Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Full Disk Encryption
« previous
next »
Print
Pages: [
1
]
Author
Topic: Full Disk Encryption (Read 5415 times)
sgoldtho
Newbie
Posts: 2
Karma: 0
Full Disk Encryption
«
on:
February 01, 2019, 12:06:44 pm »
I'm running OPNsense as a cloud base installation to provide a VPN responder, as such there are private keys etc. stored in a datacenter that's not under my control.
If for some reason my virtual server was copied and fell into the wrong hands, would full disk encryption provide protection from data loss?
Is it possible to install OPNsense with full disk encryption (if so how)?
Does OPNsense already have builtin protection for this?
Any thoughts or feedback on this scenario gratefully accepted...
Thanks,
Steve
Logged
bartjsmit
Hero Member
Posts: 1999
Karma: 193
Re: Full Disk Encryption
«
Reply #1 on:
February 01, 2019, 01:20:41 pm »
I would decouple the PKI from the VPN server. If the latter gets compromised, you revoke its cert and build a new one. None of the user private keys need be stored on it.
I'm not sure how easy this is with OPNsense, but you could run a separate OpenVPN server would certainly fit the bill.
Bart...
Logged
fabian
Hero Member
Posts: 2769
Karma: 200
OPNsense Contributor (Language, VPN, Proxy, etc.)
Re: Full Disk Encryption
«
Reply #2 on:
February 01, 2019, 04:59:06 pm »
It is quite simple: just import the certificates you need with the private key. For the others leave the private key out and just paste the public part (certificate).
Logged
sgoldtho
Newbie
Posts: 2
Karma: 0
Re: Full Disk Encryption
«
Reply #3 on:
February 02, 2019, 06:51:31 am »
Thanks for your thoughts, I will definitely move the PKI to a host under my control.
I'm still interested to know if OPNsense can be used with disk encryption (bioctl, gbde or geli)?
Thanks,
Steve
Logged
jaispirit
Newbie
Posts: 1
Karma: 0
Re: Full Disk Encryption
«
Reply #4 on:
February 01, 2020, 08:01:46 am »
Nowadays, an installation without hard disk encryption is indispensable. Hopefully this will be taken into account in future versions.
PfSense: Without root access but with disk encryption
OPNsense: With root access but without disk encryption
The intentions behind are obviously!
SAFETY FIRST!!!
«
Last Edit: February 01, 2020, 08:18:45 am by jaispirit
»
Logged
franco
Administrator
Hero Member
Posts: 17570
Karma: 1596
Re: Full Disk Encryption
«
Reply #5 on:
February 01, 2020, 08:52:26 am »
> Nowadays, an installation without hard disk encryption is indispensable.
[citation needed]
> PfSense: Without root access but with disk encryption
> OPNsense: With root access but without disk encryption
Sorry but... WTF did I just read?
You can bootstrap into any sort of disk environment if you really want. And you should check your "without root access" claim because it is untrue and merely used here for exposition.
Cheers,
Franco
Logged
banym
Sr. Member
Posts: 468
Karma: 31
Free Human Being, FreeBSD, Linux and Mac nerd
Re: Full Disk Encryption
«
Reply #6 on:
February 01, 2020, 11:08:57 am »
I am a fan of full disk encryption in many areas but network devices is not one.
Full disk encryption in a virtual cloud environment in my opinion does only add security for a small number of attacks. If someone owns the hypervisor he could make a snapshot including the memory that contains the key for decrypting the disk.
Offline backups and exposed storage attacks are addressed by disk encryption. For me this would be the only reason. To not store sensitive data on the box or in the cloud is a better way with less drawbacks.
Starting the VM could only be done when entering the password. This in the most cases is not easily possible and makes it complicated to administrate.
If you have such security concerns you should not use a Cloud Firewall in first place. If you want protection against physical access of the box there are products out there that are engineered against such scenarios, maybe it is a better fit.
«
Last Edit: February 03, 2020, 01:29:00 pm by banym
»
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog:
https://www.banym.de
franco
Administrator
Hero Member
Posts: 17570
Karma: 1596
Re: Full Disk Encryption
«
Reply #7 on:
February 03, 2020, 01:12:25 pm »
I agree with this. It's nice to have, but if you have a computer like a firewall that is always on it doesn't bring anything to the table because the disk encryption is only effective if the device is turned off when someone tries to steal it physically...
Cheers,
Franco
Logged
random1104
Jr. Member
Posts: 79
Karma: 0
Re: Full Disk Encryption
«
Reply #8 on:
March 09, 2023, 02:07:45 am »
How would you cover that case?, I would like to block attackers trying to steal openvpn or zerotier credentials from a stolen device.
I would need tk deploy several sites, many remote and mostly sale points with very basic physical security.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Full Disk Encryption