Docs/Drafts/CryptoGuide/LUKSDiskEncryption

Introduction to LUKS
Linux Unified Key Setup-on-disk-format (or LUKS) allows you to encrypt partitions on your Linux computer. This is particularly important when it comes to mobile computers and removable media. LUKS allows multiple user keys to decrypt a master key which is used for the bulk encryption of the partition.

LUKS Implementation in Fedora 9
Fedora 9 utilizes LUKS to perform file system encryption. By default, the option to encrypt the file system is checked during the installation. You are prompted for a passphrase that will be asked every time you boot the computer. This passphrase "unlocks" the bulk encryption key that is used to decrypt your partition.

If you choose to modify the default partition table you can choose which partitions you want to encrypt. This is set in the partition table settings.

Encrypted Home Directories
The following procedure will reconfigure and format your. The procedure is for single-user computers or computers that are shared between trusted users.

The following procedure will wipe all your existing data, so be sure to have a tested backup before you start. This also requires you to have a separate partition for  (in my case that is  ). All the following must be done as root. Any of these steps failing means you must not continue until the step succeeded.

Step-by-Step Instructions

 * enter runlevel 1:
 * unmount your existing /home:
 * if it fails use fuser to find and kill processes hogging /home:
 * verify /home is not mounted any longer:
 * fill your partition with random data:


 * initialize your partition:
 * open the newly encrypted device:
 * check it's there:
 * create a filesystem:
 * mount it:
 * check it's visible:
 * add the following to /etc/crypttab:
 * edit your /etc/fstab, removing the old entry for /home and adding
 * verify your fstab entry:
 * restore default SELinux security contexts:
 * reboot:
 * The entry into /etc/crypttab makes your computer ask your luks passphrase on boot.
 * Log in as root and restore your backup.

What you have just accomplished.
Congratulations, you now have an encrypted partition for all of your data to safely rest while the computer is off.

Links of Interest / For More Information

 * LUKS - Linux Unified Key Setup

= DRAFT BELOW HERE =

Using a USB Key Token
http://www.saout.de/tikiwiki/tiki-index.php?page=EncryptedVarWithUSBKey

Adding Additional Keys
LUKS allows multiple passphrases to be used to "unlock" the master key that is used to handle the bulk encryption of the partition.

FIXME