LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-23-2014, 09:22 AM   #1
postcd
Member
 
Registered: Oct 2013
Posts: 527

Rep: Reputation: Disabled
How to protect linux by full disk encryption


Hello, you may know that linux root password can be resetted (example from rescue mode), so this means linux server offers no protection against access of data when you get somehow remote or physical access to server?

So my question is how i can full encrypt linux webserver disk so no one can read disk data even he got physical access to the server? the best way, links? thank you
 
Old 03-23-2014, 11:05 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by postcd View Post
how i can full encrypt linux webserver disk so no one can read disk data even he got physical access to the server?
There's a gazillion HOWTOs that detail how to encrypt disks. Please do a search for those. What you should be a ware of is that there's basically three states for data (at rest, in flight and in use) and that data needs to be accessible (decrypted) for any process to work. So full disk encryption itself won't shield data that is in flight or in use. More than that access to the infrastructure and the machine means all bets are off: if a machine is running any sane investigator will want to seize all network traffic, volatile memory and decrypted disk contents.
 
Old 03-23-2014, 11:44 AM   #3
postcd
Member
 
Registered: Oct 2013
Posts: 527

Original Poster
Rep: Reputation: Disabled
How to go about partition encryption on remote server?

Hi,

im having an linux webserver located in another country and i have just SSH access.

My aim is to protect (by encryption) /home partition on which are located website files and mysql database data.

So i found "LUKS" SW which can encrypt partition, but the thing i dont understand is how not to cause failures when apps like apache, mysql cals files from /home while its still encrypted after server boot, and how im able to enter decryption password after /during boot over SSH? What is the process, any tutorial, or you have better idea on webserver disk encryption? thx

Last edited by postcd; 03-23-2014 at 11:59 AM.
 
Old 03-23-2014, 12:12 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
//Moderator note

Since your questions are closely related and the second one follows the first too soon after I've merged your threads.
 
Old 04-03-2014, 08:47 AM   #5
r0b0
Member
 
Registered: Aug 2004
Location: Europe
Posts: 608

Rep: Reputation: 50
Quote:
Originally Posted by postcd View Post
So i found "LUKS" SW which can encrypt partition, but the thing i dont understand is how not to cause failures when apps like apache, mysql cals files from /home while its still encrypted after server boot, and how im able to enter decryption password after /during boot over SSH? What is the process, any tutorial, or you have better idea on webserver disk encryption?
Yes, LUKS is what I would recommend to use.

And to answer your question: You need to set the /home partition as noauto in crypttab and unlock and mount it manually using ssh. Of course, until you do, any processes/services trying to access files in /home will fail so you need to have a process in place do this as quickly as possible every time the system (re)boots.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Creating a new partition on a remote linux server. Manjunath1847 Linux - Software 3 05-19-2009 01:44 AM
Remote backup with encryption miek Linux - Software 5 10-12-2007 07:15 AM
using a remote computer without encryption MrFixit Linux - General 5 09-01-2007 04:47 PM
Remote full disk encryption anonymous-coward Linux - Software 3 09-01-2007 06:25 AM
Remote VNC Login Encryption dsschanze Linux - Software 1 12-23-2004 07:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration