whatis luks
LUKS
Also known as: Linux Unified Key Setup, cryptsetup, dm-crypt
The standard Linux disk encryption format, managed with cryptsetup, that encrypts a whole partition behind one or more passphrases.
What Is LUKS in Linux?
LUKS wraps a block device with dm-crypt encryption. A header holds up to several key slots, so you can have a passphrase, a recovery key, and a TPM-backed key all unlocking the same data.
Full-disk encryption with LUKS protects data on a stolen laptop or a decommissioned drive. It does nothing once the system is booted and unlocked, so it complements rather than replaces other security.
Example
sudo cryptsetup luksFormat /dev/sdb1
sudo cryptsetup open /dev/sdb1 secure Learn more about LUKS
- LUKS Disk Encryption: Setting Up and Managing Encrypted Volumes Full disk encryption protects data at rest, which means a stolen laptop or a returned disk. Here is how key slots work, how to add and revoke passphrases, and what LUKS does not protect against.
- Encrypting Your Linux Installation with LUKS Full disk encryption protects your data if your laptop is lost or stolen. Linux uses LUKS (Linux Unified Key Setup) to encrypt partitions at the block device level. This guide explains how to enable it at install time, how it works, and how to manage it after installation.
- Remote LUKS Unlock with Dropbear in the initramfs An encrypted server cannot boot unattended because something must type the passphrase. Putting a tiny SSH server in the initramfs lets you type it from anywhere.