2010-05-05

Ubuntu 10.04 Alternate installation (encrypted LVM setup)

The Ubuntu 10.04 alternate installation CD/DVD allows you to perform certain specialist installations of Ubuntu. It provides for the following situations:
  • setting up automated deployments;
  • upgrading from older installations without network access;
  • LVM and/or RAID partitioning;
  • installs on systems with less than about 256MB of RAM (although note that low-memory systems may not be able to run a full desktop environment reasonably). 
I use this CD/DVD to install/setup an encrypted LVM (logical volume manager) disk, to protect the data on the disk.

Start by downloading the image file (ISO) from
http://releases.ubuntu.com/lucid/ or if you have some other, local location. Burn the CD/DVD and boot the computer.


Select you installation languish. If you have other keyboard setup then English I suggest that you choose yours by pressing F3. Then hit enter to install Ubuntu, choose languish for installation and location.


Type in a host/computer name. Select you time zone.


The easiest way to install on an encrypted LVM is to use the guided - use entire disk alternative. If you have dual-boot or other personal setting you need to use the manual way. I'm going with guided - use entire disk and set up encrypted LVM (and not going to address the manual way).


We hit enter to continue (this installation is on VirtualBox).


Yes.


Now we get to enter our encryption passphrase.


I choose a week passphrase, just for this installation. But you should create a very strong one and remember it. If you need help with creating a password, take a look at the s page: pctools.com/guides/password/

After this you get to size your partition, I will use max setting and if you don't have any special needs this is a good choice.


Here is the confirmation page, and if it looks ok, hit YES.

Now will the installation format the disk and install the base system. Enter your name, you user name and password.


You will get an question if you like to encrypt your home directory, if you are like me, you feel tempted to answer yes. I have tried this twice and it has only ended up in misery, so I'm not going for this choice and say NO.

If you connect to internet through a proxy server, you will get a choice to enter the address now. After this Ubuntu 10.04 will be installed, takes a while.


Typically you should go with YES so I will to (if you have multi-boot etc you should go with NO).

Choose YES to set time to UTC. And then you get to reboot.


At boot you get to enter your passphrase for the encrypted disk (or partitions). This is not the user password so don't5 mix them up, and do not forget it! You will not have access to your system without it!

Summation.
This installation is not as easy as the graphic standard installation, but if you use common sense and read carefully you should not have any problem. And now your data is more secure (much more), to hack this is, pointless. The only way to use this disk (without the passphrase) is to reinstall it.

Now you have to protect your system when its booted and is running, by enableing and setup the firewall (see tweak post for little more information) etc.

Reference:

No comments:

Post a Comment