Skip to main content

Posts

Showing posts with the label cryptsetup

Achieving actually full disk encryption of UEFI ESP at rest with TCG OPAL, FIPS, LUKS

Achieving full disk encryption using FIPS, TCG OPAL and LUKS to encrypt UEFI ESP on bare-metal and in VMs Many security standards such as CIS and STIG require to protect information at rest. For example, NIST SP 800-53r5 SC-28 advocate to use cryptographic protection, offline storage and TPMs to enhance protection of information confidentiality and/or integrity. Traditionally to satisfy such controls on portable devices such as laptops one would utilize software based Full Disk Encryption - Mac OS X FileVault , Windows Bitlocker , Linux cryptsetup LUKS2 . In cases when FIPS cryptography is required, additional burden would be placed onto these systems to operate their kernels in FIPS mode. Trusted Computing Group  works on establishing many industry standards and specifications, which are widely adopted to improve safety and security of computing whilst keeping it easy to use. One of their most famous specifications them is TCG  TPM 2.0 (Trusted Platform Module). TPMs are now...

Encrypt all the things

xkcd #538: Security Went into blogger settings and enabled TLS on my custom domain blogger blog. So it is now finally a https://blog.surgut.co.uk  However, I do use feedburner and syndicate that to the planet. I am not sure if that is end-to-end TLS connections, thus I will look into removing feedburner between my blog and the ubuntu/debian planets. My experience with changing feeds in the planets is that I end up spamming everyone. I wonder, if I should make a new tag and add that one, and add both feeds to the planet config to avoid spamming old posts. Next up went into gandi LiveDNS platform and enabled DNSSEC on my domain. It propagated quite quickly, but I believe my domain is now correctly signed with DNSSEC stuff. Next up I guess, is to fix DNSSEC with captive portals. I guess what we really want to have on "wifi" like devices, is to first connect to wifi and not set it as default route. Perform captive portal check, potentially with a reduced DNS server capabil...

Now, less cryptic - Cryptsetup changes in Saucy

Previously, whenever cryptsetup package was installed, its modules and utilities were unconditionally copied into initramfs. Making it quite large. But there are legitimate use cases of installing cryptsetup, yet not needing it in the initramfs. One only needs cryptsetup in the initramfs if root filesystem or resume devices are encrypted. I have therefore modified cryptsetup initramfs hooks to only include cryptsetup in the initramfs when necessary. I have tested multiple combinations and here is a small summary: No cryptsetup in initramfs, when: no encrypted devices present non-rootfs filesystems are encrypted (e.g. /var/lib is encrypted) swap is encrypted with random key file (i.e. non-persistent encrypted swap) Cryptsetup is in initramfs, when: rootfs is encrypted ( '/' ) swap is encrypted with a passphrase / key-file (i.e. can unlock & resume from hibernate) CRYPTSETUP='y' option is specified in /etc/initramfs-tools/initramfs.conf The last...