Click here to Skip to main content
15,892,298 members
Home / Discussions / System Admin
   

System Admin

 
GeneralRe: System level memory fragmentation tool Pin
RichardM120-Jan-12 15:20
RichardM120-Jan-12 15:20 
QuestionSet credential forwarder Pin
Kanel Roath17-Jan-12 14:35
Kanel Roath17-Jan-12 14:35 
AnswerRe: Set credential forwarder Pin
SCraw285524-Jan-12 13:52
SCraw285524-Jan-12 13:52 
QuestionFull Disk Encryption for Ubuntu Linux: How? Pin
Kevin Li (Li, Ken-un)12-Jan-12 6:48
Kevin Li (Li, Ken-un)12-Jan-12 6:48 
AnswerRe: Full Disk Encryption for Ubuntu Linux: How? Pin
loctrice12-Jan-12 17:03
professionalloctrice12-Jan-12 17:03 
GeneralRe: Full Disk Encryption for Ubuntu Linux: How? Pin
Kevin Li (Li, Ken-un)17-Jan-12 16:18
Kevin Li (Li, Ken-un)17-Jan-12 16:18 
GeneralRe: Full Disk Encryption for Ubuntu Linux: How? Pin
RichardM120-Jan-12 18:40
RichardM120-Jan-12 18:40 
AnswerRe: Full Disk Encryption for Ubuntu Linux: How? Pin
ruready51126-Jan-12 18:57
ruready51126-Jan-12 18:57 
Lee, Gun-Woon,

Just to pitch in my two cents... You may not be able to achieve what you want with a solution other than TrueCrypt. The only reason I say that is because you made it very clear that you want...
Lee, Gun-Woon wrote:
"...every (or almost every) bit persisted in storage is encrypted and unreadable to unauthorized users."
However, you very likely already know that there are elements on the disk that cannot be encrypted (ie: boot partition). There is one additional element that cannot be encrypted using any FDE software that boots from the same disk (or any that I am aware of) - the partition definitions (ie: start and stop LBAs).

The reason TrueCrypt is excellent in a situation like this is because it can create an altogether hidden operating system[^]. Their methods are rather tactful and if your situation requires security that can thwart others' attempts at getting to your data *even after you give them the pre-boot authentication password*, than this is what you want.

Now, about your BitLocker setup. The reason BitLocker isn't requesting a password for it's pre-boot authentication is because your motherboard has something called a Trusted Platform Module (TPM) installed on it. You probably already know that since you likely had to activate the thing before the encryption process could start. Anyway, the TPM holds the en/decryption keys to your encrypted partition. When the system boots, the system partition (Windows' 100MB boot partition) authenticates with the TPM, exchanges keys, and boots the encrypted partition by decrypting it on-the-fly. When the TPM is locked or the disk configuration changed, or the disk is booted on a different system, or any number of things - this will cause Windows to start the BitLocker bootloader in a recovery mode. You will be prompted for a password if and when this occurs.

I'm also new to Linux myself (I've been aspiring to the genius required to understand Unix's simplicity[<ahref="http: en.wikipedia.org="" wiki="" unix_philosophy"="" target="_blank" title="New Window">^] for some time now...). Anyway, I think you'll be hard pressed to find an Open Source Software (OSS) implementation of a FDE package that supports hardware en/decryption components. The only one I've seen that can use a TPM is TpmCrypt[^] (which, ironically, seems to have an invalid certificate for their website!).

Moving along to your specific desired setup - the partitioning scheme you have illustrated is possible with TrueCrypt. Now, there is the normal way of doing things - then there is tuning the system for every last drop of performance possible. Here's a quick exit - if you'll be installing the entire system to the SSD, don't bother with tuning the partitions. It won't gain you anything.

If you'll be using any portion of the ATA/SATA disks, then you'd do well to put the swap partition on the SSD. This is important with any non-hardware en/decryption solution because all of the data must be en/decrypted either in RAM or in swap space (even if the encryption software pushes all of the normal memory functions to swap and reserves the physical RAM for itself, you'll still want to make sure that your swap disk is fast enough to keep up). Anyway, I'll let you figure out the rest of the partitioning.

Let me know what you end up doing, I'm interested to find out what route you take!! I just recently made the switch to Linux on my personal computer and am currently trying to get my way through some of the rough spots associated with the switch. Three main areas that are giving me nightmares are GRUB, RAID, and FDE.
GeneralRe: Full Disk Encryption for Ubuntu Linux: How? Pin
Kevin Li (Li, Ken-un)27-Jan-12 10:52
Kevin Li (Li, Ken-un)27-Jan-12 10:52 
GeneralHow do I remove Personalistion Pin
Bram van Kampen5-Jan-12 16:31
Bram van Kampen5-Jan-12 16:31 
GeneralRe: How do I remove Personalistion Pin
Richard Andrew x645-Jan-12 16:52
professionalRichard Andrew x645-Jan-12 16:52 
GeneralRe: How do I remove Personalistion Pin
Luc Pattyn5-Jan-12 17:11
sitebuilderLuc Pattyn5-Jan-12 17:11 
GeneralRe: How do I remove Personalistion Pin
smcnulty20005-Jan-12 17:22
smcnulty20005-Jan-12 17:22 
GeneralRe: How do I remove Personalistion Pin
Bram van Kampen6-Jan-12 15:47
Bram van Kampen6-Jan-12 15:47 
GeneralRe: How do I remove Personalistion Pin
SCraw28558-Jan-12 3:46
SCraw28558-Jan-12 3:46 
QuestionXP Dowloading file defaults to Text Pin
AnnieMacD15-Dec-11 11:48
AnnieMacD15-Dec-11 11:48 
AnswerRe: XP Dowloading file defaults to Text Pin
Peter_in_278015-Dec-11 12:51
professionalPeter_in_278015-Dec-11 12:51 
GeneralRe: XP Dowloading file defaults to Text Pin
AnnieMacD16-Dec-11 3:41
AnnieMacD16-Dec-11 3:41 
GeneralRe: XP Dowloading file defaults to Text Pin
User 171649216-Dec-11 4:12
professionalUser 171649216-Dec-11 4:12 
AnswerRe: XP Dowloading file defaults to Text Pin
Randor 16-Dec-11 9:23
professional Randor 16-Dec-11 9:23 
GeneralRe: XP Dowloading file defaults to Text Pin
AnnieMacD16-Dec-11 11:38
AnnieMacD16-Dec-11 11:38 
GeneralRe: XP Dowloading file defaults to Text Pin
Randor 17-Dec-11 3:32
professional Randor 17-Dec-11 3:32 
GeneralRe: XP Dowloading file defaults to Text Pin
AnnieMacD17-Dec-11 5:36
AnnieMacD17-Dec-11 5:36 
GeneralRe: XP Dowloading file defaults to Text Pin
Randor 17-Dec-11 9:27
professional Randor 17-Dec-11 9:27 
GeneralRe: XP Dowloading file defaults to Text Pin
AnnieMacD17-Dec-11 10:53
AnnieMacD17-Dec-11 10:53 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.