
WARNING: Security Restrictions
Encrypting a user's home directory does not provide strong security from other
users. If strong security is required, the system should not be physically shared.
To enhance security, also encrypt the
swap
partition,
/tmp
, and
/var/tmp
,
because these can contain temporary images of critical data.
You can encrypt
swap
,
/tmp
, and
/var/tmp
with the YaST partitioner as described
in
Section 47.1.1, “Creating an Encrypted Partition during Installation”
(page 863) and
Section 47.1.3, “Creating an Encrypted File as a Container”
(page 864). In addition to
the options YaST offers, you can use the
cryptconfig
command line tool for some
special tasks.
For example, as a safety for users that may lose their key files, you can create and
add an additional key to the image.
1
Log in to a shell as
root
.
2
Run
cryptconfig create-key admin.key
to create a key for administrators.
3
To create an encrypted home directory for user
tux
and to add the administration
key to it, enter
cryptconfig make-ehd –extra-key-file=admin.key tux 200
This creates a home directory with the initial size of 200 MB.
4
To change the size of the home directory at any time, use
cryptconfig enlarge-size image size_to_add_in_MB
For more information about the command line tool, run
cryptconfig --help
to
view a list of options available.
866
Installation and Administration
Summary of Contents for LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007
Page 1: ...SUSE Linux Enterprise Server www novell com 10 May 11 2007 Installation and Administration...
Page 14: ......
Page 19: ...Part I Deployment...
Page 20: ......
Page 60: ......
Page 128: ......
Page 243: ...Part II Administration...
Page 244: ......
Page 274: ......
Page 312: ......
Page 348: ......
Page 380: ......
Page 381: ...Part III System...
Page 382: ......
Page 438: ......
Page 452: ......
Page 478: ......
Page 486: ......
Page 498: ......
Page 512: ......
Page 558: ......
Page 559: ...Part IV Services...
Page 560: ......
Page 652: ......
Page 670: ......
Page 742: ......
Page 754: ......
Page 796: ......
Page 817: ...Part V Security...
Page 818: ......
Page 858: ......
Page 886: ......
Page 910: ......
Page 911: ...Part VI Troubleshooting...
Page 912: ......
Page 924: ......