encrypted_trisquel.html 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514
  1. <!DOCTYPE html>
  2. <html>
  3. <head>
  4. <meta charset="utf-8">
  5. <meta name="viewport" content="width=device-width, initial-scale=1">
  6. <style type="text/css">
  7. @import url('../css/main.css');
  8. </style>
  9. <title>Installing Trisquel or Debian GNU/Linux with full disk encryption (including /boot)</title>
  10. </head>
  11. <body>
  12. <div class="section">
  13. <h1>Installing Trisquel or Debian GNU/Linux with full disk encryption (including /boot)</h1>
  14. <p>
  15. Libreboot on x86 uses the GRUB <a href="http://www.coreboot.org/Payloads#GRUB_2">payload</a>
  16. by default, which means that the GRUB configuration file
  17. (where your GRUB menu comes from) is stored directly alongside libreboot
  18. and its GRUB payload executable, inside
  19. the flash chip. In context, this means that installing distributions and managing them
  20. is handled slightly differently compared to traditional BIOS systems.
  21. </p>
  22. <p>
  23. On most systems, the /boot partition has to be left unencrypted while the others are encrypted.
  24. This is so that GRUB, and therefore the kernel, can be loaded and executed since the firmware
  25. can't open a LUKS volume. Not so with libreboot! Since GRUB is already included directly as a
  26. payload, even /boot can be encrypted. This protects /boot from tampering by someone with physical
  27. access to the system.
  28. </p>
  29. <p>
  30. This works in Trisquel 7, and probably Trisquel 6. Boot the 'net installer' (Install Trisquel in Text Mode).
  31. <a href="grub_boot_installer.html">How to boot a GNU/Linux installer</a>.
  32. This guide also works for the Debian distribution, when you install using the netinstall option in Debian.
  33. </p>
  34. <p>
  35. <b>This guide is *only* for the GRUB payload. If you use the depthcharge payload, ignore this section entirely.</b>
  36. </p>
  37. <p>
  38. Note: on some thinkpads, a faulty DVD drive can cause the cryptomount -a step during boot to fail. If this happens to you, try removing the drive.
  39. </p>
  40. <p><a href="index.html">Back to previous index</a></p>
  41. </div>
  42. <div class="section">
  43. <p>
  44. Set a strong user password (lots of lowercase/uppercase, numbers and symbols).
  45. </p>
  46. <p>
  47. Use of the <i>diceware method</i> is recommended, for generating secure passphrases (instead of passwords).
  48. </p>
  49. <p>
  50. when the installer asks you to set up
  51. encryption (ecryptfs) for your home directory, select 'Yes' if you want to: <b>LUKS is already secure and performs well. Having ecryptfs on top of it
  52. will add noticeable performance penalty, for little security gain in most use cases. This is therefore optional, and not recommended.
  53. Choose 'no'.</b>
  54. </p>
  55. <p>
  56. <b>
  57. Your user password should be different from the LUKS password which you will set later on.
  58. Your LUKS password should, like the user password, be secure.
  59. </b>
  60. </p>
  61. </div>
  62. <div class="section">
  63. <h1>Partitioning</h1>
  64. <p>Choose 'Manual' partitioning:</p>
  65. <ul>
  66. <li>Select drive and create new partition table</li>
  67. <li>
  68. Single large partition. The following are mostly defaults:
  69. <ul>
  70. <li>Use as: physical volume for encryption</li>
  71. <li>Encryption: aes</li>
  72. <li>key size: whatever default is given to you</li>
  73. <li>IV algorithm: whatever default is given to you</li>
  74. <li>Encryption key: passphrase</li> (<i>diceware method</i> recommended for choosing password)
  75. <li>erase data: Yes (only choose 'No' if it's a new drive that doesn't contain your private data)</li>
  76. </ul>
  77. </li>
  78. <li>
  79. Select 'configure encrypted volumes'
  80. <ul>
  81. <li>Create encrypted volumes</li>
  82. <li>Select your partition</li>
  83. <li>Finish</li>
  84. <li>Really erase: Yes</li>
  85. <li>(erase will take a long time. be patient)</li>
  86. <li>(if your old system was encrypted, just let this run for about a minute to
  87. make sure that the LUKS header is wiped out)</li>
  88. </ul>
  89. </li>
  90. <li>
  91. Select encrypted space:
  92. <ul>
  93. <li>use as: physical volume for LVM</li>
  94. <li>Choose 'done setting up the partition'</li>
  95. </ul>
  96. </li>
  97. <li>
  98. Configure the logical volume manager:
  99. <ul>
  100. <li>Keep settings: Yes</li>
  101. </ul>
  102. </li>
  103. <li>
  104. Create volume group:
  105. <ul>
  106. <li>Name: <b>matrix</b> (you can use whatever you want here, this is just an example)</li>
  107. <li>Select crypto partition</li>
  108. </ul>
  109. </li>
  110. <li>
  111. Create logical volume
  112. <ul>
  113. <li>select <b>matrix</b> (or whatever you named it before)</li>
  114. <li>name: <b>root</b> (you can use whatever you want here, this is just an example)</li>
  115. <li>size: default, minus 2048 MB</li>
  116. </ul>
  117. </li>
  118. <li>
  119. Create logical volume
  120. <ul>
  121. <li>select <b>matrix</b> (or whatever you named it before)</li>
  122. <li>name: <b>swap</b> (you can use whatever you want here, this is just an example)</li>
  123. <li>size: press enter</li>
  124. </ul>
  125. </li>
  126. </ul>
  127. </div>
  128. <div class="section">
  129. <h1>Further partitioning</h1>
  130. <p>
  131. Now you are back at the main partitioning screen. You will simply set mountpoints and filesystems to use.
  132. </p>
  133. <ul>
  134. <li>
  135. LVM LV root
  136. <ul>
  137. <li>use as: btrfs</li>
  138. <li>mount point: /</li>
  139. <li>done setting up partition</li>
  140. </ul>
  141. </li>
  142. <li>
  143. LVM LV swap
  144. <ul>
  145. <li>use as: swap area</li>
  146. <li>done setting up partition</li>
  147. </ul>
  148. </li>
  149. <li>Now you select 'Finished partitioning and write changes to disk'.</li>
  150. </ul>
  151. </div>
  152. <div class="section">
  153. <h1>Kernel</h1>
  154. <p>
  155. Installation will ask what kernel you want to use. linux-generic is fine.
  156. </p>
  157. </div>
  158. <div class="section">
  159. <h1>Tasksel</h1>
  160. <p>
  161. Choose <i>&quot;Trisquel Desktop Environment&quot;</i> if you want GNOME,
  162. <i>&quot;Trisquel-mini Desktop Environment&quot;</i> if you
  163. want LXDE or <i>&quot;Triskel Desktop Environment&quot;</i> if you want KDE.
  164. If you want to have no desktop (just a basic shell)
  165. when you boot or if you want to create your own custom setup, then choose nothing here (don't select anything).
  166. You might also want to choose some of the other package groups; it's up to you.
  167. </p>
  168. <p>
  169. For Debian, use the <em>MATE</em> option, or one of the others if you want.
  170. </p>
  171. <p>
  172. On Debian or Trisquel, you may also want to select the option for a printer server,
  173. so that you can print.
  174. </p>
  175. <p>
  176. If you want debian-testing, then you should only select barebones options here
  177. and change the entries in /etc/apt/sources.list after install to point to the new distro,
  178. and then run <strong>apt-get update</strong> and <strong>apt-get dist-upgrade</strong>
  179. as root, then reboot and run <b>tasksel</b> as root. This is to avoid downloading large
  180. packages twice.
  181. </p>
  182. </div>
  183. <div class="section">
  184. <h1>Postfix configuration</h1>
  185. <p>
  186. If asked, choose <i>&quot;No Configuration&quot;</i> here (or maybe you want to select something else. It's up to you.)
  187. </p>
  188. </div>
  189. <div class="section">
  190. <h1>Install the GRUB boot loader to the master boot record</h1>
  191. <p>
  192. Choose 'Yes'. It will fail, but don't worry. Then at the main menu, choose 'Continue without a bootloader'.
  193. You could also choose 'No'. Choice is irrelevant here.
  194. </p>
  195. <p>
  196. <i>You do not need to install GRUB at all, since in libreboot you are using the GRUB payload (for libreboot) to boot your system directly.</i>
  197. </p>
  198. </div>
  199. <div class="section">
  200. <h1>Clock UTC</h1>
  201. <p>
  202. Just say 'Yes'.
  203. </p>
  204. </div>
  205. <div class="section">
  206. <h1>
  207. Booting your system
  208. </h1>
  209. <p>
  210. At this point, you will have finished the installation. At your GRUB payload, press C to get to the command line.
  211. </p>
  212. <p>
  213. Do that:<br/>
  214. grub&gt; <b>cryptomount -a</b><br/>
  215. grub&gt; <b>set root='lvm/matrix-root'</b><br/>
  216. grub&gt; <b>linux /vmlinuz root=/dev/mapper/matrix-root cryptdevice=/dev/mapper/matrix-root:root</b><br/>
  217. grub&gt; <b>initrd /initrd.img</b><br/>
  218. grub&gt; <b>boot</b>
  219. </p>
  220. </div>
  221. <div class="section">
  222. <h1>
  223. ecryptfs
  224. </h1>
  225. <p>
  226. If you didn't encrypt your home directory, then you can safely ignore this section.
  227. </p>
  228. <p>
  229. Immediately after logging in, do that:<br/>
  230. $ <b>sudo ecryptfs-unwrap-passphrase</b>
  231. </p>
  232. <p>
  233. This will be needed in the future if you ever need to recover your home directory from another system, so write it down and keep the note
  234. somewhere secret. Ideally, you should memorize it and then burn the note (or not even write it down, and memorize it still)>
  235. </p>
  236. </div>
  237. <div class="section">
  238. <h1>
  239. Modify grub.cfg (CBFS)
  240. </h1>
  241. <p>
  242. Now you need to set it up so that the system will automatically boot, without having to type a bunch of commands.
  243. </p>
  244. <p>
  245. Modify your grub.cfg (in the firmware) <a href="grub_cbfs.html">using this tutorial</a>;
  246. just change the default menu entry 'Load Operating System' to say this inside:
  247. </p>
  248. <p>
  249. <b>cryptomount -a</b><br/>
  250. <b>set root='lvm/matrix-root'</b><br/>
  251. <b>linux /vmlinuz root=/dev/mapper/matrix-root cryptdevice=/dev/mapper/matrix-root:root</b><br/>
  252. <b>initrd /initrd.img</b>
  253. </p>
  254. <p>
  255. Without specifying a device, the <i>-a</i> parameter tries to unlock all detected LUKS volumes.
  256. You can also specify -u UUID or -a (device).
  257. </p>
  258. <p>
  259. Additionally, you should set a GRUB password. This is not your LUKS password, but it's a password that you have to enter to see
  260. GRUB. This protects your system from an attacker simply booting a live USB and re-flashing your firmware. <b>This should be different than your LUKS passphrase and user password.</b>
  261. </p>
  262. <p>
  263. Use of the <i>diceware method</i> is recommended, for generating secure passphrases (as opposed to passwords).
  264. </p>
  265. <p>
  266. The GRUB utility can be used like so:<br/>
  267. $ <b>grub-mkpasswd-pbkdf2</b>
  268. </p>
  269. <p>
  270. Give it a password (remember, it has to be secure) and it'll output something like:<br/>
  271. <b>grub.pbkdf2.sha512.10000.711F186347156BC105CD83A2ED7AF1EB971AA2B1EB2640172F34B0DEFFC97E654AF48E5F0C3B7622502B76458DA494270CC0EA6504411D676E6752FD1651E749.8DD11178EB8D1F633308FD8FCC64D0B243F949B9B99CCEADE2ECA11657A757D22025986B0FA116F1D5191E0A22677674C994EDBFADE62240E9D161688266A711</b>
  272. </p>
  273. <p>
  274. Use of the <i>diceware method</i> is recommended, for generating secure passphrases (instead of passwords).
  275. </p>
  276. <p>
  277. Put that in the grub.cfg (the one for CBFS inside the ROM) before the 'Load Operating System' menu entry like so (example):<br/>
  278. </p>
  279. <pre>
  280. <b>set superusers=&quot;root&quot;</b>
  281. <b>password_pbkdf2 root grub.pbkdf2.sha512.10000.711F186347156BC105CD83A2ED7AF1EB971AA2B1EB2640172F34B0DEFFC97E654AF48E5F0C3B7622502B76458DA494270CC0EA6504411D676E6752FD1651E749.8DD11178EB8D1F633308FD8FCC64D0B243F949B9B99CCEADE2ECA11657A757D22025986B0FA116F1D5191E0A22677674C994EDBFADE62240E9D161688266A711</b>
  282. </pre>
  283. <p style="font-size:2em;">
  284. MAKE SURE TO DO THIS ON grubtest.cfg *BEFORE* DOING IT ON grub.cfg.
  285. Then select the menu entry that says <i>Switch to grubtest.cfg</i> and test that it works.
  286. Then copy that to grub.cfg once you're satisfied.
  287. WHY? BECAUSE AN INCORRECTLY SET PASSWORD CONFIG MEANS YOU CAN'T AUTHENTICATE, WHICH MEANS 'BRICK'.
  288. </p>
  289. <p>
  290. (emphasis added, because it's needed. This is a common roadblock for users)
  291. </p>
  292. <p>
  293. Obviously, replace it with the correct hash that you actually got for the password that you entered. Meaning, not the hash that you see above!
  294. </p>
  295. <p>
  296. After this, you will have a modified ROM with the menu entry for cryptomount, and the entry before that for the GRUB password. Flash the modified ROM
  297. using <a href="../install/index.html#flashrom">this tutorial</a>.
  298. </p>
  299. </div>
  300. <div class="section">
  301. <h1 id="troubleshooting">Troubleshooting</h1>
  302. <p>
  303. A user reported issues when booting with a docking station attached
  304. on an X200, when decrypting the disk in GRUB. The error
  305. <i>AHCI transfer timed out</i> was observed. The workaround
  306. was to remove the docking station.
  307. </p>
  308. <p>
  309. Further investigation revealed that it was the DVD drive causing problems.
  310. Removing that worked around the issue.
  311. </p>
  312. <pre>
  313. &quot;sudo wodim -prcap&quot; shows information about the drive:
  314. Device was not specified. Trying to find an appropriate drive...
  315. Detected CD-R drive: /dev/sr0
  316. Using /dev/cdrom of unknown capabilities
  317. Device type : Removable CD-ROM
  318. Version : 5
  319. Response Format: 2
  320. Capabilities :
  321. Vendor_info : 'HL-DT-ST'
  322. Identification : 'DVDRAM GU10N '
  323. Revision : 'MX05'
  324. Device seems to be: Generic mmc2 DVD-R/DVD-RW.
  325. Drive capabilities, per MMC-3 page 2A:
  326. Does read CD-R media
  327. Does write CD-R media
  328. Does read CD-RW media
  329. Does write CD-RW media
  330. Does read DVD-ROM media
  331. Does read DVD-R media
  332. Does write DVD-R media
  333. Does read DVD-RAM media
  334. Does write DVD-RAM media
  335. Does support test writing
  336. Does read Mode 2 Form 1 blocks
  337. Does read Mode 2 Form 2 blocks
  338. Does read digital audio blocks
  339. Does restart non-streamed digital audio reads accurately
  340. Does support Buffer-Underrun-Free recording
  341. Does read multi-session CDs
  342. Does read fixed-packet CD media using Method 2
  343. Does not read CD bar code
  344. Does not read R-W subcode information
  345. Does read raw P-W subcode data from lead in
  346. Does return CD media catalog number
  347. Does return CD ISRC information
  348. Does support C2 error pointers
  349. Does not deliver composite A/V data
  350. Does play audio CDs
  351. Number of volume control levels: 256
  352. Does support individual volume control setting for each channel
  353. Does support independent mute setting for each channel
  354. Does not support digital output on port 1
  355. Does not support digital output on port 2
  356. Loading mechanism type: tray
  357. Does support ejection of CD via START/STOP command
  358. Does not lock media on power up via prevent jumper
  359. Does allow media to be locked in the drive via PREVENT/ALLOW command
  360. Is not currently in a media-locked state
  361. Does not support changing side of disk
  362. Does not have load-empty-slot-in-changer feature
  363. Does not support Individual Disk Present feature
  364. Maximum read speed: 4234 kB/s (CD 24x, DVD 3x)
  365. Current read speed: 4234 kB/s (CD 24x, DVD 3x)
  366. Maximum write speed: 4234 kB/s (CD 24x, DVD 3x)
  367. Current write speed: 4234 kB/s (CD 24x, DVD 3x)
  368. Rotational control selected: CLV/PCAV
  369. Buffer size in KB: 1024
  370. Copy management revision supported: 1
  371. Number of supported write speeds: 4
  372. Write speed # 0: 4234 kB/s CLV/PCAV (CD 24x, DVD 3x)
  373. Write speed # 1: 2822 kB/s CLV/PCAV (CD 16x, DVD 2x)
  374. Write speed # 2: 1764 kB/s CLV/PCAV (CD 10x, DVD 1x)
  375. Write speed # 3: 706 kB/s CLV/PCAV (CD 4x, DVD 0x)
  376. Supported CD-RW media types according to MMC-4 feature 0x37:
  377. Does write multi speed CD-RW media
  378. Does write high speed CD-RW media
  379. Does write ultra high speed CD-RW media
  380. Does not write ultra high speed+ CD-RW media
  381. </pre>
  382. </div>
  383. <div class="section">
  384. <p>
  385. Copyright &copy; 2014, 2015 Leah Rowe &lt;info@minifree.org&gt;<br/>
  386. Permission is granted to copy, distribute and/or modify this document
  387. under the terms of the GNU Free Documentation License, Version 1.3
  388. or any later version published by the Free Software Foundation;
  389. with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts.
  390. A copy of the license can be found at <a href="../gfdl-1.3.txt">../gfdl-1.3.txt</a>
  391. </p>
  392. <p>
  393. Updated versions of the license (when available) can be found at
  394. <a href="https://www.gnu.org/licenses/licenses.html">https://www.gnu.org/licenses/licenses.html</a>
  395. </p>
  396. <p>
  397. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE
  398. EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS
  399. AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF
  400. ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS,
  401. IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION,
  402. WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR
  403. PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS,
  404. ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT
  405. KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT
  406. ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU.
  407. </p>
  408. <p>
  409. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE
  410. TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION,
  411. NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT,
  412. INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES,
  413. COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR
  414. USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN
  415. ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR
  416. DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR
  417. IN PART, THIS LIMITATION MAY NOT APPLY TO YOU.
  418. </p>
  419. <p>
  420. The disclaimer of warranties and limitation of liability provided
  421. above shall be interpreted in a manner that, to the extent
  422. possible, most closely approximates an absolute disclaimer and
  423. waiver of all liability.
  424. </p>
  425. </div>
  426. </body>
  427. </html>