# Linux Encryption methods

**URL:** <https://community.unix.com/t/linux-encryption-methods/330134>\
**Category:** Cybersecurity\
**Created:** [June 5, 2013, 11:26pm UTC](https://community.unix.com/t/linux-encryption-methods/330134 "2013-06-05T23:26:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![landossa](https://community.unix.com/letter_avatar/landossa/32/5_5575768a8748004e209b776fc1b2916d.png) [@landossa](https://community.unix.com/u/landossa)\
**Post date:** [June 5, 2013, 11:26pm UTC](https://community.unix.com/t/linux-encryption-methods/330134/1 "2013-06-05T23:26:23Z")

</div>

Hi all,

I am looking to encrypt a filesystem with a CentOS 6.4 install.  
However I note that when using LUKS the system does not boot without prompting for the password encryption key.

I am looking for an drive/filesystem encryption solution which will allow reboots and shutdown/starts of the system so the system continues to function without prompting for a password.

Is there any disk encryption system which allows for this?

thanks,  
Ll

---

<div class="post-metadata">

**Author:** ![Corona688](https://community.unix.com/letter_avatar/corona688/32/5_5575768a8748004e209b776fc1b2916d.png) [@Corona688](https://community.unix.com/u/Corona688)\
**Post date:** [June 6, 2013, 12:25pm UTC](https://community.unix.com/t/linux-encryption-methods/330134/2 "2013-06-06T12:25:31Z")

</div>

Think about that. If the hard drive knows the secret needed to decrypt itself, so would anyone stealing that hard drive. It's like installing a steel security door then welding it open. What possible use would it be?

There has to be some sort of secret which a hacker can't get. If the computer can't get it from a human in person, it has to get it somewhere else, somewhere secure.

I've heard of schemes like keeping a security key on a USB thumb drive, so it will only boot with the USB drive plugged in. Of course, that's no use if someone steals the USB key too.

---

<div class="post-metadata">

**Author:** ![verdepollo](https://community.unix.com/user_avatar/community.unix.com/verdepollo/32/1854_2.png) [@verdepollo](https://community.unix.com/u/verdepollo)\
**Post date:** [June 6, 2013, 1:31pm UTC](https://community.unix.com/t/linux-encryption-methods/330134/3 "2013-06-06T13:31:01Z")

</div>

Plus, it's never secure enough:

![](https://community.unix.com/uploads/default/original/2X/b/be3d6112bd741dd1bbd6fb2f891e8a6cbb3e7276.png)

---

<div class="post-metadata">

**Author:** ![landossa](https://community.unix.com/letter_avatar/landossa/32/5_5575768a8748004e209b776fc1b2916d.png) [@landossa](https://community.unix.com/u/landossa)\
**Post date:** [June 6, 2013, 11:49pm UTC](https://community.unix.com/t/linux-encryption-methods/330134/4 "2013-06-06T23:49:53Z")

</div>

Yes in theory I agree with you both. 🙂

Lets just say that I am trying to meet compliance so that I can say the drive is encrypted, and get a check in the box.

So if there is a tool which can achieve the type of 'compliance' I am looking for, I would be interested in hearing about it.

---

<div class="post-metadata">

**Author:** ![Corona688](https://community.unix.com/letter_avatar/corona688/32/5_5575768a8748004e209b776fc1b2916d.png) [@Corona688](https://community.unix.com/u/Corona688)\
**Post date:** [June 7, 2013, 12:37pm UTC](https://community.unix.com/t/linux-encryption-methods/330134/5 "2013-06-07T12:37:50Z")

</div>

If the encryption doesn't protect him, or he learns better after you sell it to him, he will be very upset. So I'd try the [key on drive](https://wiki.archlinux.org/index.php/Dm-crypt_with_LUKS) method then, to avoid misleading them.

As far as I can tell the USB drive would become the magic key that lets it boot. Without it, they need a password.
