How do I protect my scripts/programs when server offsite?

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP








up vote
0
down vote

favorite












I want to protect a server that resides at a clients site (they have physical access). I don't want anyone accessing the files/programs/scripts etc. Currently I have a strong password on the user account but that doesn't protect it if someone boots a live cd. So I chose to encrypt the entire disk (LVM) as well. The problem is when the computer restarts (power outage) the programs don't automatically start as the o/s is waiting for the password.



Is there a way to autoboot a encrypted lvm headless machine or am I going about this the wrong way?



I thought maybe a small partition or thumbdrive with an encrypted password file saved but not sure how luks would unencrypt the file to get the password to inject back into the o/s so it could boot.
I did see some ppl post about using Mandos & tang but those seem to require another server. This solution wont work.



How do I protect those scripts and programs from a livecd boot?



Thanks







share|improve this question
















  • 1




    One of the major basic tenets of information security is that physical access trumps everything. While you might be able to get it secure enough, it won't be easy.
    – BillThePlatypus
    Apr 26 at 18:10














up vote
0
down vote

favorite












I want to protect a server that resides at a clients site (they have physical access). I don't want anyone accessing the files/programs/scripts etc. Currently I have a strong password on the user account but that doesn't protect it if someone boots a live cd. So I chose to encrypt the entire disk (LVM) as well. The problem is when the computer restarts (power outage) the programs don't automatically start as the o/s is waiting for the password.



Is there a way to autoboot a encrypted lvm headless machine or am I going about this the wrong way?



I thought maybe a small partition or thumbdrive with an encrypted password file saved but not sure how luks would unencrypt the file to get the password to inject back into the o/s so it could boot.
I did see some ppl post about using Mandos & tang but those seem to require another server. This solution wont work.



How do I protect those scripts and programs from a livecd boot?



Thanks







share|improve this question
















  • 1




    One of the major basic tenets of information security is that physical access trumps everything. While you might be able to get it secure enough, it won't be easy.
    – BillThePlatypus
    Apr 26 at 18:10












up vote
0
down vote

favorite









up vote
0
down vote

favorite











I want to protect a server that resides at a clients site (they have physical access). I don't want anyone accessing the files/programs/scripts etc. Currently I have a strong password on the user account but that doesn't protect it if someone boots a live cd. So I chose to encrypt the entire disk (LVM) as well. The problem is when the computer restarts (power outage) the programs don't automatically start as the o/s is waiting for the password.



Is there a way to autoboot a encrypted lvm headless machine or am I going about this the wrong way?



I thought maybe a small partition or thumbdrive with an encrypted password file saved but not sure how luks would unencrypt the file to get the password to inject back into the o/s so it could boot.
I did see some ppl post about using Mandos & tang but those seem to require another server. This solution wont work.



How do I protect those scripts and programs from a livecd boot?



Thanks







share|improve this question












I want to protect a server that resides at a clients site (they have physical access). I don't want anyone accessing the files/programs/scripts etc. Currently I have a strong password on the user account but that doesn't protect it if someone boots a live cd. So I chose to encrypt the entire disk (LVM) as well. The problem is when the computer restarts (power outage) the programs don't automatically start as the o/s is waiting for the password.



Is there a way to autoboot a encrypted lvm headless machine or am I going about this the wrong way?



I thought maybe a small partition or thumbdrive with an encrypted password file saved but not sure how luks would unencrypt the file to get the password to inject back into the o/s so it could boot.
I did see some ppl post about using Mandos & tang but those seem to require another server. This solution wont work.



How do I protect those scripts and programs from a livecd boot?



Thanks









share|improve this question











share|improve this question




share|improve this question










asked Apr 26 at 17:50









Chip

11




11







  • 1




    One of the major basic tenets of information security is that physical access trumps everything. While you might be able to get it secure enough, it won't be easy.
    – BillThePlatypus
    Apr 26 at 18:10












  • 1




    One of the major basic tenets of information security is that physical access trumps everything. While you might be able to get it secure enough, it won't be easy.
    – BillThePlatypus
    Apr 26 at 18:10







1




1




One of the major basic tenets of information security is that physical access trumps everything. While you might be able to get it secure enough, it won't be easy.
– BillThePlatypus
Apr 26 at 18:10




One of the major basic tenets of information security is that physical access trumps everything. While you might be able to get it secure enough, it won't be easy.
– BillThePlatypus
Apr 26 at 18:10















active

oldest

votes











Your Answer







StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "89"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: true,
noModals: false,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1028492%2fhow-do-i-protect-my-scripts-programs-when-server-offsite%23new-answer', 'question_page');

);

Post as a guest



































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes















 

draft saved


draft discarded















































 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1028492%2fhow-do-i-protect-my-scripts-programs-when-server-offsite%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

pylint3 and pip3 broken

Missing snmpget and snmpwalk

How to enroll fingerprints to Ubuntu 17.10 with VFS491