{"id":33937,"date":"2021-06-11T16:25:32","date_gmt":"2021-06-11T16:25:32","guid":{"rendered":"https:\/\/ubuntuhandbook.org\/?p=33937"},"modified":"2021-06-11T16:25:32","modified_gmt":"2021-06-11T16:25:32","slug":"encrypt-system-disk-installing-ubuntu","status":"publish","type":"post","link":"https:\/\/ubuntuhandbook.org\/index.php\/2021\/06\/encrypt-system-disk-installing-ubuntu\/","title":{"rendered":"How to Encrypt Full System Disk While Installing Ubuntu 20.04, 21.04"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2020\/06\/ubuntu-icon.png\" alt=\"\" width=\"250\" height=\"250\" class=\"alignleft size-full wp-image-10245\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2020\/06\/ubuntu-icon.png 250w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2020\/06\/ubuntu-icon-150x150.png 150w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><\/p>\n<p>This is an easy to follow beginner&#8217;s guide shows how to encrypt the full file system while installing Ubuntu.<\/p>\n<p>As you may know, it&#8217;s easy to hack against Ubuntu Linux physically. Though users can add password protect to the Grub boot menu, the file system is still accessible via a live system, e.g., bootable USB installer. <\/p>\n<p>To prevent your Ubuntu from physical hacking ultimately, adding password protect to the full system disk can be the best choice. And you can do it during installing Ubuntu.<\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-password.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-password-600x302.jpg\" alt=\"\" width=\"600\" height=\"302\" class=\"aligncenter size-large wp-image-33945\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-password-600x302.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-password-300x151.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-password-768x387.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-password.jpg 800w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<div class=\"arconix-box arconix-box-red\"><i class='fa fa-2x pull-left fa-exclamation-triangle'><\/i><div class=\"arconix-box-content\">Important: If you forget the password, all data will be lost! No way to reset forgotten password.<\/div><\/div>\n<p><b>1.)<\/b> Firstly, this tutorial is not a full Ubuntu installation guide. If you are not getting started, take a look at this <a href=\"https:\/\/ubuntuhandbook.org\/index.php\/how-to-install-ubuntu\/\" rel=\"noopener\" target=\"_blank\">step by step how to install guide<\/a>.<\/p>\n<p><b>2.)<\/b> If you&#8217;re going to <i>install Ubuntu as the ONLY operating system in the hard drive<\/i>, just choose &#8216;<i><b>Erase disk and install Ubuntu<\/b><\/i>&#8216; when you&#8217;re at <b>Installation type<\/b> page.<\/p>\n<p>Then click on &#8216;Advanced features&#8217; to choose either LVM or ZFS and enable &#8216;Encrypt the new Ubuntu installation for security&#8217;.<\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-erase-encrypt.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-erase-encrypt-600x337.jpg\" alt=\"\" width=\"600\" height=\"337\" class=\"aligncenter size-large wp-image-33939\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-erase-encrypt-600x337.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-erase-encrypt-300x168.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-erase-encrypt-768x431.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-erase-encrypt.jpg 1368w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><b>3.)<\/b> Mostly I&#8217;ll choose &#8216;<i>Something else<\/i>&#8216; to manually create partitions for Ubuntu file system.<\/p>\n<p>Unlike Fedora and Manjaro, Ubuntu does not provide an &#8216;<i>Encrypt<\/i>&#8216; checkbox while creating an EXT4 partition. Instead you need to create a partition use as &#8216;physical volume for encryption&#8217;.<\/p>\n<p><b>a.)<\/b> Simply choose the free space and click on &#8216;<b>+<\/b>&#8216; icon on partition table. In the pop-up <i>Create partition<\/i> dialog do:<\/p>\n<div class=\"arconix-box arconix-box-yellow\"><i class='fa fa-2x pull-left fa-lightbulb-o'><\/i><div class=\"arconix-box-content\">DO LEAVE 500 MB free space for \/boot partition, and a few GB for Swap area if need.<\/div><\/div>\n<ul>\n<li>Set the size for Ubuntu file system. 20 GB at least. For long time use, as large as possible.<\/li>\n<li>Select use as &#8216;<i><b>physical volume for encryption<\/b><\/i>&#8216;.<\/li>\n<li>Set your password and confirm, and finally click OK.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-phiz-encrypt.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-phiz-encrypt-600x337.jpg\" alt=\"\" width=\"600\" height=\"337\" class=\"aligncenter size-large wp-image-33940\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-phiz-encrypt-600x337.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-phiz-encrypt-300x168.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-phiz-encrypt-768x431.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-phiz-encrypt.jpg 1368w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><b>b.)<\/b> After clicking OK, wait for a few seconds. A new device &#8216;<b>\/dev\/mapper\/sdaX_crypt<\/b>&#8216; will be created as EXT4 file system.<\/p>\n<p>Highlight it, and click on &#8216;<i>Change<\/i>&#8216; button. In the pop-up dialog, set the mount point as <b>\/<\/b>.<\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-ext4-encrypted.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-ext4-encrypted-600x337.jpg\" alt=\"\" width=\"600\" height=\"337\" class=\"aligncenter size-large wp-image-33941\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-ext4-encrypted-600x337.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-ext4-encrypted-300x168.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-ext4-encrypted-768x431.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-ext4-encrypted.jpg 1368w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><b>c.)<\/b> Same to Fedora, you have to create a separated <b>\/boot<\/b> partition, as it can not be encrypted.<\/p>\n<p>To do so, select the free space and click &#8220;+&#8221; to create:<\/p>\n<ul>\n<li>500 MB should be enough. 1 GB will be better.<\/li>\n<li>use as &#8216;<b>Ext4<\/b> journaling file system&#8217;<\/li>\n<li>mount point <b>\/boot<\/b><\/li>\n<\/ul>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-600x337.jpg\" alt=\"\" width=\"600\" height=\"337\" class=\"aligncenter size-large wp-image-33942\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-600x337.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-300x168.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot-768x431.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-boot.jpg 1368w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><b>d.)<\/b> Also create  250 MB &#8216;<b>EFI System Partition<\/b>&#8216; for UEFI boot machine, or 2 MB &#8216;<b>Reserved BIOS boot area<\/b>&#8216; for legacy BIOS boot machine. For small RAM, a swap area is also recommended.<\/p>\n<p>Finally the partition table will look like:<\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-600x337.jpg\" alt=\"\" width=\"600\" height=\"337\" class=\"aligncenter size-large wp-image-33943\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-600x337.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-300x168.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-768x431.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition.jpg 1368w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Finally click on &#8220;<b>Install Now<\/b>&#8221; button. And confirm on pop-up dialog.<\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-confirm.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-confirm-600x337.jpg\" alt=\"\" width=\"600\" height=\"337\" class=\"aligncenter size-large wp-image-33944\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-confirm-600x337.jpg 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-confirm-300x168.jpg 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-confirm-768x431.jpg 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/06\/ubuntu-encrypted-partition-confirm.jpg 1368w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Once you successfully installed Ubuntu, restart and you&#8217;ll get into the password prompt when booting Ubuntu (<i>see the top picture<\/i>). As well, accessing the file system from any other OS need the password you set.<\/p>","protected":false},"excerpt":{"rendered":"<p>This is an easy to follow beginner&#8217;s guide shows how to encrypt the full file system while installing Ubuntu. As you may know, it&#8217;s easy to hack against Ubuntu Linux physically. Though users can add password protect to the Grub boot menu, the file system is still accessible via a live system, e.g., bootable USB [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33938,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[2011],"class_list":["post-33937","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-howtos","tag-disk-encryption"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/posts\/33937","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/comments?post=33937"}],"version-history":[{"count":0,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/posts\/33937\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/media\/33938"}],"wp:attachment":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/media?parent=33937"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/categories?post=33937"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/tags?post=33937"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}