autounlock luks encrypted drives upon startup with keyfile

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP








up vote
0
down vote

favorite












i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.







share|improve this question
























    up vote
    0
    down vote

    favorite












    i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



    how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



    i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.







    share|improve this question






















      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



      how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



      i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.







      share|improve this question












      i have a raidz2 zpool across 6 disks. i am using ubuntu server 16.04 LTS and i want to encrypt those disks with luks and have the system decrypt them on startup, so that zfs can use them.



      how exactly do i configure luks so that upon startup it automatically decrypts those drives using a keyfile (generated with dd if=/dev/urandom...) stored on the root of the boot drive.



      i'd also like for each drive to have a different key file. preferribly sha-512 or, heck, even something higher would be nice.









      share|improve this question











      share|improve this question




      share|improve this question










      asked May 15 at 17:35









      bigblackcard

      61




      61




















          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          This is done in /etc/crypttab, something very similar to /etc/fstab



          Just have a look at the man page.



          So a line like that would do it.



          myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


          where the UUID is the uuid of your LUKS volume, that you can find with blkid.



          The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



          Don't forget to add a line in /etc/fstab



          /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





          share|improve this answer




















            Your Answer







            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "89"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            convertImagesToLinks: true,
            noModals: false,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );








             

            draft saved


            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1036630%2fautounlock-luks-encrypted-drives-upon-startup-with-keyfile%23new-answer', 'question_page');

            );

            Post as a guest






























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes








            up vote
            0
            down vote













            This is done in /etc/crypttab, something very similar to /etc/fstab



            Just have a look at the man page.



            So a line like that would do it.



            myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


            where the UUID is the uuid of your LUKS volume, that you can find with blkid.



            The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



            Don't forget to add a line in /etc/fstab



            /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





            share|improve this answer
























              up vote
              0
              down vote













              This is done in /etc/crypttab, something very similar to /etc/fstab



              Just have a look at the man page.



              So a line like that would do it.



              myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


              where the UUID is the uuid of your LUKS volume, that you can find with blkid.



              The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



              Don't forget to add a line in /etc/fstab



              /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





              share|improve this answer






















                up vote
                0
                down vote










                up vote
                0
                down vote









                This is done in /etc/crypttab, something very similar to /etc/fstab



                Just have a look at the man page.



                So a line like that would do it.



                myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


                where the UUID is the uuid of your LUKS volume, that you can find with blkid.



                The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



                Don't forget to add a line in /etc/fstab



                /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2





                share|improve this answer












                This is done in /etc/crypttab, something very similar to /etc/fstab



                Just have a look at the man page.



                So a line like that would do it.



                myzfs UUId=e758456d-eb80-4eea-947c-9ac914643b61 /root/mykeyfile luks


                where the UUID is the uuid of your LUKS volume, that you can find with blkid.



                The unencrypted LUKS volume is available at /dev/mapper/myzfs. The name you gave to it above, in crypttab



                Don't forget to add a line in /etc/fstab



                /dev/mapper/myzfs /where/to/mount/it fstype defaults 0 2






                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered May 15 at 19:57









                solsTiCe

                4,87721642




                4,87721642






















                     

                    draft saved


                    draft discarded


























                     


                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1036630%2fautounlock-luks-encrypted-drives-upon-startup-with-keyfile%23new-answer', 'question_page');

                    );

                    Post as a guest













































































                    Popular posts from this blog

                    pylint3 and pip3 broken

                    Missing snmpget and snmpwalk

                    How to enroll fingerprints to Ubuntu 17.10 with VFS491