Sanitise by overwrite and by cryptographic erase, and record the custody
Task
Sanitise two virtual drives by two methods and prove each one worked: overwrite an unencrypted volume and confirm no data remains, and cryptographically erase an encrypted one by destroying its keys and confirm even the correct passphrase no longer opens it. Then produce the certificate and chain-of-custody records a real disposal needs, drive by drive.
Steps
- Drive A: create a file, attach it, make an ext4 file system, write files containing
SECRET-A, unmount it, and confirmgrep -c SECRET-Aon the raw loop device finds it. Save the count tolab/sanitise/a-before.txt. - Overwrite drive A with
shred -n 1 -zon the loop device (ordd if=/dev/zeroof the same size), then search again and save the count tolab/sanitise/a-after.txt. - Drive B: create a LUKS volume on a second loop device, write files containing
SECRET-B, close it, then destroy every key slot withcryptsetup luksErase. Try to open it with the correct passphrase and save the result tolab/sanitise/b-open.txt, andcryptsetup luksDumptolab/sanitise/b-dump.txt. - Write
lab/sanitise/certificate.csvwith headerserial,method,standard_level,date,operator,witness,verified, using the loop files' names as serial numbers. - Write
lab/sanitise/custody.csvwith headerserial,from,to,date,seal,signaturerecording each drive's path from removal to disposal, with at least three transfers each.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
cat lab/sanitise/a-before.txt lab/sanitise/a-after.txt
grep -Eic 'no key available|failed|No usable keyslot' lab/sanitise/b-open.txt
awk '/^Keyslots:/ {k=1; next} /^[A-Z]/ {k=0} (k && /^[[:space:]]+[0-9]+: luks/) || /Key Slot [0-9]: ENABLED/ {n++} END {print n+0" key slot(s) left"}' lab/sanitise/b-dump.txt
awk -F, 'NR>1 && ($5=="" || $6=="" || $7=="") {bad++} END {print bad+0" incomplete certificate row(s)"}' lab/sanitise/certificate.csv
awk -F, 'NR>1 {c[$1]++} END {for (s in c) if (c[s]<3) short++; print short+0" drive(s) with fewer than 3 transfers"}' lab/sanitise/custody.csv
Drive A's marker count goes from at least one to zero; drive B refuses its own correct passphrase because no key slot remains, so the dump lists 0; every certificate row names an operator, a witness and a verification; and every drive has at least three recorded transfers. On a real SSD, the overwrite result would not be trustworthy for the reasons in the lesson, which is why drive B's method exists.
Notes
luksErase destroys only the key slots, not the encrypted data, which remains as ciphertext that nothing can decrypt. That is exactly how a self-encrypting drive's cryptographic erase works, done here in software where you can see it.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.