Full Drive Encryption on Rockstor 5

Hello everyone,

I’m wondering whether the NAS can have full disk encryption on on the system disk, and data disks? Where it auto-decrypts based on TPM bound keys, by using the Clevis (GitHub - latchset/clevis: Automated Encryption Framework) software. Please ensure that it’s a release including PR #462.

What do you guys think of doing full disk encryption on Rockstor using this please? Could it be added into the core of Rockstor please? The user would be able to choose whether to do this likely during the installation of Rockstor.

@John1 at this time, only this encryption is implemented:

https://rockstor.com/docs/howtos/luks.html

If you want the root disk encrypted as well, at this time, you will need to build your own installer, as described here:

And enable it in the rockstor.kiwi file:

In a future release that might be considered to be built into the initial installer.

2 Likes