Sanitise by overwrite and by cryptographic erase, and record the custody

applied · 50 min · Objective 3.6

Task

Sanitise two virtual drives by two methods and prove each one worked: overwrite an unencrypted volume and confirm no data remains, and cryptographically erase an encrypted one by destroying its keys and confirm even the correct passphrase no longer opens it. Then produce the certificate and chain-of-custody records a real disposal needs, drive by drive.

Steps

  1. Drive A: create a file, attach it, make an ext4 file system, write files containing SECRET-A, unmount it, and confirm grep -c SECRET-A on the raw loop device finds it. Save the count to lab/sanitise/a-before.txt.
  2. Overwrite drive A with shred -n 1 -z on the loop device (or dd if=/dev/zero of the same size), then search again and save the count to lab/sanitise/a-after.txt.
  3. Drive B: create a LUKS volume on a second loop device, write files containing SECRET-B, close it, then destroy every key slot with cryptsetup luksErase. Try to open it with the correct passphrase and save the result to lab/sanitise/b-open.txt, and cryptsetup luksDump to lab/sanitise/b-dump.txt.
  4. Write lab/sanitise/certificate.csv with header serial,method,standard_level,date,operator,witness,verified, using the loop files' names as serial numbers.
  5. Write lab/sanitise/custody.csv with header serial,from,to,date,seal,signature recording each drive's path from removal to disposal, with at least three transfers each.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

cat lab/sanitise/a-before.txt lab/sanitise/a-after.txt
grep -Eic 'no key available|failed|No usable keyslot' lab/sanitise/b-open.txt
awk '/^Keyslots:/ {k=1; next} /^[A-Z]/ {k=0} (k && /^[[:space:]]+[0-9]+: luks/) || /Key Slot [0-9]: ENABLED/ {n++} END {print n+0" key slot(s) left"}' lab/sanitise/b-dump.txt
awk -F, 'NR>1 && ($5=="" || $6=="" || $7=="") {bad++} END {print bad+0" incomplete certificate row(s)"}' lab/sanitise/certificate.csv
awk -F, 'NR>1 {c[$1]++} END {for (s in c) if (c[s]<3) short++; print short+0" drive(s) with fewer than 3 transfers"}' lab/sanitise/custody.csv

Drive A's marker count goes from at least one to zero; drive B refuses its own correct passphrase because no key slot remains, so the dump lists 0; every certificate row names an operator, a witness and a verification; and every drive has at least three recorded transfers. On a real SSD, the overwrite result would not be trustworthy for the reasons in the lesson, which is why drive B's method exists.

Notes

luksErase destroys only the key slots, not the encrypted data, which remains as ciphertext that nothing can decrypt. That is exactly how a self-encrypting drive's cryptographic erase works, done here in software where you can see it.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.