Chapter 29. Disk Encryption Guide
288
• LUKS is not well-suited for applications requiring many (more than eight) users to have distinct
access keys to the same device.
• LUKS is not well-suited for applications requiring file-level encryption.
For more information on LUKS, refer to
http://code.google.com/p/cryptsetup/
29.2.2. How will I access the encrypted devices after installation?
(System Startup)
During system startup you will be presented with a passphrase prompt. After the correct passphrase
has been provided the system will continue to boot normally. If you used different passphrases for
multiple encypted devices you may need to enter more than one passphrase during the startup.
Tip
Consider using the same passphrase for all encrypted block devices in a given system.
This will simplify system startup and you will have fewer passphrases to remember. Just
make sure you choose a good passphrase!
29.2.3. Choosing a Good Passphrase
While dm-crypt/LUKS supports both keys and passphrases, the anaconda installer only supports the
use of passphrases for creating and accessing encrypted block devices during installation.
LUKS does provide passphrase strengthening but it is still a good idea to choose a good (meaning
"difficult to guess") passphrase. Note the use of the term "passphrase", as opposed to the term
"password". This is intentional. Providing a phrase containing multiple words to increase the security of
your data is important.
29.3. Creating Encrypted Block Devices in Anaconda
You can create encrypted devices during system installation. This allows you to easily configure a
system with encrypted partitions.
To enable block device encryption, check the "Encrypt System" checkbox when selecting automatic
partitioning or the "Encrypt" checkbox when creating an individual partition, software RAID array, or
logical volume. After you finish partitioning, you will be prompted for an encryption passphrase. This
passphrase will be required to access the encrypted devices. If you have pre-existing LUKS devices
and provided correct passphrases for them earlier in the install process the passphrase entry dialog
will also contain a checkbox. Checking this checkbox indicates that you would like the new passphrase
to be added to an available slot in each of the pre-existing encrypted block devices.
Important — Global Passphrases Not Supported
Devices encrypted with LUKS can share a global passphrase. When a system contains
more than two encrypted block devices,
anaconda
offers you the option to set a global
passphrase for them. However, although
anaconda
can set this passphrase correctly, the
use of global passphrases is not supported by the init scripts in Red Hat Enterprise Linux
5.
Summary of Contents for ENTERPRISE LINUX 5 - VIRTUAL SERVER ADMINISTRATION
Page 12: ...xii ...
Page 20: ......
Page 30: ...12 ...
Page 32: ...14 ...
Page 82: ...64 ...
Page 106: ...88 ...
Page 122: ...104 ...
Page 124: ...106 ...
Page 126: ......
Page 132: ...114 ...
Page 168: ...150 ...
Page 182: ...164 ...
Page 192: ...174 ...
Page 194: ......
Page 236: ...218 ...
Page 238: ...220 ...
Page 270: ......
Page 274: ...256 ...
Page 278: ...260 ...
Page 292: ...274 ...
Page 294: ......
Page 300: ...282 ...
Page 304: ......
Page 316: ...298 ...
Page 370: ...352 ...
Page 384: ...366 ...
Page 385: ...Part VII Appendix ...
Page 386: ......