Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Encrypted Swap and Home with LUKS

  1. #1
    Join Date
    Jun 2006
    Location
    Italy
    Beans
    11
    Distro
    Ubuntu 6.06

    Encrypted Swap and Home with LUKS

    I wrote the wiki page https://wiki.ubuntu.com/EncryptedFilesystemHowto3 to show how to encrypt swap and home with LUKS on Ubuntu 6.06 and 5.10

    hope you will find it useful

    bye

  2. #2
    Join Date
    Feb 2006
    Location
    Norway
    Beans
    29
    Distro
    Ubuntu

    Re: Encrypted Swap and Home with LUKS

    nice how-to. didnt know encrypted swap was so easy to set up.

    can you add how to do the same when home is a file, not a partition?
    and if you know, how to integrate this with pam, so login pass will be accepted as mount-pass.

  3. #3
    Join Date
    Apr 2005
    Location
    Parts Unknown
    Beans
    9,213
    Distro
    Ubuntu Development Release

    Re: Encrypted Swap and Home with LUKS

    That looks great. I am going to have to try it out when I have some spare time.
    what's a troll? | my blog | my writing | Ubuntu Unleashed

    Don't ask support questions in PMs--post a thread so everyone can benefit!

  4. #4
    Join Date
    Nov 2005
    Beans
    30

    Re: Encrypted Swap and Home with LUKS

    Very nice!!!

    Would be also wonderful to have a wiki including a fully encrypted ubuntu system...

  5. #5
    Join Date
    Jun 2006
    Location
    Italy
    Beans
    11
    Distro
    Ubuntu 6.06

    Re: Encrypted Swap and Home with LUKS

    Quote Originally Posted by ways
    nice how-to. didnt know encrypted swap was so easy to set up.

    can you add how to do the same when home is a file, not a partition?
    and if you know, how to integrate this with pam, so login pass will be accepted as mount-pass.
    look here:


    However, I won't use PAM, because I think that a good encryption password (diceware.com) isn't a good login/root password; in fact, I prefer to have a long (around 40 chars) encryption password to be used one time, and a mildly long (around 15 chars) system password to be used every time I need.

  6. #6
    Join Date
    Feb 2006
    Location
    Norway
    Beans
    29
    Distro
    Ubuntu

    Re: Encrypted Swap and Home with LUKS

    thanks. those links really helped. but does anyone else get problems with ownership?

    volume * crypt - /home/.&.img /home/& loop,user,exec - -
    in pam_mount

    after mount root owns my home. tried adding uid=&, but apparently ext3 (which i used) does not allow this option.

  7. #7
    Join Date
    Jan 2006
    Beans
    11

    Re: Encrypted Swap and Home with LUKS

    Will this destroy anything in the home folder? Should I start with a clean system before puting anything on it?

  8. #8
    Join Date
    Feb 2006
    Location
    Norway
    Beans
    29
    Distro
    Ubuntu

    Re: Encrypted Swap and Home with LUKS

    Quote Originally Posted by ways
    thanks. those links really helped. but does anyone else get problems with ownership?

    volume * crypt - /home/.&.img /home/& loop,user,exec - -
    in pam_mount

    after mount root owns my home. tried adding uid=&, but apparently ext3 (which i used) does not allow this option.
    works now. dont think i changed anything.


    Will this destroy anything in the home folder? Should I start with a clean system before puting anything on it?
    it will, if you follow the guide and reformat a home partition. but if you choose to create a file to keep "home" in, you can do it without deleting anything.

  9. #9
    Join Date
    Jun 2006
    Location
    Italy
    Beans
    11
    Distro
    Ubuntu 6.06

    Re: Encrypted Swap and Home with LUKS

    Quote Originally Posted by ways
    it will [destroy anything in the home folder], if you follow the guide and reformat a home partition. but if you choose to create a file to keep "home" in, you can do it without deleting anything.
    I've updated the guide to better explain home data preservation.

    From the guide, warnings section:
    encrypting a partition is a destructive operation; then, your new home partition (/dev/hda3) must be empty, because all data on it will be erased.

    unencrypted data on the old home directory won’t be deleted and will be accessible, for example, with a live CD; then, you shouldn't put any sensible data on home before encrypting.

    otherwise, if you have sensible data to delete securely from the old unencrypted home, you should shred the old home directory.

    if the partition containing the old home directory is formatted with a journaled file system (JFS, ReiserFS, XFS, Ext3, etc.), you must boot with a live CD and shred the entire partition containing the old home directory.

    if the shredded partition is the partition containing the OS, reinstall ubuntu, and finally mount the previously created encrypted home.

    references for secure deletion:

    http://man.linuxquestions.org/index....pe=2&section=1

    http://www.cs.auckland.ac.nz/~pgut00...ecure_del.html

  10. #10
    Join Date
    Feb 2006
    Location
    Norway
    Beans
    29
    Distro
    Ubuntu

    Re: Encrypted Swap and Home with LUKS

    anyone else lost suspend & hibernate after doing this?

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •