They offer different flash templates with latest features.
Login

Forgot password
Register
Back
Written by:
Pepas
Score: 2
votes: 9
Format: Awaiting official review

 Install LinuxMint totally LUKS encrypted, with LVMs of root, swap (and optionally data)


This tutorial shows how to install Linux Mint Debian Edition (201403), or Linux Mint Debian Edition version 2 (201503 or 201701), or regular Linux Mint 17.1, 17.2, 17.3 or 18, 18.1, 18.2, 18.3, 19, 19.1, either i686 or amd64, whether with MSDOS or GPT partitions, UEFI or not. The result is:

A fully LUKS encrypted system, with LVM2 volumes of root, swap and (optionally: data) with optional boot partition (with optional boot-from-iso-file too).

Instructions

1. Boot the Live environment

2. Open the Terminal (Menu, Terminal or Ctrl-Alt-T) and enter:

sudo -i
wget j.mp/lmdescrypt

3. If needed, adapt the SETTINGS section:

nano lmdescrypt

4. Make sure all partitions in the SETTINGS section exist

For example, (re)partitioning the drive like this
(erasing all, taking up all space):

swapoff -a  # unmount all automounted swap partitions
sgdisk -Zon1::+2M -t1:ef02 -c1:BIOS -n 2::-0 -t2:8e00 -c2:X -g /dev/sda

 

# For a UEFI setup instead, this example works:
sgdisk -Zon1::+260M -t1:ef00 -c1:EFI -n2::-0 -t2:8e00 -c2:X -g /dev/sda

This is giving almost the whole drive to the encrypted lvm2

5. Start the script:

source lmdescrypt

6. Answer the questions as they come up:

  • set password for encryption

Then all the preparations have happened:

  • set password for user
  • set timezone
  • configure keyboard

And that's it!

Installing into a pre-existing environment

  • Using a pre-existing boot-partition, LUKS partition and LVM Logical Volumes is entirely supported.
  • Not having a separate boot partition is also supported: total encryption!
  • Multiple booting with other OSes also works out of the box.
  • MBR, GPT partition tables and UEFI work according to configuration.
     

Tags: install installation linuxmint 17.1 17.2 17.3 18 18.1 18.2 18.3 19 19.1 lmde lmde2 201403 201503 201701 luks encrypted lvm lvm2 encryption
Created: 2 years ago.
Last edited: 1 month ago.


Comments
5 months ago

Trapper333
You've been busy. :) I see that lmdescrypt v0.988 to include 19 & lmde3 is now available. Thank you very much.  
5 months ago

Trapper333
I am having difficulty finding lmdescrypt v0.987. The links provided above link to 0.986. Also, 0.986 will install LMDE 3 but not properly. Most things seem to work properly but other things just don't work right. A biggie being gnome-terminal.  
6 months ago

Pepas
The new lmdescrypt v0.987 supports LM19 even better!  
7 months ago

Trapper333
Actually I was able to install LM19 beta with lmdescrypt v0.986 today.  
7 months ago

Trapper333
Itching for lmdescrypt support for the upcoming LM 19. :)  
1 year ago

Pepas
Sorry zeina, I don't get notifications of comments here, I just saw yours.
I have never had a problem like you describe with the terminal not opening. If it still occurs in more recent versions I should look into it more.

1. To get an encrypted /home partition, set the data-partition accordingly: data_label=home, set data_size to the desired size, set data_fs to the desired filesystem.
2. To have no swap partition: set swap_size= (empty) and after the install is finished, set up a swap file on the newly installed system.
3. To have /boot encrypted too: set boot_part= (empty). There is little sense to have a separate encrypted boot partition (with a separate password). You could leave some space on the encrypted partition and after the install make a separate boot logical partition, but again, what do you gain by that?
 
1 year ago

zeina
Hi, when I install LM 18.1 via your routine (in a VM) I cant open a terminal. When I click on the terminal icon, my mouse pointer turns into the loading clock icon for a couple of secs and then just nothing happens. When I install LM without encryption the terminal works.

Furthermore I have 3 questions:

1. I want to have a seperate encrypted home partition. How do I have to modify your script?
2. Is it possible to install without a swap partition and use a swap file instead?
3. How do I have to modify your script to encrypt /boot too?
 
1 year ago

Pepas
Added the option to include the iso as a file on the boot partition that can be booted from for rescue/reinstall purposes.  
2 years ago

Pepas
Refactored to use the script in an interactive session only, so it needs to be sourced, not run. The variables and functions are then available in the same session, which can be helpful.  
2 years ago

Pepas
With Linux Mint 18 support, I added total encryption (boot doesn't have to be separate).  
2 years ago

Trapper333
Thanks for posting this Pepas!
 
2 years ago

remoulder
Self promotional - all that is needed is a link to the original page  

Other tutorials from Pepas

No other tutorials.