Linux Disk Encryption
Links ecrypt , 2018-systemd-boot
- Options
- Ontop of mounted disk, e.g. homedrive or loop module
- Full disk, key entered at bootup
- Only partial.
- Single loopback file e.g. luks.
- Multi disk layered
disks -> lvm -> encryption -> fs
disks -> individual encrypted -> combined (lvm/btrfs)
- Ideal would be to have encryption built into BTRFS so we can easily span multiple disk.
- # cryptsetup -y -v luksFormat /dev/xvdc
...