OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Full Disk Encryption
« previous next »
  • Print
Pages: [1]

Author Topic: Full Disk Encryption  (Read 5482 times)

sgoldtho

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Full Disk Encryption
« on: February 01, 2019, 12:06:44 pm »
I'm running OPNsense as a cloud base installation to provide a VPN responder, as such there are private keys etc. stored in a datacenter that's not under my control.

If for some reason my virtual server was copied and fell into the wrong hands, would full disk encryption provide protection from data loss?

Is it possible to install OPNsense with full disk encryption (if so how)?

Does OPNsense already have builtin protection for this?

Any thoughts or feedback on this scenario gratefully accepted...

Thanks,
Steve

 
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Full Disk Encryption
« Reply #1 on: February 01, 2019, 01:20:41 pm »
I would decouple the PKI from the VPN server. If the latter gets compromised, you revoke its cert and build a new one. None of the user private keys need be stored on it.

I'm not sure how easy this is with OPNsense, but you could run a separate OpenVPN server would certainly fit the bill.

Bart...
Logged

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Full Disk Encryption
« Reply #2 on: February 01, 2019, 04:59:06 pm »
It is quite simple: just import the certificates you need with the private key. For the others leave the private key out and just paste the public part (certificate).
Logged

sgoldtho

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Full Disk Encryption
« Reply #3 on: February 02, 2019, 06:51:31 am »
Thanks for your thoughts, I will definitely move the PKI to a host under my control.

I'm still interested to know if OPNsense can be used with disk encryption (bioctl, gbde or geli)?

Thanks,
Steve
Logged

jaispirit

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: Full Disk Encryption
« Reply #4 on: February 01, 2020, 08:01:46 am »
Nowadays, an installation without hard disk encryption is indispensable. Hopefully this will be taken into account in future versions.

PfSense: Without root access but with disk encryption
OPNsense: With root access but without disk encryption

The intentions behind are obviously!

SAFETY FIRST!!!
« Last Edit: February 01, 2020, 08:18:45 am by jaispirit »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Full Disk Encryption
« Reply #5 on: February 01, 2020, 08:52:26 am »
> Nowadays, an installation without hard disk encryption is indispensable.

[citation needed]

> PfSense: Without root access but with disk encryption
> OPNsense: With root access but without disk encryption

Sorry but... WTF did I just read?

You can bootstrap into any sort of disk environment if you really want. And you should check your "without root access" claim because it is untrue and merely used here for exposition.


Cheers,
Franco
Logged

banym

  • Sr. Member
  • ****
  • Posts: 468
  • Karma: 31
  • Free Human Being, FreeBSD, Linux and Mac nerd
    • View Profile
    • Banym
Re: Full Disk Encryption
« Reply #6 on: February 01, 2020, 11:08:57 am »
I am a fan of full disk encryption in many areas but network devices is not one.

Full disk encryption in a virtual cloud environment in my opinion does only add security for a small number of attacks. If someone owns the hypervisor he could make a snapshot including the memory that contains the key for decrypting the disk.

Offline backups and exposed storage attacks are addressed by disk encryption. For me this would be the only reason. To not store sensitive data on the box or in the cloud is a better way with less drawbacks.

Starting the VM could only be done when entering the password. This in the most cases is not easily possible and makes it complicated to administrate.

If you have such security concerns you should not use a Cloud Firewall in first place. If you want protection against physical access of the box there are products out there that are engineered against such scenarios, maybe it is a better fit.
« Last Edit: February 03, 2020, 01:29:00 pm by banym »
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog: https://www.banym.de

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Full Disk Encryption
« Reply #7 on: February 03, 2020, 01:12:25 pm »
I agree with this. It's nice to have, but if you have a computer like a firewall that is always on it doesn't bring anything to the table because the disk encryption is only effective if the device is turned off when someone tries to steal it physically...


Cheers,
Franco
Logged

random1104

  • Jr. Member
  • **
  • Posts: 79
  • Karma: 0
    • View Profile
Re: Full Disk Encryption
« Reply #8 on: March 09, 2023, 02:07:45 am »
How would you cover that case?, I would like to block attackers trying to steal openvpn or zerotier credentials from a stolen device.

I would need tk deploy several sites, many remote and mostly sale points with very basic physical security.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Full Disk Encryption
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2