LUKS Encryption for RAID5/LVM2

chris lostpkts at gmail.com
Sun Oct 21 16:12:01 UTC 2007


I have a Gentoo server that is running with 8x400 drives in a Raid5
set. /dev/md0 is then 'carved' up using LVM2.

I noticed while playing with Gutsy in a vm that it has the encrypt
option at install for / and /swap. And since I've been thinking of
moving my server to Ubuntu this comes at a great time.

How can I go about using the encryption that is there after the
install of the base server to encrypt md0 or the lvm2 'partitions'?
Currently I have 10 lvm2 'partitions' on my server and would really
like to not have to enter the luks passwd in all 10 times.

My thoughts are to encrypt /dev/md0 and then after it is unencrypted
and running, carve it up via lvm2. That way if I want to resize, add
space, etc to the lvm2 logical volumes I can and not be affected by
each 'partition' being encrypted.

I found this http://ubuntuforums.org/showthread.php?t=578667&highlight=gutsy+luks
 and it looks like what I need to do to /dev/md0. But I'm not sure.

Can someone please point me in the right direction or offer comments/advice?

Thanks




More information about the ubuntu-users mailing list