LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-18-2011, 05:16 PM   #1
mgrunt
LQ Newbie
 
Registered: Oct 2011
Posts: 4

Rep: Reputation: Disabled
ecryptfs


Hi, I have HP Microserver with one HDD. I was installed last Debian. I'm using LVM with ecryptfs. Every time when is PC booting, i must type password. It is posible (and how) using USB flash where is save private key and when is PC booting and USB flash is connect, PC is automatically starting?

Thank you
MG
 
Old 10-19-2011, 07:44 AM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Welcome to LQ security.

You have run into one of the core problems with whole HDD encryption, booting. In order to boot, the file system needs to be decrypted. The decryption key is password protected and to do otherwise would be both foolish and would defeat the purpose of encrypting the drive. I know of no way to put your password / key on a USB stick and use that to start up, and again - you run the real risk of defeating the purpose of encryption. My initial response would be to suggest that you reconsider your approach and ask why you are encrypting the WHOLE HDD? What I am getting at is do you really care if directories like /bin, which contain system binaries that are exact duplicates of widely distributed software is encrypted or are you more concerned with your personal files located in your user's home directory. If you encrypt your home directory, it can be decrypted and mounted automatically when you log in, but the system can boot an other users (if any) can still access the system.

Edit: This subject has come up several times over the last year or so. A search of the security forum will provide you with a lot of information for research on the subject.
 
Old 10-19-2011, 02:31 PM   #3
realbluntz
Member
 
Registered: Jun 2010
Location: the D
Distribution: arch x86_64
Posts: 57

Rep: Reputation: 3
Encrypting the entire HDD usually isn't needed unless you're paranoid (or you don't have home partitioned).

Your solution may be installing your bootloader on the the USB with the key and configuring accordingly.
 
Old 10-19-2011, 05:24 PM   #4
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
While I use LUKS without LVM it is entirely possible to set up HDD encryption to require a keyfile when booting, and to store said keyfile on a USB stick, so that boot is not possible without it plugged in. It is not complicated but does take some time and effort to implement. There are numerous HOW-TO's around the net.

The simplest approach is that mentioned by realbluntz and having your boot files and keyfile on the USB derive and booting from it.

A look through the security sub-forum, as suggested by Noway2 should yield plenty of reading material.

Why encrypt an entire drive? Because there are often bits and pieces of data stored elsewhere that can provide clues to an intruder. Some of us also don't believe in giving any advantage to a thief at all. Most drive encryption for a home user is more to protect information in case the drive is stolen than any other reason. Other reasons include work, political activity, social activism, etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
can't mount ecryptfs as user mike11 Linux - Newbie 2 12-19-2010 11:59 PM
eCryptfs idlehands Linux - Security 3 10-04-2010 03:22 AM
[SOLVED] eCryptfs/ext4/Ubuntu 10.04 riganta Linux - Laptop and Netbook 3 05-20-2010 10:57 AM
[ECRYPTFS] ecryptfs_init_miscdev: Error whilst attempting to open [/dev/ecryptfs] nitinarora Linux - Kernel 0 03-22-2010 05:36 AM
ecryptfs installation problem nkd Linux - Security 3 10-02-2007 03:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration