USB RAM drive stick for dm-crypt/luks partitions (or other crypto setup)Storing key/password files on the common removable media like USB flash drives is not secure - device may be removed from the USB port and its contents will be disclosed. USB RAM drive stick is differ - it retains its contents only when plugged into USB port. This device is a compromise between the advantages of the use of the encrypted disks/partitions and secure auto-mounting them (dm-crypt or others) without interactively entering password/keyfile on each reboot/restart. Most PCs and servers provide stable power to the USB port even during poweroff state, so USB RAM drive stick retains its contents when PC is powered off (PC power supply is in standby mode). When power is completely off (hardware "off" switch on the power supply or mains was removed) USB RAM drive stick lost its contents and password file(s) must be rewritten.
WARNING
Device features:
|
USB RAM drive stick MINI HOWTO for Linux Debian (or compatible) with dm-cryptThe following instructions do not explain how prepare, format and mount dm-crypted partitions. They assume that you already have experience with working dm-crypt setup and you always enter the password(s) on each boot/restart for mounting encrypted partitions. To learn how use dm-crypt please refer to the dm-crypt documentation (man cryptsetup). USB RAM stick preparing & mounting instructions:
Now you can verify auto-mounting dm-crypt partitions during boot. Init script tcryptdisk try mount /tc if USB RAM drive stick is detected.
If /tc/key file exits (and contains proper password) encrypted
partition(s) will be auto mounted. If the key file is not available (USB stick was removed or PC mains was switched off) auto-mounting
script will ask on the console for the password and you have to re-create key file as described above. |
The USB RAM stick is avialable on eBay. For any questions or ordering informations please use the contact form in the page header. |