<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Encryption on CeMoCom</title><link>https://www.cemocom.de/tags/encryption/</link><description>Recent content in Encryption on CeMoCom</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 15 Apr 2020 08:50:25 +0000</lastBuildDate><atom:link href="https://www.cemocom.de/tags/encryption/feed.xml" rel="self" type="application/rss+xml"/><item><title>Open LUKS encrypted device via key on USB stick</title><link>https://www.cemocom.de/2020/04/15/open-luks-encrypted-device-via-key-on-usb-stick/</link><pubDate>Wed, 15 Apr 2020 08:50:25 +0000</pubDate><guid>https://www.cemocom.de/2020/04/15/open-luks-encrypted-device-via-key-on-usb-stick/</guid><description>&lt;h2 id="background"&gt;Background&lt;/h2&gt;
&lt;p&gt;If you want to encrypt the root file system of a computer running Linux with LUKS, you usually have to entere the encryption password at every system boot. Especially in the case of a headless computer acting as a server this is not suitable. To overcome this problem LUKS offers the possibility to store the encryption key as a keyfile and use it to open the encrypted disk.&lt;/p&gt;
&lt;p&gt;There also exist several guides how the keyfile can be stored on a USB stick. Examples include &lt;a href="https://blog.tinned-software.net/automount-a-luks-encrypted-volume-on-system-start/"&gt;here&lt;/a&gt;, &lt;a href="https://decatec.de/linux/verschluesselte-festplatte-luks-mit-usb-stick-bei-systemstart-entschluesseln/"&gt;here&lt;/a&gt; or &lt;a href="https://wiki.debianforum.de/Cryptsetup_mit_systemd_und_Schl%C3%BCssel_auf_externem_USB-Stick"&gt;here&lt;/a&gt; (the second and third guides are only available in German).&lt;/p&gt;</description></item></channel></rss>