From: Florian Philipp <lists@binarywings.net>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] crypt my home repository
Date: Mon, 02 Jan 2012 11:49:11 +0100 [thread overview]
Message-ID: <4F018BA7.1000207@binarywings.net> (raw)
In-Reply-To: <201201020907.55698.stephane@22decembre.eu>
[-- Attachment #1: Type: text/plain, Size: 1721 bytes --]
Am 02.01.2012 09:07, schrieb Stéphane Guedon:
> Hi all
>
> I may ask something already discussed, but I can't find any good documentation.
> I am wondering of how to secure my home repository on my laptop. I am thinking
> of cryptography and other things (the password uncrypt the repository and
> allows to read files...).
>
> What tool to use for ? Anybody knows a good doc (in french would be really
> good) ?
>
> I am not really paranoïd, but I work now in a quite important environnement
> and want any data I get out to be secured...
I recommend dm-crypt (a.k.a. cryptsetup-luks). It encrypts the block
device under the actual file system. Gentoo wiki has some tutorials on
it (although you don't need much of it): [1] [2]
If you only want to encrypt your home partition, you only need to follow
these steps:
1. Create an encrypted partition (see `man cryptsetup`)
2. Move /home/* over to it (don't forget backup)
3. Configure /etc/conf.d/dmcrypt
4. Add /etc/init.d/dmcrypt to boot runlevel
Then the init script will ask you for the password at boot. dm-crypt
allows multiple passwords per partition so that different users can have
different passwords.
The alternative to the dmcrypt init script is to use sys-auth/pam_mount.
It allows you to use the login password to automatically decrypt a
partition and mount it as /home/$user. [2] has a section about it.
However, this breaks easily and is pretty hard to administrate if you
have no experience with dm-crypt and pam. I recommend the first solution.
[1]
http://en.gentoo-wiki.com/wiki/SECURITY_System_Encryption_DM-Crypt_with_LUKS
[2] http://en.gentoo-wiki.com/wiki/DM-Crypt
Regards,
Florian Philipp
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 262 bytes --]
next prev parent reply other threads:[~2012-01-02 10:50 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-01-02 8:07 [gentoo-user] crypt my home repository Stéphane Guedon
2012-01-02 9:23 ` Kfir Lavi
2012-01-02 10:49 ` Florian Philipp [this message]
2012-01-02 11:01 ` Florian Philipp
2012-01-02 11:36 ` Stéphane Guedon
2012-01-02 12:37 ` Florian Philipp
2012-01-02 12:58 ` Neil Bothwick
2012-01-02 13:12 ` Stéphane Guedon
2012-01-02 13:29 ` Neil Bothwick
2012-01-02 14:26 ` Florian Philipp
2012-01-02 17:06 ` Neil Bothwick
2012-01-02 18:16 ` Kfir Lavi
2012-01-02 16:17 ` Stéphane Guedon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4F018BA7.1000207@binarywings.net \
--to=lists@binarywings.net \
--cc=gentoo-user@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox