whoami
}
rule_key_disk_send () {
- gpg --decrypt var/lib/luks/$vm_fqdn.key.gpg |
+ gpg --decrypt var/sec/luks/$vm_fqdn.key.gpg |
"$tool"/vm_ssh root@$vm_fqdn "$@" \
-o CheckHostIP=no \
-o HostKeyAlias=init.$vm_fqdn \
rule_key_disk_backup () {
for part in root var home
do
- mkdir -p var/lib/luks
+ mkdir -p var/sec/luks
rule ssh -l root ' \
tmp=$(mktemp)
cryptsetup luksHeaderBackup \
shred --remove "$tmp"
' |
gpg --encrypt --recipient $USER@ \
- -o var/lib/luks/${vm_lvm_lv}_${part}.luks.gpg
+ -o var/sec/luks/${vm_lvm_lv}_${part}.luks.gpg
done
}