LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 12-01-2016, 11:09 AM   #1
kaplan71
Member
 
Registered: Nov 2003
Posts: 809

Rep: Reputation: 39
Implementing encryption


Hello --

We are going to be deploying a server with Red Hat Enterprise 7.3 as its operating system. The server has 256 GB of RAM, and is going operate in the following capacities:

1. NFS server
2. Samba server - with Active Directory authentication enabled
3. Postgres database server
4. NIS authentication server

The configuration will include encryption of all filesystems. I did some research into this, and I came across the RHEL-native LUKS disk encryption, and also the eCryptFS file system service.

I had several questions concerning the two encryption methods:

1. Are the two methods exclusive from each other, or can they be used together?
2. How much of a performance impact does each solution have on general operations?
3. If there are problems with implementing the above solutions, does anyone have an alternative?
 
Old 12-02-2016, 05:14 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,627

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
We have implemented LUKS on a couple of RHEL 7 servers at work. It does slow things down a bit, but our systems have on the order of 360G ram, 32 or 64 cores, and fast SAN storage which limits the impact. We found that there was more impact to Database performance if you were using the XFS, or ReiserFS file systems: EXT4 did significantly better. Your mileage may vary.
 
Old 12-02-2016, 07:40 AM   #3
kaplan71
Member
 
Registered: Nov 2003
Posts: 809

Original Poster
Rep: Reputation: 39
Hello --

Thank-you for your reply. I had a follow-up question regarding the LUKS implementation. According to documentation that I read, LUKS is effective when the system is either shut down, or in single-user mode, but not when in run level 2 and above. If that is correct, how would the filesystems on the server be encrypted?
 
Old 12-03-2016, 06:52 AM   #4
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,627

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
Quote:
Originally Posted by kaplan71 View Post
Hello --

Thank-you for your reply. I had a follow-up question regarding the LUKS implementation. According to documentation that I read, LUKS is effective when the system is either shut down, or in single-user mode, but not when in run level 2 and above. If that is correct, how would the filesystems on the server be encrypted?
Perhaps you misunderstand what they are saying here, and what encryption is FOR.
If someone rips open the machine and steals the drive, proper encryption ensures that they cannot get into the data on it easily. While the system is running the OS must be able to do encryption/decryption on the fly to make use of the disk. If something makes use of the OS while they system is up and running then it can read anything the OS can read because they OS is decrypting the data for your sessions and applications.

I see great purpose in encryption for disks and tapes that will be transported (at risk), but I see MUCH less value in using encryption for server disks in a physically secured and protected environment. Some companies and auditors have, I believe, adopted it as a standard without understanding the value. Encryption in place is not very real protection for any data.

Encryption makes the data disks nearly totally unusable (in terms of data collection) without the disks used to boot the OS it was configured with, or the security keys extracted from that disk. WITH that disk or key, it is as readable as this post. (Perhaps more so, I am not a great writer.)
To avoid greater risk when using it, you need a secure way and place to back up the security keys: in a place physically and logically separated from the server. I also recommend doubling up on your backups, and keep in mind that to maintain the protection levels you need to encrypt your backups and maintain and secure THOSE keys as well!

If the data will ever be in motion, and the risk justifies it, encryption is very doable and worthwhile. It is something of a "can of worms" project that has implications for your systems and performance, backups and Disaster Recovery plans, onsite and offsite storage and record keeping, auditing, and more. Great fun!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Non-system partition encryption versus container-file encryption of equal size Ulysses_ Linux - Security 13 07-17-2015 07:38 PM
error while implementing encryption in ns2 vartika.shah Linux - Wireless Networking 2 06-28-2014 01:26 AM
Implementing 3DES Encryption in linux thirumalesh Programming 0 02-06-2009 01:20 AM
Linux password encryption and data encryption Tux-Slack Programming 4 06-20-2007 06:46 AM
Mandrake 9.0 Wireless Works without encryption.. does not with encryption topcat Linux - Wireless Networking 3 05-04-2003 08:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 02:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration