LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-02-2015, 01:21 PM   #1
Mr. Alex
Senior Member
 
Registered: May 2010
Distribution: No more Linux. Done with it.
Posts: 1,238

Rep: Reputation: Disabled
ext4 filesystem encryption — is it suitable for ~ ?


Hi LQ.org! Linux v4.1 has new feature — filesystem level encryption. Is it suitable for encrypting home dir in a way where when loading Arch Linux it will prompt for passphrase to get access to ~ and if passphrase cannot be entered you don't get access to ~ files?
 
Old 08-02-2015, 01:43 PM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,621

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
Encryption

FWIW: I have done some test trials involving one form (LUKS) of encryption and different file systems. It is interesting how they interact.
My results would indicate that, yes, it is suitable for home folder encryption. Or entire file system encryption.

There are, however, I/O penalties that are more than what I have seen described elsewhere. Advantage goes to a box with FAR more ram than you expect to need, that made more difference than minor CPU variations. Advantage to ext4 over xfs, or most other journalled formats.

The company owns the test results, so I cannot share them here. If I get time to do somewhat similar tests on my home systems I will be glad to post the results.

Some distros now enable home folder encryption by default. I prefer to run without it and keep any HIPAA data in another and more secured location.
 
Old 08-02-2015, 08:35 PM   #3
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,126

Rep: Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120
The ext4 encryption is supposed to alleviate the memory footprint issue, but I haven't tested for it.
I note that the 4.1 Fedora kernel doesn't have all the options set. And no new e2fsprogs.

I'll check Arch later - but it looks like not all the necessary parts are there yet. And no note from Ted on the ext4 wiki either. Hmmmm.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ext4 Encryption. cwizardone Slackware 6 06-29-2015 02:37 AM
Linux 4.1 - ext4 encryption coralfang Linux - Software 1 06-25-2015 04:24 PM
problem with ext4 filesystem farazinux Linux - Server 5 03-03-2013 07:57 AM
support for ext4 filesystem info1686 Programming 2 06-30-2009 11:49 PM
Resize ext4 partition with LUKS encryption wsduvall Linux - Software 1 03-09-2009 10:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration