mkdocs-benoit.jp.net/HowtoSecureMailServer.page
2017-02-23 21:35:43 +01:00

25 lines
752 B
Plaintext

Notes...
```
# dd if=/dev/zero of=/var.img bs=1M count=36000
# losetup /dev/loop0 /var.img
# cryptsetup luksFormat --hash sha256 --key-size=512 /dev/loop0
# cryptsetup luksOpen /dev/loop0 crypted-var
# mkfs.ext4 -LVAR /dev/mapper/crypted-var
# mount /dev/mapper/crypted-var /mnt/
# ### stop your service using /var, rsyslog, etc.
# rsync -avh --progress /var/ /mnt/
# umount /mnt
# echo "crypted-var /var.img none luks" >> /etc/crypttab
# echo "/dev/mapper/crypted-var /var ext4 defaults 0 2" >> /etc/fstab
# reboot
# go to scaleway console, and type your passphrase!
```
Enjoy you crypted `/var` volume!
```
root@machine:~# df -h /var
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/crypted-var 35G 861M 32G 3% /var
```