> > To have /boot unencrypted, you have to have a separate partition for just /boot, which is undesirable. what a problem? it is standard on ALL my instalations - just to have booting independent of configuration i make. i often put this (by using gmirror or making copies) on all disks so i don't have to care about disk numbering etc.