Secure laptop with SuSE 9.1?

From: Christian Lederer (christianlederer_at_web.de)
Date: 06/29/04


Date: Tue, 29 Jun 2004 05:57:28 +0200


Hi,

in order to have a secure notebook i want to to encrypt /home, /tmp,
/var and the swap, and i am looking most convenient and secure way
to achieve this.

If i create encrypted partitions for /home, /tmp and /var using Yast2,
i will have to type the password(s) three times at each boot.
Supposing i use the same password for these partitions, is there
an easy way to mount these partitions typing the password only once?
Is it perhaps possible, to attach these partitions to the same loop
device?

I found out, that a can use encrypted swap by adding the options
loop=/dev/loop?,encryption=twofish256 in my /etc/fstab.
In this case, at each boot will recreate an encrypted swap using
a password which is derived from /dev/urandom.
But does /dev/urandom contain enough randomness at boot time in order
to create a secure password?

Or is there a possibility to encrypt the root partition, if one has a
separate boot partition and includes the encryption module in the
initrd?

Any hints would highly be appreciated!

Thanks
Christian



Relevant Pages

  • Secure Boot Manager
    ... Our company needs to securely seperate two partitions on several laptops. ... This involves keeping two secure networks seperated. ... encrypt the partitions - we will buy a commercial software so that the OS ...
    (Security-Basics)
  • RE: local admin account password
    ... > encrypt the database and create alerts in the event of unsuccessful ... >> no more recovery console and don't think cached logins will work. ... >> The DB file would be encrypted with EFS so only the limited user SQL ... >> itself doesn't really need to be secure as the authentication is based ...
    (Focus-Microsoft)
  • RE: local admin account password
    ... > Subject: local admin account password ... > secure it. ... > and then encrypt the file (PGP or something like it with the private ...
    (Focus-Microsoft)
  • Re: How to convert a SecureString into an encrypted String in a se
    ... secure string and into a byte array looked a little weird to me, ... You can then either convert that to a .NET string (not a good idea if the ... Note that you can encrypt your SQL network traffic on the wire if you are ... planning to encrypt the passwords using the symmetric Rijndael algorithm, ...
    (microsoft.public.dotnet.security)
  • Re: [Full-disclosure] Encrypted files and the 5th amendment
    ... Don't forget that for "hidden" partitions (essentially virtual ... there are truly random bits to first encrypt, ... discussions about economics (without realizing they are discussing ... The path to the loss of freedom is ...
    (Full-Disclosure)