Luks encrypted USB startup key

It's a good idea to backup the headers anyway, the header of one of my disks became corrupt recently after a reboot and that made it impossible to open.

1 Like

@Scoopta Have you accomplished this yet?

@Scoopta I've been trying to get this to work on Fedora. If you're using systemd you have to add rd.luks.key to the kernel parameters in grub. I've never got it to work thou.

No. I have yet to make this work.

I'll reply back with some info on this for you guys

Cool!

A quick Question: @Scoopta @orbit Are you guys trying to encrypt the /boot partition of the USB as well?

In my case the /boot partition is on the system drive and isn't encrypted. The USB drive just has a file with random data I'd like to use as a key.

No. The /boot partition is unencrypted on my system drive. I just want to encrypt the ext4 partition on my USB drive that contains my key file for my systems root partition.

Kind of the same scenario here. I was thinking you guys wanted /boot on the USB with your drives encrypted on the PC, so the PC's can't boot without the USB.

I mean I guess that'd be fine too. My goal is to require both a USB drive and password to get into the system. How I accomplish that doesn't really matter to me. As long as it isn't a USB key file to decrypt and then a traditional login I'm good.

1 Like

I just wanted to clarify, thanks. Gimme a few and I'll post some info on it