LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-28-2018, 10:31 AM   #1
stile23
LQ Newbie
 
Registered: Jun 2018
Posts: 2

Rep: Reputation: Disabled
Question Disk Encryption with clevis and tang


So I've been tasked with enabling whole disk encryption at my site (which I've never done) but I really hate the idea of having to enter a password at every boot. I was reading about using "network found disk encryption" and how it works. There are actually some decent notes on in the RHEL Security Guide on setting up clevis and tang but I was wondering if anyone had a write up of configuring and using it? Any pointers would be appreciated.

I'm running RHEL 7.5 on Dell workstations.
 
Old 06-28-2018, 11:06 AM   #2
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,733

Rep: Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212
A thought: whole disk encryption without a pass phrase at boot seems kinda useless. It’s not that onerous...a once a day thing, right? Just sayin’.
 
Old 06-28-2018, 01:25 PM   #3
stile23
LQ Newbie
 
Registered: Jun 2018
Posts: 2

Original Poster
Rep: Reputation: Disabled
So with clevis and tang instead of a passphrase at boot it goes out to a server and checks out a key. At least that's the way I read it. And if it were only one or two computers it wouldn't be a big deal but when there are 150+ it becomes bothersome.

I suspect that there would still be a local key included on an encrypted partition for the case where the NIC died or your key server died but that would be secondary to the found network disk option.
 
Old 06-28-2018, 04:17 PM   #4
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,733

Rep: Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212
Shop I was in got to where everyone was issued a laptop with full-disk encryption. There were more than 20,000 laptops...each requiring pass-phrase at boot which only the person issued the laptop knew.

But I don't mean to hijack your thread. Hopefully someone will share there experiences with clevis and tang. You have searched the web, yes?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to have luks encryption with keyfile OR passphrase (efi full disk encryption including boot)? byroncollege Linux - Security 2 03-30-2017 07:45 AM
Mint 18 Full disk encryption VS Veracrypt Full Disk encryption: Help a Noob Decide Please ! APeacefulRig Linux - Security 2 11-11-2016 08:10 AM
Encryption of the whole disk vs. a partition filling the whole disk taylorkh Linux - Security 5 09-19-2016 11:03 AM
Hi all, I am Yonghui Tang linuxtyh LinuxQuestions.org Member Intro 1 12-01-2008 04:31 AM
disk encryption ankscorek Linux - Security 5 05-03-2006 12:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration