#!/bin/bash # omarchy:summary=Set a new encryption password for a drive selected. # omarchy:requires-sudo=true encrypted_drives=$(blkid -t TYPE=crypto_LUKS -o device) if [[ -n $encrypted_drives ]]; then if (( $(wc -l <<<"$encrypted_drives") == 1 )); then drive_to_change="$encrypted_drives" else drive_to_change="$(omarchy-drive-select "$encrypted_drives")" fi if [[ -n $drive_to_change ]]; then new_password=$(gum input --password --header "New encryption password") || exit 1 [[ -n $new_password ]] || { echo "Password cannot be empty."; exit 1; } confirmation=$(gum input --password --header "Confirm new encryption password") || exit 1 [[ $new_password == "$confirmation" ]] || { echo "Passwords do not match."; exit 1; } echo "Changing full-disk encryption password for $drive_to_change" # The new key travels over stdin and reaches cryptsetup as a keyfile via # <(cat), leaving the tty free for the current-passphrase prompt. printf "%s" "$new_password" | sudo bash -c 'exec cryptsetup luksChangeKey --pbkdf argon2id --iter-time 2000 "$1" <(cat)