Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
from modem_down@thebrainbin.org to selfhosted@lemmy.world on 31 Jul 16:40
https://thebrainbin.org/m/selfhosted@lemmy.world/t/1840432

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

##fde ##linux ##luks ##nitrokey ##security ##sysadmin ##yubikey #selfhosted

threaded - newest

talkingpumpkin@lemmy.world on 31 Jul 17:07 next collapse

Does this have anything to do with self hosting?

modem_down@thebrainbin.org on 31 Jul 17:28 collapse

Yes. Here are some common self-hosting scenarios:

  • Home server containing family files: scans, photos, device backups, ...
  • Office server containing business files: sensitive documents, device backups, ...
  • Web or email server containing websites, Fediverse instances, emails, etc

In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It's mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

However, there is more than one way to do that. Hence the question in my OP.

irmadlad@lemmy.world on 31 Jul 18:17 next collapse

I just manually type the password in. Not quit as elegant, but does the job.

It_is_gaslighting@discuss.tchncs.de on 31 Jul 18:37 collapse

FIDO2 is great. Only thing I am scared of is losing it/them. So a backup access becomes the issue IMHO.