fscrypt icon indicating copy to clipboard operation
fscrypt copied to clipboard

[Feature] Automatically re-use recovery protector when re-using login protector

Open Redsandro opened this issue 5 years ago • 1 comments

Encrypting a new directory with a new v2 policy re-uses the login protector. However, it does not re-use the recovery protector, but creates a new one (Y/n). User ends up with multiple directories with the same login protector but different recovery protectors.

After offering to create a recovery protector (recommended), perhaps fscrypt can ask if the user would like to re-use [list all keys with "Recovery" in the description] or create a new one.

Or detect what recovery protector is used by another policy that uses the login protector.

In the end it makes sense for the user to have the same recovery passphrase for directories that use the same login protector.

Redsandro avatar Sep 11 '20 12:09 Redsandro

This was exactly my thinking, will probably mesh well with #249

josephlr avatar Sep 11 '20 13:09 josephlr