Using Encrypted Home Directories - Novell LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007 Installation Manual

Table of Contents

Advertisement

47.1.4 Encrypting the Content of Removable
Media
YaST treats removable media like external hard disks or USB flash drives the same as
any other hard disk. Container files or partitions on such media can be encrypted as
described above. However, enable Do Not Mount During Booting in the Fstab Options
dialog, because removable media are usually only connected while the system is running.
If you have encrypted your removable device with LUKS (Linux Unified Key Set-
up)—which is the default for SUSE Linux Enterprise SP1— the KDE and GNOME
desktops automatically recognize this and prompt for the password when the device is
detected. If you have formatted your removable medium with a FAT file system, the
user logged in to the desktop that enters the password for decryption automatically be-
comes the owner of the device and can read and write files there. For devices with a
file system other than FAT, change the ownership explicitly for users other than root
to read or write files on the device.
47.2 Using Encrypted Home
Directories
To protect data in home directories against theft and hard disk removal, create encrypted
home directories for users. These are encrypted with LUKS, which results in an image
and an image key generated for the user. The image key is protected with the user's login
password. By default, the image and the image key are located in the respective user's
home directory. The key can also be located anywhere in the file system—for example,
on a removable device that can be mounted manually. To make use of this, specify a
persistent device name in the Fstab Options when setting up the device with the YaST
expert partitioner.
Use the YaST user management module or the cryptconfig command line tool to
enable encryption of home directories. You can create encrypted home directories for
new or existing users. To encrypt or modify encrypted home directories of already ex-
isting users, enter the user's current login password.
Encrypting Partitions and Files
865

Advertisement

Table of Contents
loading

This manual is also suitable for:

Suse linux enterprise server 10

Table of Contents