djwong: (Default)
[personal profile] djwong
Hi all,

Here's how you install Ubuntu 14 with a LUKS-encrypted / and /boot partition when using regular UEFI (i.e. not Apple's insane firmware):


  1. Install Ubuntu. You'll want to create a 256M /boot (unencrypted), a LUKS container with LVM for /.

  2. Disable SecureBoot. Hopefully I will figure out how to fix this later.

  3. Boot the system to prove that it boots correctly.

  4. apt-get purge grub-efi-amd64-signed (the signed grub image does not have LUKS/cryptodisk support)

  5. Copy the contents of /boot somewhere, and note the device (say /dev/sda2 for this example).

  6. cryptsetup luksFormat /dev/sda2 -c aes-xts-plain64
    DO NOT install LVM here; grub2 refuses to allow FS writes to LVM volumes, which is needed for recordfail.

  7. Create an entry in /etc/crypttab for the new LUKS container. We'll assume you called the device-mapper node "boot_crypt".

  8. /etc/init.d/cryptdisks-early start (prove that crypttab works)

  9. mkfs.ext4 /dev/mapper/boot_crypt -L boot (or whatever filesystem you want here)

  10. Edit /etc/fstab to point /boot to /dev/mapper/boot_crypt.

  11. Copy the saved files from step 5 into the new /boot.

  12. echo 'GRUB_ENABLE_CRYPTODISK=y' >> /etc/default/grub

  13. grub-install -v (verify that grub-mkimage is called with luks/cryptodisk modules included)

  14. update-grub

  15. Reboot. Grub should now prompt to unlock the disk before showing the boot menu. For extra credit, set up LUKS keys for automount, since the only thing unencrypted on your HDD is grub, and (in theory) you could stash the rootfs LUKS keys in the initramfs. If I figure out how to make this work with SecureBoot I'll update this post.

Profile

djwong: (Default)
Bogus J. Simpson

May 2016

S M T W T F S
1234567
891011121314
15161718192021
2223242526 2728
293031    

Style Credit

Expand Cut Tags

No cut tags
Page generated 6 Oct 2026 00:54
Powered by Dreamwidth Studios