public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Stéphane Guedon" <stephane@22decembre.eu>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] crypt my home repository
Date: Mon, 2 Jan 2012 12:36:55 +0100	[thread overview]
Message-ID: <201201021237.01284.stephane@22decembre.eu> (raw)
In-Reply-To: <4F018BA7.1000207@binarywings.net>

[-- Attachment #1: Type: Text/Plain, Size: 2457 bytes --]

On Monday 02 January 2012 11:49:11 Florian Philipp wrote:
> Am 02.01.2012 09:07, schrieb Stéphane Guedon:
> > Hi all
> > 
> > I may ask something already discussed, but I can't find any good
> > documentation. I am wondering of how to secure my home repository on my
> > laptop. I am thinking of cryptography and other things (the password
> > uncrypt the repository and allows to read files...).
> > 
> > What tool to use for ? Anybody knows a good doc (in french would be
> > really good) ?
> > 
> > I am not really paranoïd, but I work now in a quite important
> > environnement and want any data I get out to be secured...
> 
> I recommend dm-crypt (a.k.a. cryptsetup-luks). It encrypts the block
> device under the actual file system. Gentoo wiki has some tutorials on
> it (although you don't need much of it): [1] [2]
> 
> If you only want to encrypt your home partition, you only need to follow
> these steps:
> 
> 1. Create an encrypted partition (see `man cryptsetup`)
> 2. Move /home/* over to it (don't forget backup)
> 3. Configure /etc/conf.d/dmcrypt
> 4. Add /etc/init.d/dmcrypt to boot runlevel
> 
> Then the init script will ask you for the password at boot. dm-crypt
> allows multiple passwords per partition so that different users can have
> different passwords.
> 
> The alternative to the dmcrypt init script is to use sys-auth/pam_mount.
> It allows you to use the login password to automatically decrypt a
> partition and mount it as /home/$user. [2] has a section about it.
> However, this breaks easily and is pretty hard to administrate if you
> have no experience with dm-crypt and pam. I recommend the first solution.
> 
> [1]
> http://en.gentoo-wiki.com/wiki/SECURITY_System_Encryption_DM-Crypt_with_LUK
> S [2] http://en.gentoo-wiki.com/wiki/DM-Crypt
> 
> Regards,
> Florian Philipp

Is this solution (the first one) easily integrated into some environnement 
(kde) ?

I don't want to have numerous password (one for decrypt, one other to open the 
desktop session as usual...), plus my wife would argue with some reason I am 
always hacking the computer whereas we are just using it to look movies... 
(she uses the computer also, but in a much more used way, so any solution has 
to be comfortable to her too !)

-- 
Stéphane Guedon
http://www.22decembre.eu/
http://lectures.22decembre.eu/
carte de visite : http://www.22decembre.eu/downloads/Stephane-Guedon.vcf

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 490 bytes --]

  parent reply	other threads:[~2012-01-02 11:38 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-01-02  8:07 [gentoo-user] crypt my home repository Stéphane Guedon
2012-01-02  9:23 ` Kfir Lavi
2012-01-02 10:49 ` Florian Philipp
2012-01-02 11:01   ` Florian Philipp
2012-01-02 11:36   ` Stéphane Guedon [this message]
2012-01-02 12:37     ` Florian Philipp
2012-01-02 12:58       ` Neil Bothwick
2012-01-02 13:12         ` Stéphane Guedon
2012-01-02 13:29           ` Neil Bothwick
2012-01-02 14:26             ` Florian Philipp
2012-01-02 17:06               ` Neil Bothwick
2012-01-02 18:16                 ` Kfir Lavi
2012-01-02 16:17 ` Stéphane Guedon

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=201201021237.01284.stephane@22decembre.eu \
    --to=stephane@22decembre.eu \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox