LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-04-2016, 10:24 AM   #1
Ray52
LQ Newbie
 
Registered: Aug 2016
Posts: 2

Rep: Reputation: Disabled
Recovering Encrypted Drive


My problem is as follows:

I have installed Debian on an Encrypted Hard Drive with a USB flash drive boot key

So /boot is on USB drive the rest is on the encrypted hard drive.

First setup i made the harddisk with a passphrase and then i made a random data 4 kilobyte key file to unlock my harddrive.

This file is /boot/keyfile.gpg

It worked fine, i just insert my usb flash drive and it will start my Debian OS and decrypts the hard drive for me.

Then the problem started. The USB flash drive stopped working, if i start it it says there is no operating system. So i can't start from the USB drive.


Luckely i also have another hard disk in my system with Mint installed. So if i boot into Mint and look at the mounted drives i can see the encrypted drive. I still have (the non booting usb drive) with the keyfile.gpg on it, but i have no idea how i can use that keyfile to decrypt my hard drive. If i click the harddrive it wants a passphrase and there is no option to load a keyfile.

So in my opinion i have 2 option:
1. Make the USB drive bootable again, without destroying the /root and keyfile
2. Decrypt the hard drive with some tool using the keyfile.

What is the best (and working) method to decrypt my drive and get the data off and then reinstall the OS again?
 
Old 08-04-2016, 10:42 AM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,297

Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
You didn't mention your USB drive backup. If you didn't back up, that's a newbie error.

What goes wrong when you try to boot from the USB drive?
 
Old 08-04-2016, 10:46 AM   #3
Ray52
LQ Newbie
 
Registered: Aug 2016
Posts: 2

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by business_kid View Post
You didn't mention your USB drive backup. If you didn't back up, that's a newbie error.

What goes wrong when you try to boot from the USB drive?
Yes you are correct, i didn't back up my USB drive...

If i boot from my USB drive it says no operating system, it looks like the USB is not bootable anymore. I can still open it (in mint) and see the files on it. but no more booting...
 
Old 08-04-2016, 07:04 PM   #4
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,128

Rep: Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121
Have a look at the manpage for cryptsetup - you should be able to use the open command with --key-file.
 
Old 08-05-2016, 08:43 AM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
I've never known anyone who encrypted a hard drive who did not subsequently sorely regret it.
 
Old 08-05-2016, 08:47 AM   #6
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,128

Rep: Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121
Rubbish !!!.
I've got one that has never been breached - not even by me ...

Nah, gotta agree - waste of f'ing effort. The spooks already know everything, or can get it. The crims just ask the spooks for it ... :shrug:

Cynic ... me ???
 
Old 08-06-2016, 01:17 AM   #7
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,297

Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
Quote:
Originally Posted by Ray52 View Post
Yes you are correct, i didn't back up my USB drive...

If i boot from my USB drive it says no operating system, it looks like the USB is not bootable anymore. I can still open it (in mint) and see the files on it. but no more booting...

Is it an issue with the drive or with grub/lilo?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Recovering GPT w/ encrypted partition ajrl Linux - Hardware 1 12-22-2014 09:03 AM
Recovering encrypted LVM partitions garden3 Linux - General 13 07-09-2013 02:17 PM
Recovering data using Knoppix on a PGP encrypted drive crazypoker Linux - Newbie 19 07-05-2013 10:15 AM
Please help with recovering an encrypted partition Ironicus Linux - General 1 01-02-2013 01:53 PM
Problem recovering encrypted partitions lupe *BSD 1 01-17-2012 04:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration