LeRoy on 15 Jul 2010 02:31:40 -0700 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 07/14/2010 08:27 PM, Art Clemons wrote: > The more this discussion goes on, the more I realize that there are > talks at the meetings to be made out of this discussion. For > example what are the downsides to encrypting an entire disk? What > happens if for example shutdown is improperly done and a partition > needs the service of FSCK or some similar technique? I know there > are answers out there, but obviously most of the folks on this list > don't readily know them. > > My last experiment with truecrypting an entire partition ended in > disaster, but fortunately I had all relevant data backed up so it > was just a reinstall. I couldn't escape the impression though that > if I had known more, the reinstall could have been avoided. Thus if > any of you like JP actually has the experience, the suggestion is > obvious. > On laptops I encrypt /home /tmp and swap. /var/tmp is a symlink to /tmp and If the laptop has mysql or postgresql loaded /var/lib/postgresql is a symlink to /home/postgresql. Of course if you use mysql change the symlink accordingly. This way you have access to the operating system and have fsck at your disposal. Of course with my setup booting the laptop requires me to enter 3 passphrases in order to mount the encrypted partitions. I do not know if it is possible to resize an encrypted partiton. Thus you need to know in advance how much space you need for the partitions. - -- Rev. LeRoy D. Cressy mailto:leroy@lrcressy.com /\_/\ http://lrcressy.com ( o.o ) Phone: 215-535-4037 > ^ < Cell: 267-307-3527 gpg fingerprint: 62DE 6CAB CEE1 B1B3 359A 81D8 3FEF E6DA 8501 AFEA For info on enigmail: http://lrcressy.com/linux/mozilla.pdf For info on gpg: http://www.gnupg.org/ Jesus saith unto him, I am the way, the truth, and the life: no man cometh unto the Father, but by me. (John 14:6) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQEcBAEBAgAGBQJMPtVsAAoJEKuxGqN1iGbbpswH/RBRF/5OQVZgOtAI9ucD7EJr QqPQjd9/xY+bXgtgBer6xWWdfN7XZkcNXZo22PvqZbWC+m9A7hu+CaktpkkdOwIn TyxtFiNoNuuOz8RrNxk18E6SeByonCKf0e+WQobPtuU4HA7DRy3hr2rWiHx9BofT I1C4LHLYE3EqTpm0XsJHWEKq81cgIwlLqibZjNH4vWcQxXjxVw2SyMmKzXVyTwVF W4HNn3Yp4zWpSx0hif8IwpSsNdE2BD80GgVh7mfAnu5N5uHOc/flMdukz3Bioeeq Ur7KhYDd9KDo/7a8V7P/cmwFO+ij4jyV9DC5P2QKcU7cW1Ay4eSbUFXPlmuKtZ8= =YsjR -----END PGP SIGNATURE----- ___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
|
|