Full Disk Encryption
#3
(11-06-2017, 04:28 AM)elatllat Wrote: I just use a second partition and mount bind over root where required. The advantage being the system can reboot remotely.

Thanks! I haven't tried that approach yet but it'd be nice to have all partitions encrypted to maintain integrity and availability.

Also, even though it's a bit of a nightmare to configure initially, initrd can be configured to load a dropbear SSH server on boot that'll drop a user to a busybox shell, allowing remote disk decryption. The advantage of this approach is that all the things are encrypted and the device can still be rebooted remotely. Like I said, it's a bit of a nightmare to configure. Maybe that'll be a future post once we figure this out.

Also, I'll admit that I have no experience with building custom Linux images and this seems like it'd be a situation where I should do just that and opt for Grub2 over U-Boot. I'm unsure of compatibility though.
  Reply


Messages In This Thread
Full Disk Encryption - by archangel - 11-05-2017, 05:59 PM
RE: Full Disk Encryption - by elatllat - 11-06-2017, 04:28 AM
RE: Full Disk Encryption - by archangel - 11-06-2017, 05:21 AM
RE: Full Disk Encryption - by gzom - 03-30-2019, 11:13 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Encryption support rockfun 1 3,252 06-10-2020, 08:27 AM
Last Post: rockfun
  Arch Linux minimal image w/ full HDMI output support hiccupstix 1 3,961 11-01-2018, 08:33 AM
Last Post: danboid
  Problems with USB 3.0 and SATA disk (UAS) diglam 6 12,913 10-16-2018, 11:05 AM
Last Post: Trash_Can_Man
  Official Debian image doesn't recognize full SD capacity silverknight 2 3,537 08-29-2017, 06:00 AM
Last Post: silverknight

Forum Jump:


Users browsing this thread: 4 Guest(s)