Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242230 > unrolled thread

Late encryption of /home Partition

Started byKlaus Singvogel <deb-user-ml@singvogel.net>
First post2021-11-18 14:50 +0100
Last post2021-11-18 23:00 +0100
Articles 5 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  Late encryption of /home Partition Klaus Singvogel <deb-user-ml@singvogel.net> - 2021-11-18 14:50 +0100
    Re: Late encryption of /home Partition Charles Curley <charlescurley@charlescurley.com> - 2021-11-18 18:00 +0100
      Re: Late encryption of /home Partition Hans <hans.ullrich@loop.de> - 2021-11-18 18:20 +0100
        Re: Late encryption of /home Partition Charles Curley <charlescurley@charlescurley.com> - 2021-11-18 20:10 +0100
          Re: Late encryption of /home Partition Klaus Singvogel <deb-user-ml@singvogel.net> - 2021-11-18 23:00 +0100

#242230 — Late encryption of /home Partition

FromKlaus Singvogel <deb-user-ml@singvogel.net>
Date2021-11-18 14:50 +0100
SubjectLate encryption of /home Partition
Message-ID<DkPXB-59q-17@gated-at.bofh.it>
Hi,

I installed Debian 11 (bullseye) on a fresh PC.
I created 3 partitions: /, swap, /home.

...and forgot during installation dialog to encrypt the /home partition.

- how can I encrypt the /home partition now?
- In such a way that the password is asked for manual input during every boot?

- does it make sense to use a LVM atop? How?

I usually prefer using shell commands before graphical stuff, but will accept GUI tools either.

Thanks in advance.

Best regards,
	Klaus Singvogel.

[toc] | [next] | [standalone]


#242231

FromCharles Curley <charlescurley@charlescurley.com>
Date2021-11-18 18:00 +0100
Message-ID<DkSVs-6Tv-9@gated-at.bofh.it>
In reply to#242230
On Thu, 18 Nov 2021 14:40:14 +0100
Klaus Singvogel <deb-user-ml@singvogel.net> wrote:

> I installed Debian 11 (bullseye) on a fresh PC.
> I created 3 partitions: /, swap, /home.
> 
> ...and forgot during installation dialog to encrypt the /home
> partition.
> 
> - how can I encrypt the /home partition now?
> - In such a way that the password is asked for manual input during
> every boot?
> 

You can. These instructions are adapted from notes I took on a similar,
related project. You do risk making your system unbootable, and
requiring a fresh installation, so proceed with caution.

Copy everything you want to preserve from the /home partition to
somewhere else. Use tar or the like to preserve permissions.

Log out all non-root users, and umount /home.

Encrypt that partition:

cryptsetup -y -v luksFormat /dev/sdaX
cryptsetup luksOpen /dev/sdaX encryptedhome

Check your work:

cryptsetup -v status encryptedhome
cryptsetup luksDump /dev/sdaX

cryptsetup luksHeaderBackup /dev/sdaX --header-backup-file ${HOSTNAME}.$(date +%Y.%m.%d).luks.home.backup

Then build the LVM on top of /dev/mapper/encryptedhome:

See: https://www.linuxsysadmins.com/create-logical-volume-filesystem-in-linux/

pvcreate /dev/mapper/encryptedhome	# create the physical volume.
vgcreate ${HOSTNAME}-vg /dev/mapper/encryptedhome	# Create the volume group.
lvcreate -n homelv -L <SIZE> ${HOSTNAME}-vg	# Create a logical volume the size of the old /crc partition.

where <SIZE> is the available space less some 20 GB so 1) you have
room to grow, and 2) a background task in Bullseye has a place to
create snapshots and fsck them.

And finally, create and (optionally) tune the file system:

mkfs.ext4 /dev/mapper/${HOSTNAME}-vg-homelv
tune2fs -i 3m -c 15 /dev/mapper/${HOSTNAME}-vg-homelv

When you've done that, mount /dev/mapper/${HOSTNAME}-vg-homelv on
/home, and restore your data.

Then edit /etc/fstab to suit. Then run update-grub. Then reboot to see
if you got everything right.

> - does it make sense to use a LVM atop? How?

It may. I mentioned two reasons to do so and leave some empty
space. It would have been better to include the encryption and LVM as
part of installing,

-- 
Does anybody read signatures any more?

https://charlescurley.com
https://charlescurley.com/blog/

[toc] | [prev] | [next] | [standalone]


#242232

FromHans <hans.ullrich@loop.de>
Date2021-11-18 18:20 +0100
Message-ID<DkTeO-7fy-9@gated-at.bofh.it>
In reply to#242231
Hi all,

as far as I know, you also have to edit /etc/crypttab.

If one has forgotten to encrypt a partition, the easiest way is, to boot from 
a livefile system. Then backup the whole content of this partition to an 
external partition. Note, this should be a ext3 or ext4 partition, so you 
preserve all hard- and softlinks.

I suggest for using rsync doing this.

Then you can encrypt and format this partion and rsync everything back.

Doing so, I never lost data or settings.

Hope this helps.

Best regards

Hans

[toc] | [prev] | [next] | [standalone]


#242233

FromCharles Curley <charlescurley@charlescurley.com>
Date2021-11-18 20:10 +0100
Message-ID<DkUXi-8jP-51@gated-at.bofh.it>
In reply to#242232
On Thu, 18 Nov 2021 18:17:43 +0100
Hans <hans.ullrich@loop.de> wrote:

> as far as I know, you also have to edit /etc/crypttab.

Correct. Sorry, I forget that. "man crypttab".

Do this before you run update-grub.


> 
> If one has forgotten to encrypt a partition, the easiest way is, to
> boot from a livefile system. Then backup the whole content of this
> partition to an external partition. Note, this should be a ext3 or
> ext4 partition, so you preserve all hard- and softlinks.
> 
> I suggest for using rsync doing this.

I find tar easier to use for this, but rsync will do it, as you say,
provided one has an ext[34] partition to copy to.

-- 
Does anybody read signatures any more?

https://charlescurley.com
https://charlescurley.com/blog/

[toc] | [prev] | [next] | [standalone]


#242242

FromKlaus Singvogel <deb-user-ml@singvogel.net>
Date2021-11-18 23:00 +0100
Message-ID<DkXBL-1fp-7@gated-at.bofh.it>
In reply to#242233
Hi,

thanks for all your help. It's working now as expected.

Fun fact: Had a small issue with the UUIDs, where I added a quote on left
side to a system config file, but none was allowed there. Therefore
(auto-)mounting failed (/dev/disk/by-uuid/\x22...) and it took some time
till the system came up without mounted /home.

For the sake of completeness: data loss was never possible, as it was a
fresh installed machine, which was never used productively.

Thanks again.

Best regards,
	Klaus.
-- 
Klaus Singvogel
GnuPG-Key-ID: 1024R/5068792D  1994-06-27

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web