Skip to main content

the avatar of Pascal Bleser

How to use tin to read the openSUSE Forums

The openSUSE forums also support the NNTP protocol (usually referred to as "news"). There are plenty of GUI news readers out there (thunderbird, knode, pan, ...), but as I'm using mutt to read my emails as well as irssi for IRC in screen sessions (in urxvt, I wanted a console based NNTP client for that as well. (No, I don't use lynx or w3m for web browsing, I'm not a masochist ;).)

Hence I installed trn.

Here is how to set it up to access the openSUSE forums with it:

  1. Obviously, first install trn:
    zypper install trn
  2. then run rtin once, which will give you an error message and exit, but that will create its configuration file tree in ~/.tin:
    rtin
  3. next, edit the configuration file ~/.tin/newsrctable and add the following line:
    forums.opensuse.org /home/XXX/.tin/foo foo
    (where you replace /home/XXX with your actual home directory)
    If you are not fluent with text editors, you can also simply execute the following command from a shell (just copy/paste it):
    echo "forums.opensuse.org $HOME/.tin/foo foo" >> ~/.tin/newsrctable
  4. now we can actually run rtin to connect to the openSUSE forums:
    rtin -a -g foo
    (note that the -a flag turns on color support, and -g foo tells rtin to connect to the server we configured as "foo" in ~/.tin/newsrctable)
  5. you are now greeted with an (almost) empty screen: press the y key (yank in/out) to get a list of all the forums in order to subscribe to those that are of interest to you: simply use the arrow keys to scroll the list and press the s key (subscribe) to subscribe those you want to follow
a silhouette of a person's head and shoulders, used as a default avatar

openSUSE Linux 11.4 Lançado

Enviado por Sandro Andrade (sandroandradeΘkde·org):


“O openSUSE 11.4 já está disponível, trazendo melhorias significativas de desempenho e escalabilidade, processo de boot otimizado e utilização mais eficiente dos repositórios.

openSUSE 11.4 traz o kernel 2.6.37, drivers para placas Broadcom, suporte melhorado a tablets Wacom e as versões mais recentes do Xorg e Mesa, propiciando melhor aceleração 2D e 3D. O KDE Plasma Desktop 4.6 traz o gerenciamento mais fácil de atividades, possibilidades de criação de scripts para o KWin e melhorias no gerenciamento de rede e dispositivos bluetooth.

O GNOME 2.32 traz melhorias na usabilidade e acessibilidade e o GNOME Shell (parte do futuro GNOME 3) já está disponível para testes. O Firefox 4 sofreu redesign da sua interface e a tecnologia “Firefox Synch” permite sincronizar bookmarks, senhas e históricos entre as suas diferentes instalações do Firefox.

Adicionalmente, além do openSUSE 11.4 um conjunto de outros serviços estão disponíveis: Tumbleweed (repositório rolling-release), o Build Service (geração e liberação de pacotes para diversas distros) e o SUSEStudio (solução completa para geração de appliances openSUSE configurados para as sua necessidades).

Leia também: Anúncio Oficial, Novidades do KDE no openSUSE 11.4, On the tenth day, openSUSE 11.4 changed everything, openSUSE 11.4 Highlights."

[referência: news.opensuse.org]



Fonte: BR-Linux.org




Sobre o openSUSE Linux 11.4:


Clique na imagem para ampliar.




http://en.opensuse.org/Portal:11.4






Faça o download aqui.





Avise se algum erro for encontrado nesse artigo.


O conteúdo desse artigo pode ser modificado ou atualizado, por isso, visite essa página constantemente e mantenha-se atualizado.

a silhouette of a person's head and shoulders, used as a default avatar

openSUSE 11.4 – A New Hallmark For The openSUSE Project

Dear openSUSE Community. Users. Contributors. Fans and friends. The time has come: openSUSE 11.4 has arrived!. After 8 months of hard work, you can learn what is new, download it and upgrade!
We are proud to announce the launch of 11.4 in the openSUSE tradition of delivering the latest technology while maintaining stability. The 11.4 release brings significant improvements along with the latest in Free Software applications. Combined with the appearance of new tools, projects and services around the release, 11.4 marks a showcase of growth and vitality for the openSUSE Project! Read on for more details about this release…
Get 11.4

Base System

openSUSE always concentrates on a stable foundation that is usable for different workloads. The base system of 11.4 brings better scalability and performance, an enhanced boot processes and significantly faster repository refresh, package install and update.
11.4 is based around Kernel 2.6.37 which improves the scalability of virtual memory management and separation of tasks executed by terminal users, leading to better scalability and performance and less interference between tasks. The new kernel also brings better hardware support, with open Broadcom Wireless drivers, improved Wacom support and many other new or updated drivers. It also supports the improvements to graphic drivers in the latest Xorg and Mesa shipped, so users will enjoy better 2D and 3D acceleration.
New tools for an enhanced boot process. The latest gfxboot 4.3.5 supports VirtualBox and qemu-kvm while Vixie Cron has been replaced with Cronie 1.4.6 supporting the PAM and the SELinux security frameworks. The more experimental software options include GRUB2 and systemd.
The ZYpp package management introduces a MultiCurl backend, support for zsync transfers, and Metalink download support. With simultaneous downloads from multiple servers, and fetching of only changed parts of files, the result is a significantly faster repository refresh, package install and update. The new backend gives better support for network proxies and allows for HTTP BASIC password-protected repositories. On the desktop, KPackageKit replaces the KDE applet and both KDE and GNOME applets now default to installing all package updates, not just patches.

Desktops and Applications

openSUSE is committed to flexibility and choice, providing all major desktops and a full range of applications, well integrated and supported. The desktops and applications of 11.4 take the next step with a revamped user experience, all the popular up to date Free Software applications and consistent functionality even in lighter desktops.
The KDE Plasma Desktop 4.6 introduces script-ability to window manager KWin and easier Activity management as well as improvements to network and bluetooth handling. Stable GNOME 2.32 improves usability and accessibility. 11.4 also has GNOME Shell, part of the upcoming GNOME3, available for testing. This brings a fully revamped user experience with a visual and intuitive way of launching and switching between applications, making heavy use of 3D acceleration, window tiling, integrating notifications and messaging in the shell. Xfce 4.8 now makes use of the GIO VFS implementation for better remote file system browsing as well as udev, ConsoleKit and PolicyKit. The lighter weight LXDE 0.5 hasn’t seen any major changes with this release but continues to enhance stability and usability with a series of bugfixes, improved file association and theming.
Firefox 4.0, first to ship in 11.4, introduces a major redesign of  the user interface with tabs moved to the top of the toolbar, support for pinning of tabs and more. Firefox Sync synchronizes bookmarks, history, passwords and tabs between all your installations. Firefox 4 also supports newer web standards like HTML5, WebM and CSS3. 11.4 includes even more of the popular up to date Free Software applications as it’s the first major distribution to ship LibreOffice 3.3.1. Delivering it’s cleaner, faster code base and features like import and edit SVG files in Draw, support for up to 1 million rows in Calc and easier slide layout handling in Impress. 11.4 also débuts the result of almost 4 years of work with the Scribus 1.4 release based on Qt 4 and Cairo technology. Improved text rendering, undo-redo, image/color management and vector file import are highlights of this release.
openSUSE offers deep integration of all these technologies. By carefully creating ‘patterns’ of software, openSUSE ensures consistent functionality even in lighter desktops like XFCE and LXDE. Keyboard shortcuts are set, menu layouts tweaked, user-friendly file associations chosen and branding and theming integrated. 11.4 furthermore improves on the LibreOffice and Firefox integration in KDE Plasma, using native file dialogs, oxygen styling (also for GTK applications) and respecting the user’s mail client and browser choices.

Professional tools for administrators and developers

openSUSE aims to be the perfect power tool for system administrators to keep their network safe and their systems under control. And as developing and maintaining free software is the bread and butter task of the openSUSE Project the distribution naturally brings everything a software developer needs. 11.4 ships the latest virtualization and web server stacks and all the major development languages, platforms and associated IDEs.
11.4 brings the latest virtualization stack with Xen 4.0.2 introducing memory overcommit and a VMware Workstation/player driver, VirtualBox 4.0.4 supporting VMDK, VHD, and Parallels images, as well as resizing for VHD and VDI and KVM 0.14 with support for the QEMU Enhanced Disk format and the SPICE protocol. As guest, 11.4 includes open-vm-tools and virtualbox-guest-tools, and seamlessly integrates clipboard sharing, screen resizing and un-trapping your mouse.
openSUSE ships with the latest web server stack featuring Apache 2.2.17, lighttpd 1.4.26 and ngninx 0.8.54. As well as the main databases like version 9.0.3 of PostgreSQL, a release that brings major features like easy-to-use replication, a mass permission-changing facility, and anonymous code blocks. And MySQL 5.1.53 (community edition), and its fork MariaDB 5.1 that offers a drop-in replacement with better performance and some extra features are complemented while SQLite features a new transaction control mechanism using a write-ahead log.
openSUSE 11.4 comes with all the major development languages, platforms and associated IDEs. Qt 4.7.1 and QtCreator 2.1 bring a better and faster WebKit and support for the QML Declarative language, also supported in the KDE Development Platform 4.6 which in turn introduces a ‘Mobile Build Target’ for a thinner version of its libraries. The GNOME 2.32 platform brings Vala and Python support to Anjuta and Glib 2.26 supports Gsettings. 11.4 ships with GTK+ 3 bringing improved device input handling, fully Cairo based drawing (with multiple backends) and much easier theming to developers who want to develop for the upcoming GNOME 3 release. For developers who are interested in working on LibreOffice, openSUSE offers the unique advantage of using a ‘split build’, making it easy to get involved.

Around 11.4

Additionally to the distribution the openSUSE project also provides a variety of tools, projects and services to its fellow Free and Open Source community members and its users. Supporting 11.4 are Tumbleweed, a rolling release repository, the Build Service to easily create and release open source software and 11.4 inside susestudio for you to experiment with.
For this release we are particularly pleased to introduce Tumbleweed, a rolling release repository containing the latest stable versions of projects instead of relying on a rigid, periodic release cycle. The project does this for users that want the newest, but stable software. Additionally the popular third-party package provider Packman has reorganized and optimized its repositories for the openSUSE 11.4 release. The Packman team, which provides a large number of new and updated packages for openSUSE, simultaneously introduces support for Tumbleweed.
The Free and Open Source software developers are greatly aided in the distribution of their software by the innovative technologies developed or initiated by the openSUSE Project. Like the newly released Build Service 2.1.6 which provides the infrastructure to easily create and release open source software for openSUSE, Fedora, Debian and many other Linux distributions and projects like Bretzn or Appstream which support developers in building and distributing their applications and users in getting it.
We are also happy to also announce that Novell’s SUSE Studio, building upon openSUSE technology like KIWI, offers 11.4 as a base to build appliances upon from its convenient webinterface. We invite anyone to visit susestudio.com to experiment with 11.4, to create custom versions as Live CD, USB or VM images and to share them on susegallery.com!

Get 11.4 now

openSUSE is now available for immediate download. You can also purchase a retail box with 11.4 that includes 90-day installation support, physical media, and a printed Getting Started guide. Read more about what is new in openSUSE 11.4 in our Product Highlights!

Thanks!

openSUSE 11.4 represents the combined effort of thousands of developers who participate in openSUSE and projects shipped in openSUSE. The contributors, inside and outside the openSUSE Project, should be proud of this release, and they deserve a major “thank you” for all of the hard work and care that have gone into 11.4. We hope that 11.4 is the best openSUSE release yet, and that it will help to encourage the use of Linux everywhere! We hope that you all have a lot of fun while you use 11.4, and we look forward to working with you on the next release!

About the openSUSE Project

The openSUSE Project is a worldwide community that promotes the use of Linux everywhere. It creates one of the world’s best Linux distributions, working together in an open, transparent and friendly manner as part of the worldwide Free and Open Source Software community. The project is controlled by its community and relies on the contributions of individuals, working as testers, writers, translators, usability experts, artists and ambassadors or developers. The project embraces a wide variety of technology, people with different levels of expertise, speaking different languages and having different cultural backgrounds.
 

Πηγή: http://news.opensuse.org/2011/03/10/opensuse-11-4/
a silhouette of a person's head and shoulders, used as a default avatar

flash + 11.4 + youtube

При миграции на 11.4, заметил странное поеведение Flash плагина на youtube. При переходе с видео на видео, flash плагин крешится. Либо показывается черный экран, вместо видео.

Всему виной как оказалось, включенное апаратное усорение во флеше.

Отключить его можно в меню "Settings" flash плеера.

the avatar of Matthias Hopf

RAnsrID continued

Our group is now in HackWeek 6, quite a few weeks delayed after all other groups at SuSE. I will use the time to (finally!) continue work on RAnsrID - see also my initial blog entry. The project source is hosted on gitorious.

The basic redundancy routines are all working already, next is a usable test suite, then run-time configuration management (live adding and removing disks, live reconstruction w/o repair in the read error case).

I doubt I will reach a final version 1.0 I can recommend to use, but it will hopefully be close.

a silhouette of a person's head and shoulders, used as a default avatar

Amazing openSUSE 11.4 : Ερχεται με τον νεο βελτιώμένο πυρίνα 2.6.37



Σε 2 μέρες φτάνει η νέα πολύ-αναμενόμενη έκδοση του openSUSE. Η 11.4 έρχεται για να δείξει ακόμη μια φορά πως είναι να είσαι μια σταθερή και συνάμα στην αιχμή της τεχνολογίας διανομή.

Έρχεται 'φορώντας' κάτω από το 'καπό' της τον νέο πυρήνα 2.6.37. Όπως έχω γράψει παλαιότερα η σχέση αυτού του πυρίνα με το openSUSE Project έχει ιστορία.

Ο πυρήνας 2.6.37 φέρνει μαζί του μια σειρά από σημαντικές αλλαγές στην επεκτασιμότητα της διαχείρισης της εικονικής μνήμης,οι οποίες βοηθάνε το σύστημα να αποδίδει καλύτερα ακόμα και όταν αυτό κάνει βαριά χρήση του σκληρού δίσκου, πράγμα που συμβαίνει αντιγράφοντας πολλά και βαριά αρχεία ταυτόχρονα.
Επίσης εξασφαλίζει στο openSUSE καλύτερο διαχωρισμό ανάμεσα στις βαριές δουλειές του διαχειριστή, όπως είναι π.χ. η αναβάθμιση του συστήματος η ακόμη και το χτίσιμο πακέτων, με αποτέλεσμα αυτές να μην επηρεάζουν την καθημερινότητα του χρήστη και να μπορεί ταυτόχρονα να δει τα μέηλ του και να σερφάρει στο διαδίκτυο χωρίς να αντιμετωπίζει τα προβλήματα που είχε μέχρι τώρα κάθε φορά που λ.χ. έκανε μια αναβάθμιση...

Επίσης όπως είναι αναμενόμενο ο νέος πυρήνας έρχεται να δώσει στο openSUSE 11.4 ακόμα καλύτερη υποστήριξη στο υποστηριζόμενο υλικό (hardware) συμπεριλαμβανομένων και πολλών ανοιχτών Broadcom ασυρμάτων καρτών, κάνοντας τους περισσότερους φορητούς υπολογιστές της αγοράς να μπορούν να δουλέψουν απροβλημάτιστα.
Ένα ακόμη αξιοσημείωτο χαρακτηριστικό είναι ότι έρχεται με νέους αλλά και βελτιωμένους οδηγούς open Radeon και Nouveau, οι οποίοι υποστηρίζουν τις κάρτες γραφικών AMD/ATI και NVIDIA στο Xorg 1.9, Mesa 7.9 και τον πυρήνα. Αυτοί οι οδηγοί δεν παρέχουν μόνο καλά 2D γραφικά αλλά και αξιοπρεπή 3D γραφικά. Ειδικά το τελευταίο Mesa έρχεται με έναν νέο shader compiler  που δουλεύει καλύτερα με τα νέα τσιπάκια Radeon βελτιώνοντας έτσι την απόδοση αλλά και την κανονική υποστήριξη.

Το openSUSE 11.4 έρχεται και αλλάζει πολλά δεδομένα.







the avatar of Andrew Wafaa

Get Bug Tracking With The Help Of Robots

I previously enlightened people to entomologist and also showed an image or two of it running on Android. Well now’s the time to get your funk on and help test, file bugs and generally make it better. You can download entomologist from the Android Market, or if you don’t have access to the Market you can grab the .apk. When you launch it for the first time it checks to see if you have the required Qt libraries, if not it will ask you to install Ministro (if not already installed) from the Market (grab the.

a silhouette of a person's head and shoulders, used as a default avatar

license implications when packaging TrueCrypt

I use an encrypted USB stick to carry credentials and data for production servers I look after when I’m on call. One requirement was portability between my work (Windows) and home (GNU/Linux) desktops, so TrueCrypt came to mind. I packaged it all up an applied some patches to fix compiler issues and warnings. The TrueCrypt license, however, is not OSI-approved, and as such the program cannot be built in the openSUSE build service (see blacklist, discussion).

I almost forgot about the whole thing until I upgraded the package for new dependencies in the upcoming release of openSUSE 11.4. I talked with people over at packman, a popular 3rd-party repository for software not included in openSUSE proper for one reason or another. We analysed the license a bit and concluded that if we shipped binaries built from non-pristine sources, the product would have to be re-branded as per the requirements of their license. I am usually pragmatic about these things as long as FLOSS and non-FLOSS licences can be adhered to, but didn’t want to go the route Debian took with Firefox et al.

We contacted the TrueCrypt developers on this issue, we’ll see what comes out of that. Until then, if someone wants to build this package, here is what you need:

truecrypt.spec
truecrypt.desktop
truecrypt-tc_token_err.patch
truecrypt-NULL_PTR-redefinition-warning.patch
truecrypt-undefined-operation-warning.patch

the avatar of Will Stephenson

It's off to conf.kde.in I go!

I'm feeling very lucky today. Why? Because in a few hours I'll be getting on a plane to Bengaluru, India and attending conf.kde.in. Pradeepto has been asking me for years to look outside the cosy confines of the US-Europe Axis of KDE, and thanks to my role in the openSUSE Boosters team, this has finally become possible.

I'll be giving a talk on contributing to KDE in the openSUSE project and a long talk/practical workshop on using the openSUSE Build Service as used by openSUSE, Novell, Dell, Intel, Nokia, Broadcom and Cray, to spread free software: your own, update existing software on openSUSE, or package for it and for many other distros at one go. But mainly I'm looking forward to meeting the people who make up a whole side of KDE. So if you haven't made up your mind what you're doing next week, how about coming to the RV College of Engineering in Bengaluru?

Like many others,

PS: I'm bringing a load of openSUSE loot to give away, so just look for the guy staggering under the huge carton!

a silhouette of a person's head and shoulders, used as a default avatar

USB-Stick als Schlüssel für die Festplattenverschlüsselung

OpenSUSE bietet seit einigen Versionen die Möglichkeit bei der Installation die Festplatte komplett zu Verschlüsseln. In Anbetracht der großen Menge an Daten macht dies heutzutage nicht nur bei Laptops, sondern auch bei stationären Rechnern Sinn. Wird der Rechner aber als Server — ohne Tastatur und Monitor — betrieben stört hierbei allerdings die notwendige Passworteingabe beim Starten des Rechners. Glücklicherweise bietet LUKS aber die Möglichkeit diese auf einem USB-Stick zu speichern, womit auch bei solchen Maschinen ein komfortabler Start möglich ist.

Achtung: Diese für openSUSE 11.3 erstellte Anleitung funktioniert bis einschließlich openSUSE 13.1. Auf openSUSE 13.2 und openSUSE Leap 42.1 habe ich sie nicht getestet. Auf openSUSE Leap 42.2 funktioniert sie nicht mehr. Es gibt einen neuen Mechanismus, welchen ich, sobald ich ihn ausführlich getestet habe, verbloggen und hier verlinken werde.

Ist ein USB-Stick als Schlüssel sicher?

Sicherheit ist immer relativ zur Bedrohung zu sehen. Auch beim USB-Stick stellt sich also die Frage wovor er schützen soll. Beim stationär zuhause stehenden Rechner hat die Verschlüsselung vor allem eine Funktion, sie schützt die Daten wenn die betroffen Festplatten mal das eigene Haus verlassen. Hierbei gibt es im Prinzip nur zwei Fälle. Stellt sich eine Platte während der Garantiezeit als defekt heraus so erspart einem die Verschlüsselung das heutzutage sehr zeitaufwendige Löschen der Platte. Wird die Festplatte entwendet, so ist sie ohne den USB-Stick, der natürlich in diesem Fall nicht im Rechner gesteckt haben darf, auch nicht auszulesen.

Ein großer Vorteil des USB-Sticks besteht hier darin, dass er sehr lange Passwörter ermöglicht. Möchte man lange Passwörten auf klassischem Weg verwenden kommt man um ein Aufschreiben des Passworts oft auch nicht herum. Außerdem gewinnt man eine Möglichkeit die Herausgabe des Passworts zu verweigern, sollte man je dazu aufgefordert werden. Bei einem langen Passwort welches man nie getippt hat ist die Chance sich zu erinnern nicht existieren. Auch hier gilt natürlich, der USB-Stick darf dann nicht trivial dem Rechner zuzuordnen sein.

Die Anleitung

Backup

Wie bei allen Operationen an der Basis eines Systems ist auch hier das Backup zu beginn wichtig. In diesem Fall ist es wichtig den Kernel und die Initramdisk zu sichern, da es sonst, sollte man sich bei der Konfiguration der Entsperrung via USB-Stick vertun, schwer ist wieder in das verschlüsselte System zu booten.

Unter openSUSE ist es hierbei wichtig den Anfang des initrd und kernel-Namens zu ändern, da diese vom Befehl mkinitrd sonst dennoch aktualisiert werden.

cp /boot/initrd-2.6.34-12 /boot/safe-initrd-2.6.34-12
cp /boot/vmlinuz-2.6.34-12 /boot/safe-enable-vmlinuz-2.6.34-12
Außerdem sollte man sich der Einfachheit halber gleich einen passenden Eintrag im Grub anlegen, wozu man in der Datei /boot/grub/menu.lst die passenden Zeilen einfügt:
title SafetyNet -- openSUSE 11.3 - 2.6.34-12
    root (hd0,0)
    kernel /safe-vmlinuz-2.6.34-12 root=/dev/system/root resume=/dev/system/swap splash=silent quiet showopts vga=0x317
    initrd /safe-enable-initrd-2.6.34-12
Dadurch kann man anschließend jederzeit auch noch mit dem bei der Installation vergebenen Passwort das System starten.

Anlegen des Schlüssels

Als nächstes muss ein Schlüssel erzeugt werden. Um nicht zu viele zusätzliche Module in die Initramdisk packen zu müssen empfiehlt es sich einen Ext2-formatierten Stick zu verwenden. Dieser kann mit
mkfs.ext2 -L keystick /dev/sdb
erzeugt werden. keystick gibt hierbei das Label des erzeugten Dateisystems an, /dev/sdb muss an den tatsächlichen Gerätenamen des USB-Sticks angepasst werden. Sollte der Stick bereits mit ext2 formatiert sein sollte dennoch ein Label gesetzt werden.
tune2fs -L keystick /dev/sdb

Das Label kann natürlich frei gewählt werden. Es dient später zur Identifizierung des Sticks. Dies hat zwei Vorteile:

  • Der USB-Stick unabhängig von hinzugekommenen oder entfernten Datenträgern gefunden
  • Anders als bei der Identifizierung über die ID des Sticks kann man einen zweiten Stick mit gleichem Label als Backup verwenden. Ich recycle gerne nutzlose Werbegeschenke für diese Aufgabe. Sollte mal eines kaputt gehen spare ich mir das Zeitaufwendige zurückspielen des Backups der ganzen platte, da ich den Schlüssel ja noch von einem zweiten USB-Stick laden kann.

Anschließend sollte ein Passwort generieren und auf dem USB-Stick hinterlegen. Meine bevorzugte Methode ist diese:

pwgen -s 1024 1 > /media/keystick/keyfile

Nun kann man den erzeugten Schlüssel der verschlüsselten Partition hinzufügen. Leider verhält sich LUKS leicht unterschiedlich was interaktiv eingegebene Schlüssel und Schlüsseldateien angeht. Deshalb müssen wir unseren Schlüssel "interaktiv" eingeben. Hierzu erzeugt man zunächst eine Datei welche eine Zeile mit dem bei der Installation gewählten Schlüssel und eine mit dem neuen enthält.

cat oldkey /media/keystick/keyfile > tmp
Damit kann man nun die passenden Tastatureingaben simulieren:
cryptsetup luksAddKey /dev/sda2 < tmp
Anschließend wird die temporäre Datei nicht mehr benötigt:
rm tmp

Um zu testen ob der Schlüssel korrekt hinzugefügt wurde kann man probehalber einen leeren Schlüssel hinzufügen. LUKS ist schlau genug diesen Schlüssel nicht wirklich aufzunehmen:

cryptsetup luksAddKey /dev/sda2 < /media/keystick/keyfile

Erstellen der neuen Initramdisk

Damit der Kernel bevor das Root-Verzeichnis eingebunden ist auf den USB-Stick zugreifen kann muss man sicherstellen, dass die USB-Module in der Initrandisk ist. Hierzu sollte man in openSUSE sicherstellen, dass die Variable INITRD_MODULES in /etc/sysconfig/kernel folgende Werte enthält:
usb_storage scsi_mod

Um LUKS den Schlüssel zu übergeben benötigt man ein Skript welches ihn vom USB-Stick liest. Dies kann an einer beliebigen Stelle im Dateisystem liegen, es wird beim erstellen der Initramdisk in diese gepackt:

#!/bin/sh

STICK=/dev/disk/by-label/keystick
FSTYPE=ext2
slumber=150
modprobe usb-storage 1>&2
modprobe scsi_mod 1>&2
mkdir /keystick 1>2&
sleep 5 1>2&

while [ $slumber -gt 0 ] && [ ! -e "$STICK" ]; do
      sleep 1
      slumber=$(( $slumber - 1 ))
done
if ! mount -t $FSTYPE -r $STICK /keystick ; then
   $( echo 'FAILED!!!' ) 1>2&
   echo ''
   exit 1
fi

cat /keystick/keyfile

umount /keystick 1>2&

Damit LUKS weiß, dass es den Wert von einem Skript erhält muss die Datei /etc/crypttab angepasst werden:

cr_sda2         /dev/sda2       none    initrd,luks,keyscript=/root/keyscript.sh
Hierbei sind zwei Dinge zu beachten:
  • Ist keyscript gesetzt ist keine interaktive Eingabe mehr möglich. Deshalb sollte man die alte Initramdisk (welche die alte Konfiguration enthält) vorher sichern.
  • Der Wert initrd ist notwendig, da openSUSE bei der Generierung der Initramdisk sonst nicht merkt, dass es das Keyscript mit einpacken muss.

Zu guter letzt kann durch den Aufruf von mkinitrd die neue Initramdisk erstellt werden. Ein Neustart sollte den Schlüssel dann vom USB-Stick lesen anstatt diesen interaktiv zu erwarten.

Hat man die neue Konfiguration hinreichen getestet kann man den bei der Installation vergebenen Schlüssel aus LUKS entfernen und die gesicherte Initramdisk löschen.

Eine Anmerkung zur Distributionsaktualisierung

Diese Anleitung habe ich ursprünglich anhand von openSUSE 11.3 erstellt. Sie gilt aber auch für aktuellere Versionen bis 13.1. Auf openSUSE Leap 42.2 funktionierte diese methode aber nicht! Auf neuere Versionen kann man über das normale DVD-Update aktualisieren. Hierbei muss man allerdings die verschlüsselte Partition über einen eingetippten Schlüssel öffnen. Hierzu hilft es den bei der initialien Installation verwendeten Schlüssel nicht deaktiviert zu haben, oder aber temporär per cryptsetup luksAddKey einen kürzeren Schlüssel hinzuzufügen. Getestet habe ich auf diese Weise das Update von 11.3 auf 11.4 und von 11.4 auf 12.1. Der Installer warnt einen zwar, dass es Probleme geben kann, wenn man Partitionen per Kernel Device Name mountet, dies hat sich aber bisher nicht als Problem herausgestellt.

Quellen

Da die Literatur — was openSUSE angeht — zu diesem Thema leider noch sehr dürftig ist habe ich mich vieler Quellen bedient, von denen ich hier nur die wichtigsten nennen möchte: