Skip to content

LUKS Encryption

Setting Up LUKS

Use cryptsetup to initialize LUKS on the partition. Replace /dev/sdb1 with your target partition:

sudo cryptsetup luksFormat /dev/sdb1

This command will prompt for a passphrase and confirm the encryption settings (default: AES-CBC-ESSIV:SHA256 on most systems; verify with cryptsetup benchmark for confirmation).

⚠️ Critical Warning: LUKS encryption permanently locks data if the passphrase is lost. Always securely back up your passphrase using a hardware security key, encrypted backup drive, or trusted password manager. Never store it in plain text or unencrypted files.

To open the encrypted volume and create a mapped device:

sudo cryptsetup open /dev/sdb1 my_encrypted_volume

This creates a /dev/mapper/my_encrypted_volume device.


systemd Unit File Example

Place this file in /etc/systemd/system/luks-mount.service and run sudo systemctl enable luks-mount.service to enable the service at boot:

[Unit]
Description=Mount Encrypted Volume

[Service]
Type=oneshot
ExecStart=/usr/bin/cryptsetup open /dev/sdb1 my_encrypted_volume && /usr/bin/mount /dev/mapper/my_encrypted_volume /mnt/encrypted
ExecStop=/usr/bin/umount /mnt/encrypted && /usr/bin/cryptsetup close my_encrypted_volume
Restart=on-failure

[Install]
WantedBy=multi-user.target