry operations Phillip Hellewell
2005-11-19  4:21 ` [PATCH 9/12: eCryptfs] Inode operations Phillip Hellewell
2005-11-19  4:22 ` [PATCH 10/12: eCryptfs] Mmap operations Phillip Hellewell
2005-11-19  4:23 ` [PATCH 11/12: eCryptfs] Keystore Phillip Hellewell
2005-11-19  4:23 ` [PATCH 12/12: eCryptfs] Crypto functions Phillip Hellewell
2005-11-19  6:16 ` [PATCH 0/12: eCryptfs] eCryptfs version 0.1 Andrew Morton
2005-11-21 20:28   ` Michael Halcrow
2005-11-21 21:41     ` James Morris
2005-11-21 22:11       ` Michael Thompson
  -- strict thread matches above, loose matches on Subject: below --
2005-11-03  3:32 Phillip Hellewell
2005-11-03  3:43 ` [PATCH 2/12: eCryptfs] Documentation Phillip Hellewell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20051119041615.GB15747@sshock.rn.byu.edu \
    --to=phillip@hellewell.homeip.net \
    --cc=akpm@osdl.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mcthomps@us.ibm.com \
    --cc=mhalcrow@us.ibm.com \
    --cc=mike@halcrow.us \
    --cc=viro@ftp.linux.org.uk \
    --cc=yoder1@us.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®