Solved

Preboot Authentication for Linux

Posted on 2009-07-06
7
1,011 Views
Last Modified: 2013-12-15
Is there any generic open source project for providing preboot authentication on Linux for all distributions
0
Comment
Question by:tittu
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 43

Expert Comment

by:ravenpl
ID: 24786923
Pre-boot? You mean bios should do that? Or boot-loader? Or initrd script?
And You want to authenticate against?

Since You are asking about linux, I'm assuming grub bootloader or initrd.
I haven't heard about any initrd auth related customization.
You could probably force grub to ask for password.
You also could run the linux on LUKS encrypted root device, one have to unlock the root device first to get to real OS.
0
 

Author Comment

by:tittu
ID: 24791918
I have a driver module and source code which authenticates biometric thumb impression.
I coud able to place this authentication module before the login screen.
The requirement is to place the authetication module before uncompressing the kernel or at grub stage ?
Is it possible to access driver modules in grub ?.

How do i protect the root file system theft/copying using a rescue CD with this approach ?.

0
 
LVL 7

Accepted Solution

by:
diepes earned 500 total points
ID: 24792053
Hi,
1. You will have to encrypt the HD, to protect against some one steeling the HD or using a rescue CD
     * There is a lot of howto's basic you have a small un-encrypted /boot  and all the rest (LVM) encrypted.
2. When the kernel and initrd.img load from the un-encrypted /boot they will ask for the encryption key, this can also be on a usb device.

0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 43

Expert Comment

by:ravenpl
ID: 24792065
No, grub isn't smart enough to run kernel modules. Sorry,it's merely boot loader.
What You probably could (but would have to build custom solution) is
- include the authentication into initrd script (after kernel is booted, before root filesystem unlocked/mounted)
- include the authentication into /sbin/init or upstart (after initrd is ready and root filesystem up).
0
 
LVL 1

Expert Comment

by:dontdig
ID: 24792610
use trucypt
http://www.truecrypt.org/downloads

but firstly try on demo machine i.e virtual machine
0
 

Author Comment

by:tittu
ID: 25366341
comment is not helpful
0
 

Author Closing Comment

by:tittu
ID: 31600181
partially ok
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will explain how to establish a SSH connection to Ubuntu through the firewall and using a different port other then 22. I have set up a Ubuntu virtual machine in Virtualbox and I am running a Windows 7 workstation. From the Ubuntu vi…
The purpose of this article is to demonstrate how we can use conditional statements using Python.
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question