ecryptfs - decrypt and mount at boot with USB key

Posted by Josh McGee on Ask Ubuntu See other posts from Ask Ubuntu or by Josh McGee
Published on 2014-08-24T20:12:34Z Indexed on 2014/08/24 22:32 UTC
Read the original article Hit count: 357

Filed under:
|
|
|

I have a system running Ubuntu Server as a testbed for some services that I want to get familiar with. I decided to let the installation procedure set up encryption. I knew all along that I would have to decrypt it with the passphrase in order to get the system booted, but I assumed it wouldn't matter since it will only boot once or twice a month.

However, my brother has informed me that he is a victim of power outages at the residence where this server is located. This means we have to explain to his girlfriend how to turn on the computer, attach a keyboard, connect a monitor (she just can't understand that she can type to the computer without a display, so whatever) and input the passphrase for us, while we are at work.

I have arrived at the conclusion that I should just put together a USB key that can be plugged in before powering on the computer, to avoid all the trouble.

Is this possible with ecryptfs? Is there a tutorial or simple list of instructions available so that I can knock this out and focus back on the stuff I care about?

EDIT: I am aware that this is possible with LUKS and dm-crypt, but unfortunately the magical encryption that Ubuntu hands you during the installation is only ecryptfs so my question is specific to that.

© Ask Ubuntu or respective owner

Related posts about boot

Related posts about server