From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KOkGoY5EJZdT for ; Thu, 11 Apr 2013 06:12:43 +0200 (CEST) Received: from nm16.bullet.mail.bf1.yahoo.com (nm16.bullet.mail.bf1.yahoo.com [98.139.212.175]) by mail.saout.de (Postfix) with SMTP for ; Thu, 11 Apr 2013 06:12:43 +0200 (CEST) Message-ID: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> Date: Wed, 10 Apr 2013 21:12:40 -0700 (PDT) From: John Gomez MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="-1911863903-799828711-1365653560=:6456" Subject: [dm-crypt] How to backup entire encrypted HDD? Reply-To: John Gomez List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: "dm-crypt@saout.de" ---1911863903-799828711-1365653560=:6456 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Hello,=0ACan someone please add a section to the cryptsetup FAQ that explai= ns how to backup a HDD with whole disk encryption?=0A=0A=0AI have a 500GB = =0AHD encrypted with LUKS, partitioned with LVM (I think) and formatted ext= 4. The /boot partition is on a USB stick. I want to make a backup of the HD= D. Say my first drive is /sda and the backup drive is /sdx and I want the b= ackup to go in /sdx3.=0A=0AAFAIK, I have two choices;=0A1: Create an encryp= ted partition on /sdx say, /sdx3, mount and decrypt /sda, then use rsync to= copy the filesystem from /sda to /sdx3. Not the worst choice but there are= flaws.=A0 What if I want to do this over a network?=A0 What if I want to d= o this on /sdx that is already partitioned? (If /sdx is already partitioned= I can not encrypt the partition /sdx3. Is this correct?)=0A=0A2: Use dd (o= r GNU ddrescue or similar) using the parameters if=3D/sda of=3D/sdx3/backup= .img.=A0 Then the problems are: how do I view the files?=A0 This post descr= ibes mounting an image of a partition: http://www.rebelzero.com/howto/backu= p-and-restore-files-tofrom-a-luks-encrypted-partition-image-file/189.=A0 Do= es anyone know a better way to do this?=A0 Will this work for an image of t= he entire drive?=A0 Is there any other way to verify the integrity of the b= ackup?=0A=0AAny suggestions are appreciated.=0A=0A=0AThank you=0AJG=0A ---1911863903-799828711-1365653560=:6456 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable
Hello,Can someone please add a section to the cryptsetup FAQ that expl= ains how to backup a HDD with whole disk encryption?

I have a 500GB =0AHD encrypte= d with LUKS, partitioned with LVM (I think) and formatted ext4. The /boot p= artition is on a USB stick. I want to make a=0A backup of the HDD. Say my f= irst drive is /sda and the backup drive is /sdx and I want the backup to go= in /sdx3.

AFAIK, I have two choices;
1: Create an encrypted part= ition on /sdx say, /sdx3, mount and decrypt /sda, then use rsync to copy th= e filesystem from /sda to /sdx3. Not the worst choice but there are flaws.&= nbsp; What if I want to do this over a network?  What if I want to do = this on /sdx that is already partitioned? (If /sdx is already partitioned I= can not encrypt the partition /sdx3. Is this correct?)

2: Use dd (o= r GNU ddrescue or similar) using the parameters if=3D/sda of=3D/sdx3/backup= .img.  Then the problems are: how do I view the files?  This post= describes mounting an image of a partition: http://www.rebelzero.com/howto= /backup-and-restore-files-tofrom-a-luks-encrypted-partition-image-file/189.=   Does anyone know a better way to do this?  Will this work for a= n image of the entire drive?  Is there any other way to verify the integrity of the backup?

Any suggestion= s are appreciated.

Thank you
JG
---1911863903-799828711-1365653560=:6456-- From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ocwIaiBR1clk for ; Thu, 11 Apr 2013 11:44:54 +0200 (CEST) Received: from v52-26.vs2.regfish.de (v52-26.vs1.regfish.de [79.140.52.26]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 11 Apr 2013 11:44:54 +0200 (CEST) Received: from cassiel (p57B12C61.dip.t-dialin.net [87.177.44.97]) by v52-26.vs2.regfish.de (Postfix) with ESMTPSA id A62C43422A for ; Thu, 11 Apr 2013 11:27:44 +0200 (CEST) Date: Thu, 11 Apr 2013 11:39:23 +0200 From: orinoco Message-ID: <20130411113923.43f640c4@cassiel> In-Reply-To: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> References: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: base64 Subject: Re: [dm-crypt] How to backup entire encrypted HDD? List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de SGksDQoNCk9uIFdlZCwgMTAgQXByIDIwMTMgMjE6MTI6NDAgLTA3MDAgKFBEVCkNCkpvaG4gR29t ZXogPGQwMDA2QHltYWlsLmNvbT4gd3JvdGU6DQo+IEhlbGxvLA0KPiBDYW4gc29tZW9uZSBwbGVh c2UgYWRkIGEgc2VjdGlvbiB0byB0aGUgY3J5cHRzZXR1cCBGQVEgdGhhdCBleHBsYWlucw0KPiBo b3cgdG8gYmFja3VwIGEgSEREIHdpdGggd2hvbGUgZGlzayBlbmNyeXB0aW9uPw0KDQpJIGRvbid0 IHRoaW5rIHRoaXMgcXVlc3Rpb24gYmVsb25ncyB0byB0aGUgY3J5cHRzZXR1cCBGQVFzLCBhcyBp dCBpcyBhDQpxdWVzdGlvbiBvbiBob3cgdG8gYmFja3VwIGRhdGEgaW4gZ2VuZXJhbC4NCg0KWy4u Ll0NCj4gQW55IHN1Z2dlc3Rpb25zIGFyZSBhcHByZWNpYXRlZC4NCg0KcmRpZmYtYmFja3VwDQoN Cg0KcmVnYXJkcw0KDQpPcmlub2NvDQoNCg== From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jkkfeZGz00Lw for ; Thu, 11 Apr 2013 15:47:34 +0200 (CEST) Received: from plane.gmane.org (plane.gmane.org [80.91.229.3]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.saout.de (Postfix) with ESMTPS for ; Thu, 11 Apr 2013 15:47:34 +0200 (CEST) Received: from list by plane.gmane.org with local (Exim 4.69) (envelope-from ) id 1UQHqe-000156-I6 for dm-crypt@saout.de; Thu, 11 Apr 2013 15:47:32 +0200 Received: from c-98-227-220-190.hsd1.il.comcast.net ([98.227.220.190]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Thu, 11 Apr 2013 15:47:32 +0200 Received: from rnicholsNOSPAM by c-98-227-220-190.hsd1.il.comcast.net with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Thu, 11 Apr 2013 15:47:32 +0200 From: Robert Nichols Date: Thu, 11 Apr 2013 08:47:25 -0500 Message-ID: References: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit In-Reply-To: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> Subject: Re: [dm-crypt] How to backup entire encrypted HDD? List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On 04/10/2013 11:12 PM, John Gomez wrote: > I have a 500GB HD encrypted with LUKS, partitioned with LVM (I think) and > formatted ext4. The /boot partition is on a USB stick. I want to make a backup > of the HDD. Say my first drive is /sda and the backup drive is /sdx and I want > the backup to go in /sdx3. > > AFAIK, I have two choices; > 1: Create an encrypted partition on /sdx say, /sdx3, mount and decrypt /sda, > then use rsync to copy the filesystem from /sda to /sdx3. Not the worst choice > but there are flaws. What if I want to do this over a network? Why is that an issue? rsync will, by default, use ssh for the communication. > What if I want > to do this on /sdx that is already partitioned? (If /sdx is already partitioned > I can not encrypt the partition /sdx3. Is this correct?) Merely partitioned wouldn't be a problem, but if that partition already contains a filesystem and data you want to preserve, then converting it to encrypted would be a problem. Recent versions of the cryptsetup package do have the option to build an experimental cryptsetup-reencrypt tool that can encrypt an existing partition, but it's a long and delicate process. > 2: Use dd (or GNU ddrescue or similar) using the parameters if=/sda > of=/sdx3/backup.img. Then the problems are: how do I view the files? This post > describes mounting an image of a partition: > http://www.rebelzero.com/howto/backup-and-restore-files-tofrom-a-luks-encrypted-partition-image-file/189. > Does anyone know a better way to do this? Will this work for an image of the > entire drive? You can work with the whole drive image, but it's a bit complicated, and the steps depend on exactly how the source drive was set up and whether LVM is involved. The basic tools are "losetup" to map a loop device to a file and "kpartx" to create device maps for the partitions within a device. I can't comment on the steps needed if LVM is involved. -- Bob Nichols "NOSPAM" is really part of my email address. Do NOT delete it. From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K5Buur_yyvR4 for ; Thu, 11 Apr 2013 17:16:41 +0200 (CEST) Received: from v6.tansi.org (unknown [87.118.116.4]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 11 Apr 2013 17:16:41 +0200 (CEST) Received: from gatewagner.dyndns.org (84-72-142-22.dclient.hispeed.ch [84.72.142.22]) by v6.tansi.org (Postfix) with ESMTPA id 44CE020DC252 for ; Thu, 11 Apr 2013 17:16:40 +0200 (CEST) Date: Thu, 11 Apr 2013 17:16:39 +0200 From: Arno Wagner Message-ID: <20130411151639.GA17584@tansi.org> References: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Disposition: inline Content-Transfer-Encoding: quoted-printable In-Reply-To: <1365653560.6456.YahooMailNeo@web162401.mail.bf1.yahoo.com> Subject: Re: [dm-crypt] How to backup entire encrypted HDD? List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On Wed, Apr 10, 2013 at 09:12:40PM -0700, John Gomez wrote: > Hello, > > Can someone please add a section to the cryptsetup FAQ that explains how > to backup a HDD with whole disk encryption? =20 It is already there: Just replace "partition" with "disk" in FAQ item 6.4. It is really not different, except possibly in size.=20 =20 > I have a 500GB HD encrypted with LUKS, partitioned with LVM (I think) and > formatted ext4. The /boot partition is on a USB stick. I want to make a > backup of the HDD. Say my first drive is /sda and the backup drive is > /sdx and I want the backup to go in /sdx3. > > AFAIK, I have two choices; > > 1: Create an encrypted partition on /sdx say, /sdx3, mount and decrypt > /sda, then use rsync to copy the filesystem from /sda to /sdx3. Not the > worst choice but there are flaws.=A0 What if I want to do this over a > network?=A0=20 That would be transfer security and is out-of-scope for=20 cryptsetup. You can use the usual solutions, basically=20 ssh-tunneling or some type of VPN. > What if I want to do this on /sdx that is already partitioned?=20 > (If /sdx is already partitioned I can not encrypt the partition /sdx3. Is > this correct?) No. Why would you think that? =20 > 2: Use dd (or GNU ddrescue or similar) using the parameters if=3D/sda > of=3D/sdx3/backup.img.=A0 Then the problems are: how do I view the files?= =A0 Via the loop-device? Or restoring the image? > This post describes mounting an image of a partition: > http://www.rebelzero.com/howto/backup-and-restore-files-tofrom-a-luks-enc= rypted-partition-image-file/189.=A0 > Does anyone know a better way to do this?=A0 Will this work for an image = of > the entire drive?=A0 Is there any other way to verify the integrity of the > backup? >=20 > Any suggestions are appreciated. I think your issue is not cryptsetup, but rather the=20 complicated mess some modern distributions create using LVM. My advice would be not to use LVM in the first place. If you have to use it, just do whatever you did to the disk=20 before to the image (possibly via loop-device) and you basically=20 get the same thing you had with the raw disk. Now, doing whatever your distro did with LVM might be complicated=20 and a huge violationof KISS, but that has nothing to do with cryptsetup. Arno --=20 Arno Wagner, Dr. sc. techn., Dipl. Inform., Email: arno@wagner.name GnuPG: ID: CB5D9718 FP: 12D6 C03B 1B30 33BB 13CF B774 E35C 5FA1 CB5D 9718 ---- There are two ways of constructing a software design: One way is to make it so simple that there are obviously no deficiencies, and the other way is to make it so complicated that there are no obvious deficiencies. The first method is far more difficult. --Tony Hoare