never ever ever ever allow force overwrite luks driver
This commit is contained in:
@@ -13,15 +13,17 @@ dnf install cryptsetup
|
|||||||
# Create an encryption key
|
# Create an encryption key
|
||||||
mkdir /etc/luks-keys
|
mkdir /etc/luks-keys
|
||||||
chmod 700 /etc/luks-keys
|
chmod 700 /etc/luks-keys
|
||||||
|
mkdir /etc/luks-backups
|
||||||
|
chmod 700 /etc/luks-backups
|
||||||
dd if=/dev/urandom bs=128 count=1 of=/etc/luks-keys/data0.key
|
dd if=/dev/urandom bs=128 count=1 of=/etc/luks-keys/data0.key
|
||||||
|
|
||||||
# Create an encrypted partition
|
# Create an encrypted partition
|
||||||
# -q means don't ask for confirmation
|
# -q means don't ask for confirmation
|
||||||
# -v means verbose
|
# -v means verbose
|
||||||
cryptsetup -q -v luksFormat /dev/nvme6n1p1 /etc/luks-keys/data0.key
|
cryptsetup -v luksFormat /dev/nvme6n1p1 /etc/luks-keys/data0.key
|
||||||
|
|
||||||
# Unlock
|
# Unlock
|
||||||
cryptsetup -q -v luksOpen --key-file /etc/luks-keys/data0.key /dev/nvme6n1p1 luks-$(cryptsetup luksUUID /dev/nvme6n1p1)
|
cryptsetup -v luksOpen --key-file /etc/luks-keys/data0.key /dev/nvme6n1p1 luks-$(cryptsetup luksUUID /dev/nvme6n1p1)
|
||||||
|
|
||||||
# List keys
|
# List keys
|
||||||
cryptsetup luksDump /dev/nvme6n1p1
|
cryptsetup luksDump /dev/nvme6n1p1
|
||||||
|
|||||||
Reference in New Issue
Block a user