create_crypted_logical_volume (manual, for Ubuntu Desktop) ============================= 1. from Ubuntu alternate CD ( in virtual box, 10 GB)) =========================== start text installer ! manual partioning 1. boot-part ( 200 MB ), sda1 2. crypt-part ( rest 10,7 GB ) lukslvm, sda2 3. logical volume group vgubuntu 4. lvm-volumes root 8000 MB swap 1300 MB home 1200 MB 5. mount boot-partition sda1 to /boot ! 6. format all logical volumes 7. install system 2. from Ubuntu CD Life System ============================= (http://wiki.ubuntuusers.de/system_verschl%C3%BCsseln) - start life CD (do not click "install ubuntu") - needed packages: first: ! change source of packages in synaptic package manager ! ! update packages ! lvm2 cryptsetup (ab Karmic bereits vorhanden) ( to install mc: run: dpkg --configure -a ) - all commands need root - load module (only needed before version kermic) modprobe dm-crypt - 2 partitions needed: /dev/sdX1 (ext3) Boot-Partition (not crypted) Size: min. 120 MB (usually no more RAM needed, perhaps some old kernel-packages have to be uninstalled)) /dev/sdX2 (unformatiert) crypted LVM-Volume Size: usually the available rest, min. 8 GB (root + RAM) - creating crypted partition Caution: for security reasons it is recommended to overwrite the partition with random numbers, if it was used before unencrypted. Then there will be created a LUKS-volume and then opened by lvm. Using XTS and 256 AES the commands would be: cryptsetup -c aes-xts-plain -s 512 luksFormat /dev/sdX2 ( default: cryptsetup luksFormat /dev/sdX2) cryptsetup luksOpen /dev/sdX2 lukslvm # control: cryptsetup -v status lukslvm # cryptsetup -v remove lukslvm - creating LVM partition creating LVM volume in crypted partition: pvcreate /dev/mapper/lukslvm # create physical volume, name: lukslvm # pvs -v -a # pvremove -v /dev/mapper/lukslvm vgcreate vgubuntu /dev/mapper/lukslvm # create logical volume group, name: vgbuntu # vgs -v -a # vgremove -v vgubuntu The standard installation needs 2 partitions: swap-partition: (1.3 * RAM-size, e.g. 1024 MB RAM and 1300 MB swap-size root-partition: the rest of the available space created as logical volumes: [/sbin/]lvcreate -L 1300M -n swap vgubuntu # create logical volume, name: swap [/sbin/]lvcreate -l 100%FREE -n root vgubuntu # create logical volume, name: root # lvs -v -a # lvremove -v root If more partitions are needed, do it the same way. In this case there must be left some space for these partitions, root cannot use the whole space. To avoid problems with the life-installer all partitions have to be formatted before installation. mkswap /dev/mapper/vgubuntu-swap mkfs.ext3 /dev/mapper/vgubuntu-root - Installation Now start installation till step 4, where you choose manual partitioning. /dev/sdX1 Boot-Partition Dateisystem: ext3 Formatieren: ja Einhängepunkt: /boot /dev/mapper/vgubuntu-root Root-Partition Dateisystem: ext3 oder gewünschtes Linux-Dateisystem Formatieren: ja Einhängepunkt: / Accordingly continue installation. But after having finished installation do not restart system but continue by following steps: Caution: pssibly changes cannot be revoked ! The following commands have to be put all together in one single terminal ! To make the necessary adaptions we change by chroot to the actual crypted partion: mount /dev/mapper/vgubuntu-root /mnt mount /dev/sdX1 /mnt/boot mount -o rbind /dev /mnt/dev mount -t proc proc /mnt/proc mount -t sysfs sys /mnt/sys cp /etc/resolv.conf /mnt/etc/resolv.conf chroot /mnt /bin/bash Install needed packages apt-get install cryptsetup lvm2 Edit /etc/crypttab to correct the correct UUID of the crypted partition: What is the block id? blkid /dev/sdX2 then edit crypttab e.g. (if lukslvm was the name when crypted partion was opened by luksOpen) echo "lukslvm UUID= none luks" >> /etc/crypttab Edit /etc/modules echo "dm-crypt" >> /etc/modules Edit /etc/initramfs-tools/modules If not using Standard-Kernel (Generic) then initramfs has to be updated to serve all needed modules: echo "aes" >> /etc/initramfs-tools/modules echo "aes_i586" >> /etc/initramfs-tools/modules echo "aes_x86_64" >> /etc/initramfs-tools/modules echo "aes_generic" >> /etc/initramfs-tools/modules echo "dm-crypt" >> /etc/initramfs-tools/modules echo "dm-mod" >> /etc/initramfs-tools/modules echo "sha256" >> /etc/initramfs-tools/modules echo "sha256_generic" >> /etc/initramfs-tools/modules echo "lrw" >> /etc/initramfs-tools/modules echo "xts" >> /etc/initramfs-tools/modules echo "crypto_blkcipher" >> /etc/initramfs-tools/modules echo "gf128mul" >> /etc/initramfs-tools/modules Update Kernel-Initramfs update-initramfs -u -k all - Checking/updating grub configuration Wenn die root-Partition mit aktiviertem "data journaling" gemountet werden soll, muss bereits beim Kernelstart ein entsprechender Kernel-Parameter angegeben werden. Der Eintrag in der /etc/fstab reicht dann nicht mehr aus, weil diese Datei erst dann gelesen werden kann, wenn das root-Dateisystem bereits entschlüsselt und in das System eingehängt wurde. Unter /etc/default/grub editiert man die grub-Datei folgendermaßen: GRUB_CMDLINE_LINUX_DEFAULT="kopt=root=/dev/mapper/vgubuntu-root" - Finish / Restart To close chroot environment and to unmount boot- and root-partition cleanly, to finish LUKS and to restart the system do: exit sync umount /mnt/boot umount /mnt cryptsetup luksClose vgubuntu-root reboot - keys You can create multiple keys in parallel, there can coexist max. 8 keys. To avoid to lock you out of system firtst create a new password, test it, then remove the old one. - add key sudo cryptsetup luksAddKey /dev/sdX2 - remove key sudo cryptsetup luksDelKey /dev/sdX2 1