OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 21.7 Legacy Series »
  • Full disk encryption network unlock
« previous next »
  • Print
Pages: [1]

Author Topic: Full disk encryption network unlock  (Read 2744 times)

mnaim

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 5
    • View Profile
Full disk encryption network unlock
« on: August 26, 2021, 03:48:59 pm »
Hi,

is it possible to implement this kind of network unlock of full disk encryption?

OPNSence firewall is full of password, private keys, VPN passphrases etc, os stealing a box or VM is big risk.
But firewall with preboot auth is problem, because unattended reboot will render network unreachable.

Solution is pretty simple like in Linux world Tang - https://semanticlab.net/sysadmin/encryption/Network-bound-disk-encryption-in-ubuntu-20.04/

Is it possible to implement somehow?

Thanks
Logged

schnipp

  • Sr. Member
  • ****
  • Posts: 379
  • Karma: 19
    • View Profile
Re: Full disk encryption network unlock
« Reply #1 on: August 26, 2021, 05:08:33 pm »
Using Tang is a good solution in big companies where the tang server could be physically separated at another location. Placing the Tang server next to the Opnsense does not improve security. But indeed, stealing the box can be a big risk and can cause sleepless nights.

Edit:
I am looking for a similar solution which can be used at home, but I don't have an idea so far.
« Last Edit: August 26, 2021, 05:10:44 pm by schnipp »
Logged
OPNsense 24.7.9_1-amd64

jimjohn

  • Full Member
  • ***
  • Posts: 128
  • Karma: 3
    • View Profile
Re: Full disk encryption network unlock
« Reply #2 on: August 26, 2021, 06:54:13 pm »
Dropbear with SSH server to unlock encrypted LVM over SSH? Not quite what you were asking but maybe a help.
Logged

schnipp

  • Sr. Member
  • ****
  • Posts: 379
  • Karma: 19
    • View Profile
Re: Full disk encryption network unlock
« Reply #3 on: August 26, 2021, 09:20:56 pm »
Quote from: jimjohn on August 26, 2021, 06:54:13 pm
Dropbear with SSH server to unlock encrypted LVM over SSH? Not quite what you were asking but maybe a help.

This solution is already in place for the home server. But, for the primary network gateway (Opnsense) this does not make sense. Remote pre-boot authentication needs a network connection to the internet which is not available that time.
Logged
OPNsense 24.7.9_1-amd64

mnaim

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 5
    • View Profile
Re: Full disk encryption network unlock
« Reply #4 on: August 27, 2021, 01:44:05 am »
tang could run anywhere from small vps (over internet, yes it is secure) or raspberry zero for 10$ at home hidden in closet :)
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 21.7 Legacy Series »
  • Full disk encryption network unlock
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2