This means that upon next boot, the whole unit would be bricked by design because the LUKS key could not be decrypted. Scenario:-Raspberry Pi w/Zymkey 4i is in production mode and key destruction setting is enabled-Device is powered on and running-Case w/perimeter circuit is opened (keys are deleted)
ssd 5 installation, The X5’s read/write speeds of 2,800/2,300 MB/s* are 5.2x/4.5x faster than a Portable SSD with SATA interface and 25.5x/20.9x faster than an external HDD**.
LUKS (L inux U nified K ey S etup) is the popular key management setup for dm-crypt, the de-facto standard for block device encryption with Linux. LUKS provides a robust and flexible mechanism for multiple users (and services) to interface to and access Linux’s ‘ dm-crypt ’ infrastructure.
Please don't dig around TRUECRUPT possible solutions to match my inter operating needs, because I have the need to work with LUKS encrypted volumes, and TRUECRYPT doesn't manage them.
Phil_of_Zymbit March 23, 2019, 6:17pm #130 @doxo - this is exactly the purpose of Zymkey; it provides a “password” (named UKz - UserKeyZymbit) to LUKS, allowing for unattended operation. The “password” is based upon a measured system fingerprint (and other materials), and is automatically managed and protected by Zymkey.
LUKS (The Linux Unified Key Setup) — це специфікація шифрування дисків, створена Клеменсом Фрювірсом і, в основному, призначена для ОС Linux. LUKS визначає платформо-незалежний стандарт для використання різними інструментами.
@anand I don't know of a good answer based on what appear to be your requirements (i.e. if you need an unattended boot). My intuition tells me this isn't possible with a base hardware configuration as one way or another you will need a private key or shared secret on the SD Card, in plain text, to be used to encrypt/decrypt.
ASIDE: LUKS form of cryptography key indexing also will let you can change your phasephrase without needing to re-encrypt the whole disk.A luks encrypted disk partition is great. The only thing that can bug you from time to time is that you Second, we need to execute a shell script that unlocks the luks volume and mounts it whenever the...