Login Register






Protecting partitions with LUKS encryption filter_list
Author
Message
Protecting partitions with LUKS encryption #1
NOTE: Reposting due to europol or something.





I've used LUKS a few times now for various encryption needs, including my flash drive. I have a tendency to misplace things like flash drives, and in the event I happen to misplace it (read have one fall out of my pocket) I don't want any Joe on the street to be able to snatch it up and open my stuff. Various solutions exist for flash drive encryption, including hardware specific encryption. However, these devices are typically more expensive which makes having more than one available a bit of a challenge.

LUKS is an acronym for Linux Unified Key Setup, and while originally intended for use with Linux, is now a platform independent encryption solution. In this tutorial I'm going to explain how to prepare and use a partition/disk/block device with LUKS encryption.

We'll begin by preparing our device. I'll be using a disk partition in my example. Replace the device name I use with the name of your device. In my example I'll be creating a partition on my /dev/sdb device (second hard drive in the system). I'm going to create a 200MiB partition, then use LUKS to encrypt it. I will then open the encrypted partition, and format it using the EXT4 filesystem.

Make Partition

Code:
fdisk /dev/sdb n for new partition p for primary partition (it doesn't have to be primary, I'm just using default options) 1 for partition 1 (default for my system, yours may vary) default option for beginning sector I'm doing a 200MiB partition, so I will use +200M for my end size. w for write partition table q for quit
fdisk, done

Next we'll create the LUKS encryption.
Code:
sudo cryptsetup luksFormat /dev/sdb1
You'll get a message about destroying stuff and things; since this is a fresh disk/partition, I think I'll be ok. type YES (in caps) to continue.
You'll be prompted for a passphrase. You'll want to use a STRONG, SECURE passphrase here. This is one of the weak point of LUKS. If I can brute force your passphrase, I'm in your stuff.
Once your passphrases match, you're part way there.

Next, we need to mount our new LUKS block device we just created.

Code:
sudo cryptsetup luksOpen /dev/sdb1 name-you-want-to-mount-it-as (you can name it whatever you want)
You'll be prompted for the passphrase, type it in.
done, you'll now see the device mounted in /dev/mapper/name-you-gave-it

We need to put a file system within the encrypted partition so we can store files in it. That's as easy as

Code:
sudo mkfs -t ext4 /dev/mapper/name-you-gave-it
Whew, finally we're almost done. Final step is to mount the newly created partition.

Code:
mkdir /mountpoint (whatever you want to call it, wherever you're going to mount it) sudo mount /dev/mapper/name-you-gave-it /mountpoint

This will mount the device, you can check it for sure by typing the mount command and look for it in the list.

When you're done, unmount your device (umount /mountpoint), then close the LUKS partition with
Code:
cryptsetup luksClose name-you-gave-it


That's it, all done! Easy right?

let me know if you liked this and if it was helpful. This tutorial is kind of quick and dirty but all the info is there to create encrypted partitions on your Linux system!
---
Click here to get started with Linux!

If I helped you, please +rep me, apparently we've started over on Rep and I'd like to break 100 again...

Inori Wrote: got clickbaited by roger

Reply