Encrypt a volume with LUKS and prove the recovery key works

short · 45 min · Objective 3.1

Task

Encrypt a data volume on lin-srv with LUKS, add a second key slot as a recovery key, and prove three things: the data is unreadable without a key, the everyday passphrase opens it, and the recovery key opens it too. The last one is the check most organisations skip, and the one that decides whether encryption protects data or destroys it.

Steps

  1. Create a 500 MB file, attach it with losetup, and run cryptsetup luksFormat on the loop device with your everyday lab passphrase.
  2. Open it with cryptsetup open as securedata, create an ext4 file system, mount it, and write a file containing the word CONFIDENTIAL-MARKER.
  3. Add a recovery key with cryptsetup luksAddKey, using a long random string you generate with openssl rand -base64 24. Save cryptsetup luksDump to lab/crypto/dump.txt and record in lab/crypto/escrow.txt where a real recovery key would be kept.
  4. Unmount and close the volume. Search the raw loop device for the marker with grep -c CONFIDENTIAL-MARKER and save the count to lab/crypto/raw-search.txt.
  5. Open the volume with the recovery key instead of the passphrase, read the file, and save cat of it to lab/crypto/recovered.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Ec 'Key Slot|Keyslots' lab/crypto/dump.txt
grep -Ec '^[[:space:]]+[0-9]: luks2|Key Slot [0-9]: ENABLED' lab/crypto/dump.txt
cat lab/crypto/raw-search.txt
grep -c 'CONFIDENTIAL-MARKER' lab/crypto/recovered.txt
grep -Eic 'vault|escrow|safe|separate|offline' lab/crypto/escrow.txt

The dump shows two key slots in use, the raw device contains the marker zero times, and the recovery key opened the volume and returned it. If the raw search found the marker, the data was written before encryption or outside the encrypted volume -- the condition that makes encryption useless.

Notes

BitLocker's equivalent is the 48-digit recovery password, backed up to Active Directory or a management service. Its most common real-world failure is the one this lab tests: a TPM change prompts for the recovery key and nobody can find it.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.