Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #185164

Re: Unusual LUKS setup

From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: Unusual LUKS setup
Date 2017-08-14 12:30 +0200
Message-ID <uekNb-2XS-5@gated-at.bofh.it> (permalink)
References <uekav-2tS-27@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Aug 14, 2017 at 11:27:00AM +0200, Nicolas George wrote:
> Hi.
> 
> I have been using LUKS to encrypt part of my system, with a rather
> unusual setup, and I would like to ask for advice on making it more
> standard without sacrificing my requirements.

[...]

> - The system partitions are not encrypted. The partitions containing
>   personal data are encrypted using LUKS.

I tend to the other extreme: everything (save /boot) is encrypted,
as one big (physical, in the LVM sense) volume. Partitions whithin
it are logical (LVM) volumes. Yes, that's more or less the standard
Debian way.

Among other things this gives me peace of mind about (copies of)
sensitive data hanging around /var (/var/lib/postgresql, for example,
has a copy of my banking transactions history somewhere).

This brings the "LUKS question" to the earliest point, namely when
trying to mount /.

Now SSH... to fulfill that in this setting, the initramfs must have
some ssh server capability. I've heard that you can bake in dropbear
SSH in the initramfs, which sounds pretty elegant. Never tried, though.

Downside would be that now you've got *two* sshd instances to take
care of, security-wise.

No idea about how (or whether) that interacts with systemd (and
honestly, not very keen on finding out :)

Perhaps you knew all of this, but perhaps this gives you some ideas.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmReqIACgkQBcgs9XrR2kb9igCZASe/htbyVdUGTjU3GzSS2tL4
ougAnA6rwQGe9EPJshxhFsraDfOAMDiT
=R3Jm
-----END PGP SIGNATURE-----

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 11:50 +0200
  Re: Unusual LUKS setup Darac Marjal <mailinglist@darac.org.uk> - 2017-08-14 12:20 +0200
    Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 16:40 +0200
      Re: Unusual LUKS setup Bastien Durel <bastien@durel.org> - 2017-08-14 17:10 +0200
        Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 18:00 +0200
          Re: Unusual LUKS setup Bastien Durel <bastien@durel.org> - 2017-08-16 10:10 +0200
            Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 15:40 +0200
  Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-14 12:30 +0200
    Re: Unusual LUKS setup tomas@tuxteam.de - 2017-08-14 16:40 +0200
      Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 18:10 +0200
        Re: Unusual LUKS setup tomas@tuxteam.de - 2017-08-14 21:30 +0200
      Re: Unusual LUKS setup Curt <curty@free.fr> - 2017-08-15 14:20 +0200
        Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-15 17:30 +0200
          Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 21:10 +0200
            Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 04:50 +0200
              Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-16 09:40 +0200
                Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 15:30 +0200
        Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 21:00 +0200
          Re: Unusual LUKS setup Brian <ad44@cityscape.co.uk> - 2017-08-15 21:40 +0200
            Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 22:20 +0200
    Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 16:50 +0200

csiph-web