This course is using an outdated version of the technology and is now considered to be Legacy content. It will be removed from our catalog on June 28, 2024. Please be sure to complete your course and finish any remaining labs before that date. We recommend moving to version 9.2, which is the latest version currently available.
In this chapter, you learned:
Red Hat Enterprise Linux supports block device encryption with Linux Unified Key Setup (LUKS).
A passphrase is required at boot time to decrypt a LUKS-encrypted block device.
Network Bound Disk Encryption (NBDE) automates the decryption of LUKS-encrypted disks without manually entering a passphrase at boot time.
NBDE uses the Clevis framework on the client (decryption) side, and queries Tang servers to determine if the client is running on a secure network.
The Clevis framework provides binding policies which support the use of multiple Tang servers.
The signature and exchange keys for a Tang server should be rotated periodically.