Bookmark this page

Summary

In this chapter, you learned:

  • Red Hat Enterprise Linux supports block device encryption with Linux Unified Key Setup (LUKS).

  • A passphrase is required at boot time to decrypt a LUKS-encrypted block device.

  • Network Bound Disk Encryption (NBDE) automates the decryption of LUKS-encrypted disks without manually entering a passphrase at boot time.

  • NBDE uses the Clevis framework on the client (decryption) side, and queries Tang servers to determine if the client is running on a secure network.

  • The Clevis framework provides binding policies which support the use of multiple Tang servers.

  • The signature and exchange keys for a Tang server should be rotated periodically.

Revision: rh415-7.5-b847083