LUKS Encryption
Setting Up LUKS¶
Use cryptsetup to initialize LUKS on the partition. Replace /dev/sdb1 with your target partition:
This command will prompt for a passphrase and confirm the encryption settings (default: AES-CBC-ESSIV:SHA256 on most systems; verify with cryptsetup benchmark for confirmation).
⚠️ Critical Warning: LUKS encryption permanently locks data if the passphrase is lost. Always securely back up your passphrase using a hardware security key, encrypted backup drive, or trusted password manager. Never store it in plain text or unencrypted files.
To open the encrypted volume and create a mapped device:
This creates a /dev/mapper/my_encrypted_volume device.
systemd Unit File Example¶
Place this file in /etc/systemd/system/luks-mount.service and run sudo systemctl enable luks-mount.service to enable the service at boot:
[Unit]
Description=Mount Encrypted Volume
[Service]
Type=oneshot
ExecStart=/usr/bin/cryptsetup open /dev/sdb1 my_encrypted_volume && /usr/bin/mount /dev/mapper/my_encrypted_volume /mnt/encrypted
ExecStop=/usr/bin/umount /mnt/encrypted && /usr/bin/cryptsetup close my_encrypted_volume
Restart=on-failure
[Install]
WantedBy=multi-user.target