OpenVZ Forum


Home » General » Support » ecryptfs inside container - supported?
ecryptfs inside container - supported? [message #39532] Thu, 06 May 2010 15:52 Go to next message
hverbeek is currently offline  hverbeek
Messages: 2
Registered: May 2010
Junior Member
I'd like to use ecryptfs inside a container - is that supported?

When I try to mount a directory, I get the following error:
Unable to get the version number of the kernel
module. Please make sure that you have the eCryptfs
kernel module loaded, you have sysfs mounted, and
the sysfs mount point is in /etc/mtab. This is
necessary so that the mount helper knows which 
kernel options are supported.

Make sure that your system is set up to auto-load
your filesystem kernel module on mount.

Enabling passphrase-mode only for now.

Error attempting to evaluate mount options; rc = [-95]. See your system logs for more details on why this happened. Try updating/reinstalling your ecryptfs-utils package, contact your operating system vendor, and/or submit a bug report on the ecryptfs-devel mailing list on Launchpad.
 failed!


OVZ Host is debian lenny:
Linux cheetah 2.6.26-2-openvz-amd64 #1 SMP Tue Mar 9 23:10:10 UTC 2010 x86_64 GNU/Linux
vzctl version 3.0.22

I have tried to load the ecryptfs kernel module on the host, does not help...
Inside the container, /proc/filesystems does not show ecryptfs

Thanks!! Cheers, Hank
Re: ecryptfs inside container - supported? [message #39533 is a reply to message #39532] Thu, 06 May 2010 21:59 Go to previous messageGo to next message
sunoano is currently offline  sunoano
Messages: 8
Registered: January 2010
Junior Member
have a look at
http://sunoano.name/ws/public_xhtml/debian_security.html#fil esystem-level_encryption
Re: ecryptfs inside container - supported? [message #39534 is a reply to message #39533] Fri, 07 May 2010 06:54 Go to previous messageGo to next message
hverbeek is currently offline  hverbeek
Messages: 2
Registered: May 2010
Junior Member
Thanks sunoano, very nice howto.

My point though is that I'd like to run it *inside* the VE, if that is possible. I would like to avoid having to do this on the OVZ Host (via the /vz/root/<VEID> path).

Cheers,
Hank
Re: ecryptfs inside container - supported? [message #39535 is a reply to message #39534] Fri, 07 May 2010 09:11 Go to previous messageGo to next message
sunoano is currently offline  sunoano
Messages: 8
Registered: January 2010
Junior Member
I'd love to not having to touch the HN as well; afaict there's no other way that's why I do the mount/umount from the HN. Maybe there is some way now, there wasn't fall 2009 when I set things up.

If you come across some info that would allow us not having to involve the HN then by all means, tell me please Very Happy
Re: ecryptfs inside container - supported? [message #39541 is a reply to message #39532] Fri, 07 May 2010 14:34 Go to previous message
maratrus is currently offline  maratrus
Messages: 1495
Registered: August 2007
Location: Moscow
Senior Member
No, unfortunately ecryptfs is not virtualized yet.
But you can file a new bug report. I don't think that
it will have very high priority but at least it will
indicate that somebody needs this feature.
Previous Topic: (NAT Internet for containers) in a container
Next Topic: Configure vps.basic
Goto Forum:
  


Current Time: Mon Jul 15 12:10:18 GMT 2024

Total time taken to generate the page: 0.02389 seconds