(Although, you could just have an entire LUKS-encrypted swap volume instead of a swapfile...)
(Although, you could just have an entire LUKS-encrypted swap volume instead of a swapfile...)
This:
- Allows a encrypted swap partition (on in lvm2 on top of luks, sure not perfect but I don't really use swap)
- Allows hibernation (which I don't really use tbh.)
- Fully encrypted disc
- Fast boot (compared to e.g. encrypted grub, at least last time I checked)
- Easy resizing of partitions on demand
- Which in turn makes it easier to use more partitions (for /, /home, etc.), which is necessary for taking advantage of certain mount flags like noexec for security.
Anyway I think the reason Ubuntu uses a swap file is because it means you don't need to resize a partition when "upgrading" your RAM or similar (for hibernation to work). Through tbh. they should make the choice in the installer dependent of the hardware.
However, an alternative is having your EFI partition reside on a USB drive that in turn boots into your encrypted partition.
The reason for this are many fold including that Linux assumes /boot is managed by it but the ESP isn't managed by Linux and might contain other EFI compatible programs. Another reason is that you want to make sure only the signed blob is in the ESP and nothing else, but depending on your distro and packages all kind of thinks might be put into /boot. Another reason is the dir structure. /boot is flat but ESP isn't meant to be flat e.g. in my case it's /EFI/<osname>/<efifiles>
E.g. my /boot partition contains "initramfs-linux.img", "intel-ucode.img" and "vmlinuz-linux" but my /esp contains only linux-signed.efi which packs the necessary image files, linux kernel, kernel parameters, boot splash screen etc.
Still what you can do (with reasonable effort) depends a bit on the Linux Distro you run.
Also in many default setups you have a /boot parition and a ESP partition, in your case you just folded both into one. In my case I don't have a boot parition and could as far as I know tweak my system not not have a /boot folder at all as it's not really used, it's just not worth the effort to do so.
I guess the point I was trying to make, is whether you call the partition that holds your unified kernel images /boot or /esp or whatever.. it is still a separate unencrypted partition that most people would associate with a boot partition, whether it is mounted at /boot or /esp.
- lvm on luks: inside the luks dm-crypt container, create multiple logical volumes: one for swap, one for the root filesystem
- swap on dm-crypt: create a separate encrypted partition for swap
Since the swap data needs no permanence, it's possible to generate a new encryption key every boot. Debian's crypttab supports this out of the box [0]:
cswap /dev/sda6 /dev/urandom cipher=aes-xts-plain64,size=256,hash=sha1,swap
(although I'd recommend using a /dev/disk/by-id/ path there, for obvious reasons. The scripts do check there's no valid signature on the partition before formatting, but still...)[0] https://manpages.debian.org/buster/cryptsetup-run/crypttab.5...
Unless you want to hibernate!
partition > LUKS > LVM > swap volume
That way you get encrypted swap without having swap be a file in your filesystem.