What Kinds of Block Devices Can Be Encrypted?
289
Therefore, even if you set a global passphrase during installation, you must still supply
individual passphrases for each encrypted block device every time that the system boots.
Tip
Checking the "Encrypt System" checkbox on the "Automatic Partitioning" screen and
then choosing "Create custom layout" does not cause any block devices to be encrypted
automatically.
Tip
You can use
kickstart
to set a separate passphrase for each new encrypted block
device.
29.3.1. What Kinds of Block Devices Can Be Encrypted?
Most types of block devices can be encrypted using LUKS. From anaconda you can encrypt partitions,
LVM physical volumes, LVM logical volumes, and software RAID arrays.
29.4. Creating Encrypted Block Devices on the Installed
System After Installation
Encrypted block devices can be created and configured after installation.
29.4.1. Create the block devices
Create the block devices you want to encrypt by using
parted
,
pvcreate
,
lvcreate
and
mdadm
.
29.4.2. Optional: Fill the device with random data
Filling <device> (eg:
/dev/sda3
) with random data before encrypting it greatly increases the strength
of the encryption. The downside is that it can take a very long time.
Warning
The commands below will destroy any existing data on the device.
• The best way, which provides high quality random data but takes a long time (several minutes per
gigabyte on most systems):
dd if=/dev/urandom of=<device>
• Fastest way, which provides lower quality random data:
badblocks c 10240 s w t random v <device>
Summary of Contents for ENTERPRISE LINUX 5 - VIRTUAL SERVER ADMINISTRATION
Page 12: ...xii ...
Page 20: ......
Page 30: ...12 ...
Page 32: ...14 ...
Page 82: ...64 ...
Page 106: ...88 ...
Page 122: ...104 ...
Page 124: ...106 ...
Page 126: ......
Page 132: ...114 ...
Page 168: ...150 ...
Page 182: ...164 ...
Page 192: ...174 ...
Page 194: ......
Page 236: ...218 ...
Page 238: ...220 ...
Page 270: ......
Page 274: ...256 ...
Page 278: ...260 ...
Page 292: ...274 ...
Page 294: ......
Page 300: ...282 ...
Page 304: ......
Page 316: ...298 ...
Page 370: ...352 ...
Page 384: ...366 ...
Page 385: ...Part VII Appendix ...
Page 386: ......