autounlock luks encrypted drives upon startup with keyfile

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP








up vote
0
down vote

favorite












i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.







share|improve this question
























    up vote
    0
    down vote

    favorite












    i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



    how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



    i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.







    share|improve this question






















      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



      how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



      i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.







      share|improve this question












      i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



      how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



      i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.









      share|improve this question











      share|improve this question




      share|improve this question










      asked May 15 at 17:35









      bigblackcard

      61




      61




















          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          This is done in /etc/crypttab, something very similar to /etc/fstab



          Just have a look at the man page.



          So a line like that would do it.



          myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


          where the UUID is the uuid of your LUKS volume, that you can find with blkid.



          The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



          Don't forget to add a line in /etc/fstab



          /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





          share|improve this answer




















            Your Answer







            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "89"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            convertImagesToLinks: true,
            noModals: false,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );








             

            draft saved


            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1036630%2fautounlock-luks-encrypted-drives-upon-startup-with-keyfile%23new-answer', 'question_page');

            );

            Post as a guest






























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes








            up vote
            0
            down vote













            This is done in /etc/crypttab, something very similar to /etc/fstab



            Just have a look at the man page.



            So a line like that would do it.



            myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


            where the UUID is the uuid of your LUKS volume, that you can find with blkid.



            The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



            Don't forget to add a line in /etc/fstab



            /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





            share|improve this answer
























              up vote
              0
              down vote













              This is done in /etc/crypttab, something very similar to /etc/fstab



              Just have a look at the man page.



              So a line like that would do it.



              myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


              where the UUID is the uuid of your LUKS volume, that you can find with blkid.



              The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



              Don't forget to add a line in /etc/fstab



              /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





              share|improve this answer






















                up vote
                0
                down vote










                up vote
                0
                down vote









                This is done in /etc/crypttab, something very similar to /etc/fstab



                Just have a look at the man page.



                So a line like that would do it.



                myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


                where the UUID is the uuid of your LUKS volume, that you can find with blkid.



                The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



                Don't forget to add a line in /etc/fstab



                /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





                share|improve this answer












                This is done in /etc/crypttab, something very similar to /etc/fstab



                Just have a look at the man page.



                So a line like that would do it.



                myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


                where the UUID is the uuid of your LUKS volume, that you can find with blkid.



                The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



                Don't forget to add a line in /etc/fstab



                /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2






                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered May 15 at 19:57









                solsTiCe

                4,87721642




                4,87721642






















                     

                    draft saved


                    draft discarded


























                     


                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1036630%2fautounlock-luks-encrypted-drives-upon-startup-with-keyfile%23new-answer', 'question_page');

                    );

                    Post as a guest













































































                    Popular posts from this blog

                    Which professions warranted travel in Medieval times?

                    How do so many people here on Academia.SE, and in general, afford lavish higher education programs?

                    Trouble downloading packages list due to a “Hash sum mismatch” error