Encrypt a volume with LUKS and prove the recovery key works
Task
Encrypt a data volume on lin-srv with LUKS, add a second key slot as a recovery key, and prove three things: the data is unreadable without a key, the everyday passphrase opens it, and the recovery key opens it too. The last one is the check most organisations skip, and the one that decides whether encryption protects data or destroys it.
Steps
- Create a 500 MB file, attach it with
losetup, and runcryptsetup luksFormaton the loop device with your everyday lab passphrase. - Open it with
cryptsetup openassecuredata, create an ext4 file system, mount it, and write a file containing the wordCONFIDENTIAL-MARKER. - Add a recovery key with
cryptsetup luksAddKey, using a long random string you generate withopenssl rand -base64 24. Savecryptsetup luksDumptolab/crypto/dump.txtand record inlab/crypto/escrow.txtwhere a real recovery key would be kept. - Unmount and close the volume. Search the raw loop device for the marker with
grep -c CONFIDENTIAL-MARKERand save the count tolab/crypto/raw-search.txt. - Open the volume with the recovery key instead of the passphrase, read the file, and save
catof it tolab/crypto/recovered.txt.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Ec 'Key Slot|Keyslots' lab/crypto/dump.txt
grep -Ec '^[[:space:]]+[0-9]: luks2|Key Slot [0-9]: ENABLED' lab/crypto/dump.txt
cat lab/crypto/raw-search.txt
grep -c 'CONFIDENTIAL-MARKER' lab/crypto/recovered.txt
grep -Eic 'vault|escrow|safe|separate|offline' lab/crypto/escrow.txt
The dump shows two key slots in use, the raw device contains the marker zero times, and the recovery key opened the volume and returned it. If the raw search found the marker, the data was written before encryption or outside the encrypted volume -- the condition that makes encryption useless.
Notes
BitLocker's equivalent is the 48-digit recovery password, backed up to Active Directory or a management service. Its most common real-world failure is the one this lab tests: a TPM change prompts for the recovery key and nobody can find it.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.