Skip to main content

Encrypt partition using LUKS

At work, I have a desktop running Fedora which has an SSD.  I still am a bit old school, I suppose, and don't have as much confidence in their longevity.  I also realize that this is probably not a valid concern, particularly based on the way I use the disk, which is mostly reads.  Furthermore, I realize that my concern for losing a drive should be addressed in the same manner whether I have an SSD or an archaic spinning platter...

So - I have an external disk which I backup to weekly.  I am moderately concerned about my desktop being compromised by someone at the keyboard, but I am more concerned that someone has the ability to walk by and see my external disk hanging off my PC and try to access it from another PC.  I have a slight advantage of being protected in that the average low-life probably doesn't know anything about Linux.

NOTE: If you are particularly worried about security, do NOT create the keyfile which will force you to enter a passphrase each time.


parted -a none /dev/sdb mklabel gpt
parted -a none /dev/sdb mkpart -- primary ext4 1 -1
parted /dev/sdb unit b print

dd if=/dev/urandom of=/root/.kyfl bs=1024 count=4
chmod 0400 /root/.kyfl

yum install cryptsetup-luks
cryptsetup -y -v luksFormat /dev/sdb1

WARNING!
========
This will overwrite data on /dev/sdb1 irrevocably.

Are you sure? (Type uppercase yes): YES
Enter LUKS passphrase:
Verify passphrase:
echo <PassPhrase> | cryptsetup luksAddKey /dev/sdb1 /root/.kyfl

cryptsetup luksOpen --key-file /root/.kyfl /dev/sdb1 backups
mkdir /backups
mkfs.ext4 /dev/mapper/backups
mount /dev/mapper/backups /backups/
umount /backups
cryptsetup luksClose backups

echo "backups /dev/sdb1 /root/.kyfl luks" >> /etc/crypttab
echo "/dev/mapper/backups /backups ext4 defaults 0 2" >>
/etc/fstab



Comments

Popular posts from this blog

PXE boot a LiveCD image

Summary: I have wanted to build a kickstart environment which hosted a "rescue CD" or LiveCD to allow you to boot over the network after you blew your stuff up and needed to repair a few things.  Today I have worked through a method of doing so, with the help of the people who published a succinct script with the Red Hat Enterprise Virtualization Hypervisor.  (the script will be at the bottom of this post - if I have somehow not followed the GPL, please let me know and I will correct whatever is necessary) NOTE/Warning: The boot will fail due the initrd being too large (645mb).  I'm not sure how to proceed.  This procedure worked for RHEVh, because it is quite a bit smaller.  Hopefully I can report back with progress on this? :-$ Procedure: download your LiveCD image to /export/isos/RESCUE/Fedora-16-i686-Live-Desktop.iso # cd /var/tmp # vi livecd-iso-to-pxeboot (populate the file with the script shown below) # chmod 754 ./livecd-iso-to-pxeb...

"Error getting authority: Error initializing authority: Could not connect: No such file or directory (g-io-error-quark, 1)"

"Error getting authority: Error initializing authority: Could not connect: No such file or directory (g-io-error-quark, 1)" One issue that may cause this to arise is if you managed to break your /etc/fstab We had an engineer add a line with the intended options of "nfsvers=3" but instead added "-onfsvers=3" and it broke the system fairly catastrophically.

MOTD with colors! (also applies to shell profiles)

I'm not sure why I had never looked into this before, but this evening I became obsessed with discovering how to present different colored text in the /etc/motd. A person had suggested creating a shell script (rather than using special editing modes in vi, or something) and I agree that is the simplest way of getting this accomplished quickly. This most noteworthy portion of this script is the following: RESET="\033[0m" that puts the users shell back to the original color. I typically like a green text on black background. Also - a great reference for the different colors and font-type (underscore, etc...) https://wiki.archlinux.org/index.php/Color_Bash_Prompt I found this example on the web and I wish I could recall where so that I could provide credit to that person. #!/bin/bash #define the filename to use as output motd="/etc/motd" # Collect useful information about your system # $USER is automatically defined HOSTNAME=`uname -n` KERNEL=`un...