Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Installing Gentoo
  • Search

Complete disk encryption?

Having problems with the Gentoo Handbook? If you're still working your way through it, or just need some info before you start your install, this is the place. All other questions go elsewhere.
Post Reply
Advanced search
10 posts • Page 1 of 1
Author
Message
The_Great_Sephiroth
Veteran
Veteran
Posts: 1609
Joined: Fri Oct 03, 2014 9:34 pm
Location: Fayetteville, NC, USA

Complete disk encryption?

  • Quote

Post by The_Great_Sephiroth » Sun Mar 08, 2015 4:21 am

I am reading the wiki article on disk encryption and follow it well, but I have a question. If I opt not to use a key-file and use a password, how would that work? Also, is it possible to require the key-file to be on a USB stick? I always keep mine with me and this would mean you would need my laptop AND USB stick to gain access to the system, on top of the root password, user password, or whatever.
Ever picture systemd as what runs "The Borg"?
Top
The Doctor
Bodhisattva
Bodhisattva
User avatar
Posts: 2678
Joined: Tue Jul 27, 2010 10:56 pm

  • Quote

Post by The Doctor » Sun Mar 08, 2015 4:27 am

You don't need a keyfile, of course you could store a keyfile one an external media as long as your init process can mount and read the media.

All you need to do is set a password instead of a keyfile. If you simply use cryptsetup luksFormat <device> it will prompt you to enter a password.

Of course, you can do both.
First things first, but not necessarily in that order.

Apologies if I take a while to respond. I'm currently working on the dematerialization circuit for my blue box.
Top
The_Great_Sephiroth
Veteran
Veteran
Posts: 1609
Joined: Fri Oct 03, 2014 9:34 pm
Location: Fayetteville, NC, USA

  • Quote

Post by The_Great_Sephiroth » Sun Mar 08, 2015 4:34 pm

Alright, if I enter a password, will it be possible to change the password in the future, such as on a schedule or if the unit is transferred to another employee? Also, how would thing work at that point? Would it boot to GRUB and then ask for a password or what?
Ever picture systemd as what runs "The Borg"?
Top
teefax
n00b
n00b
Posts: 11
Joined: Wed Jan 14, 2015 1:33 pm
Location: Germany

  • Quote

Post by teefax » Sun Mar 08, 2015 5:31 pm

LUKS supports up to 8 key slots which you can add/change/remove at any time. That is, you can have e.g. one key that you hand over to your employer and up to 7 additional keys for each employee that requires access to the device.

In order be prompted for a password during startup you will need to generate an initramfs, e.g. with dracut or genkernel.
Top
frostschutz
Advocate
Advocate
User avatar
Posts: 2978
Joined: Tue Feb 22, 2005 11:23 am
Location: Germany

  • Quote

Post by frostschutz » Sun Mar 08, 2015 6:45 pm

Note that if those employees had root access at any point, they might have obtained the master key, which would allow them access regardless of passphrase changes. Note also that the device is inaccessible if no one remembers a password (if your employee had an accident, or whatever) so in such a scenario that involves several people, there should be some plans as to how to handle unexpected circumstances.
Top
Hu
Administrator
Administrator
Posts: 24401
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Sun Mar 08, 2015 7:07 pm

Also, anyone with the passphrase can unlock the device whether or not they finish the boot process, so they could unlock the device in a LiveCD and use that environment to grant themselves extra privileges on the installed system, or use it to extract data they otherwise cannot have on the raw system. In general, you should assume that anyone who has the decryption password and unsupervised physical access to the machine will have the same access that an unencrypted machine grants to someone with unsupervised physical access to the machine.
Top
The_Great_Sephiroth
Veteran
Veteran
Posts: 1609
Joined: Fri Oct 03, 2014 9:34 pm
Location: Fayetteville, NC, USA

  • Quote

Post by The_Great_Sephiroth » Mon Mar 09, 2015 12:43 am

This isn't to keep IT guys out. This is in case the laptop is stolen or lost. The people who would fall into my position after my promotion would have no problem figuring a way around this, but if some retarded thug breaks in and snatches it, they're hosed and our client data is secure.
Ever picture systemd as what runs "The Borg"?
Top
The_Great_Sephiroth
Veteran
Veteran
Posts: 1609
Joined: Fri Oct 03, 2014 9:34 pm
Location: Fayetteville, NC, USA

  • Quote

Post by The_Great_Sephiroth » Mon Mar 09, 2015 2:03 am

I just had an odd thought about this. If I encrypt the disk, would I be able to dual-boot 7 and Gentoo? I seriously doubt I would, but it would be neat if it was possible. Currently I run 7 64bit in VirtualBox, but I have a high-end Dell Latitude at home I game on when traveling, and it would be kind of cool to secure both systems. I use Gentoo for browsing and email, 7 strictly for gaming.
Ever picture systemd as what runs "The Borg"?
Top
chithanh
Retired Dev
Retired Dev
User avatar
Posts: 2158
Joined: Sat Aug 05, 2006 10:16 pm
Location: Berlin, Germany

  • Quote

Post by chithanh » Mon Mar 09, 2015 5:41 pm

Yes, you can still dual-boot while the Gentoo part of your hard disk is LUKS encrypted.

Be aware that someone with control over the Windows 7 installation can use that to attack the Gentoo boot partition.
Top
szatox
Advocate
Advocate
Posts: 3858
Joined: Tue Aug 27, 2013 12:35 pm

  • Quote

Post by szatox » Mon Mar 09, 2015 7:08 pm

Windows uses bitlocker, which is surprisingly similar to what truecrypt used to do (and it makes me a bit suspicious about tc being "deprecated"). I don't think those 2 are compatable, so if you encrypt the whole disk, you will only be able to use one of those.
On the other hand, TC used work with both, windows and linux so it might be possible. And it might be possible if you partition it and encrypt different partitions with different tools.
Top
Post Reply

10 posts • Page 1 of 1

Return to “Installing Gentoo”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic