-
Notifications
You must be signed in to change notification settings - Fork 10
Installation
Create a bootable UEFI USB —
Before installation —
Secure erasure
Disk partitioning —
Setup disk encryption —
Setup of the LVM
Formatting file systems —
Mounting file systems —
Btrfs subvolumes
After using Ubuntu and Debian for a while, I decided to switch to Arch Linux to provide a simple and lightweight OS. In addition, Arch Linux allows me to keep up to date with the latest versions of packages, which I greatly appreciate.
First of all, you should know that I'm willing to bring a new tutorial to bring my knowledge on some details. After reading about it, I found that the right compromise between safety and comfort was still LVM on LUKS.
The main reason for this choice of encryption is that I like to have a key to unlock all the volumes of the LVM, without going through one (or more) USB keys and risk losing them.
NOTE: don't forget that Arch Wiki remains the ultimate reference.
After this installation, you will have the following disk layout:
+-----------------------------------------------------------------------+ +----------------+
| Logical volume 1 | Logical volume 2 | Logical volume 3 | | Boot partition |
| | | | | |
| [SWAP] | / | /home | | /boot |
| | | | | |
| /dev/MyVolGroup/swap | /dev/MyVolGroup/root | /dev/MyVolGroup/home | | |
|_ _ _ _ _ _ _ _ _ _ _ _|_ _ _ _ _ _ _ _ _ _ _ _|_ _ _ _ _ _ _ _ _ _ _ _| | (may be on |
| | | other device) |
| LUKS2 encrypted partition | | |
| /dev/sda1 | | /dev/sdb1 |
+-----------------------------------------------------------------------+ +----------------+
where only the /boot partition is not encrypted as the bootloader needs to access the /boot directory and thus load the initramfs/encryption modules needed to load the rest of the system.
On the assumption that:
- X is the volume ID;
- Y is the partition ID.
sudo fdisk /dev/sdX
sudo mkfs.vfat -F32 /dev/sdXY
sudo mlabel -i /dev/sdXY ::LABEL
Replace archlinux by the name of your ISO image of Arch Linux:
sudo dd bs=4M if=archlinux.iso of=/dev/sdX status=progress && sync
-
bs(block size): on modern equipment (less than 5 years old), 4MB is a good bet; -
if: source of the ISO image of Arch Linux; -
of: destination to install the ISO image of Arch Linux; -
status: automatically print periodic updates in the standard output.
To do that, checks the following things:
- USB Flash Drive is first on the priority of boot;
- Secure Boot is disabled.
Before proceeding with the installation of Arch Linux, it is important to check if you have:
- an Internet access;
- booted in UEFI mode or not.
To verify that your system has Internet access, you can check it by pinging to any site (e.g. Google):
ping -c 3 www.google.com
To find out if you started in UEFI mode (recommended), simply check that the following command returns a list of defined UEFI variables. Otherwise, it means you have started in BIOS Legacy mode:
efivar -l
Before the disk partitioning we need to avoid cryptographic attacks or unwanted file recovery. This is done by performing a secure erasure from the disk by overwriting the entire drive with random data.
NOTE: overwriting the entire drive with random data can take hours or even days, according to the size of your drive.
If like me you have an SSD, consider performing a SSD memory cell clearing to minimize flash memory cache artifacts. Otherwise, I invite you to directly go to the next section.
Since I use a Lenovo ThinkPad, I have a different name for the SSD:
| SSD name | Commonly used SSD name |
|---|---|
| /dev/nvme0n1 | /dev/sdx |
Replace /dev/nvme0n1 with your SSD name.
hdparm -I /dev/nvme0n1 | grep frozen
If it is indicated non frozen, then you can continue. Otherwise, I invite you to read the documentation and resolve this issue before going any further.
This will allow the SSD to be locked until the next power-up cycle, denying normal access until it is unlocked with the correct password:
dparm --user-master u --security-set-pass ihateWindows /dev/nvme0n1 security_password="ihateWindows"
NOTE: this password is only temporary because after the secure deletion, the password will be reset to NULL.
Before going any further, check that the command below displays enabled:
hdparm -I /dev/nvme0n1
Let's notify the SSD's BIOS to perform its secure erase:
dparm --user-master u --security-erase ihateWindows /dev/nvme0n1
Finally, after a successful deletion, the security of the SSD must be automatically disabled . the command below must displays enabled:
hdparm -I /dev/nvme0n1
Let's fill our disk with random data to protect ourselves in order to protect ourselves against disclosure of usage patterns.
cryptsetup open --type plain -d /dev/urandom /dev/nvme0n1 to_be_wiped
Once done, check that the container exists:
lsblk
dd if=/dev/zero of=/dev/mapper/to_be_wiped bs=4096 status=progress
NOTE: a use of if=/dev/urandom is not required as the encryption cipher is used for randomness.
cryptsetup close to_be_wiped
The partitioning that follows concerns the UEFI installation. Be careful if you want to install Arch Linux in a Legacy BIOS mode.
First of all, I have different names for the partitions, but don't be lost for so little:
| Partition name | Commonly used partition name |
|---|---|
| /dev/nvme0n1p1 | /dev/sdx1 |
| /dev/nvme0n1p2 | /dev/sdx2 |
Our Arch Linux will have two partitions:
| Mount point | Partition name | Partition type | Bootable flag | Suggested size |
|---|---|---|---|---|
| /efi | /dev/nvme0n1p1 | EFI System | Yes | 512 Mo |
| / | /dev/nvme0n1p2 | Linux LVM | No | Remainder of the device |
Where / will be a LVM encrypted partition having a group volume containing a physical volume and two logical volumes:
swaproot
Finally, we will format the root volume in Btrfs and create two sub-volume:
/mnt/root/mnt/home
NOTE: according to Theodore Ts'o, principal developer of ext3 and ext4 file systems, ext4 has improved features, it is not a major advance; it uses old technology and is a stop-gap. He adds that Btrfs is the best direction because "it offersimprovements in scalability, reliability and ease of management".
Without going into details, Btrfs is stable, allows for better data compression, easily handles snapshots and RAIDs.
In order to know the name of your disk, it is necessary to list the partition tables for the specified devices:
fdisk -l
Let's select our disk to build the table:
gdisk /dev/nvme0n1
Then, create a new empty GTP partition table by pressing the o key.
Partition number (1-128, default 1):
First sector (2048-2000409230, default = 2048) or {+-}size{KMGTP}:
Last sector (2048-2000409230, default = 2000409230) or {+-}size{KMGTP}: 512M
Current type is'Linux filesystem'
Hex code or GUID (L to show codes, Enter = 8300): ef00
Changed type of partition to 'EFI System'
Partition number (2-128, default 2):
First sector (1050624-2000409230, default = 1050624) or {+-}size{KMGTP}:
Last sector (1050624-2000409230, default = 2000409230) or {+-}size{KMGTP}:
Current type is'Linux filesystem'Hex code or GUID (L to show codes, Enter = 8300): 8e00
Changed type of partition to'Linux LVM'
Before writing the two partitions, check that they are correct by pressing the p key.
You should have such a partition table:
| Number | Start (sector) | End (sector) | Size | Code | Name |
|---|---|---|---|---|---|
| 1 | 2048 | 1050623 | 512.0 MiB | EF00 | EFI System |
| 2 | 1050624 | 2000409230 | 953.4 GiB | 8E00 | Linux LVM |
Now that the partition table is created, all you have to do is write it to the disk by pressing the w key.
In order to enable disk encryption, we will first create a root LUKS volume, open it and then format it.
To keep it short, LUKS is a container format that will be used to encrypt containers, where our encryption key will be stored.
To encrypt our / partition, we will use the cryptsetup tool:
cryptsetup --hash sha512 --use-random --verify-passphrase luksFormat /dev/nvme0n1p2
Are you sure? YES
Enter passphrase (twice)
NOTE: the majority of current CPU platforms being 64 bits, I recommend using SHA-512 which allows better performance than the SHA-256 for keys of size ≥ 256 bytes (default size for cryptsetup).
The / partition being encrypted, we will open the LUKS container on /dev/nvme0n1p2 disk and name it cryptlvm:
cryptsetup luksOpen /dev/nvme0n1p2 cryptlvm
Enter passphrase
The decrypted container is now available at /dev/mapper/cryptlvm.
LVM is a logical volume manager for the Linux kernel. It is thanks to it that we can easily resize our partitions if necessary.
pvcreate /dev/mapper/cryptlvm
vgcreate MyVolGroup /dev/mapper/cryptlvm
lvcreate -L 24G MyVolGroup -n swap
lvcreate -l 100%FREE MyVolGroup -n root
NOTE: to determine the perfect size for your swap memory, refer to RedHat's recommendation
mkswap /dev/mapper/MyVolGroup-swap
mkfs.fat -F32 /dev/nvme0n1p1
mkfs.btrfs -L btrfs /dev/mapper/MyVolGroup-root
swapon /dev/mapper/MyVolGroup-swap
mount /dev/mapper/MyVolGroup-root /mnt
subvolumes are part of the filesystem with its own and independent file/directory hierarchy, where each subvolumes can share file extents.
NOTE: a snapshot is also subvolume, but with a given initial content of the original subvolume.
btrfs subvolume create /mnt/root
btrfs subvolume create /mnt/home
umount /mnt
mkdir /mnt/{boot,home}
SSD_MOUNTS="autodefrag,compress=lzo,discard,inode_cache,noatime,nodev,rw,space_cache,ssd"
mount -o subvol=root,$SSD_MOUNTS /dev/mapper/MyVolGroup-root /mnt
mount -o subvol=home,$SSD_MOUNTS,nosuid /dev/mapper/MyVolGroup-root /mnt/home
EFI_MOUNTS="discard,noatime,nodev,noexec,nosuid,rw"
mount -o $EFI_MOUNTS /dev/nvme0n1p1 /mnt/boot
Small details on the options given with the -o flag:
-
autodefrag: enable automatic file defragmentation for small random writes in files with a maximum file size of 64K. -
compress=lzo: compresses files with the lzo type which is a lossless data compression algorithm that is focused on decompression speed. -
discard: enable discarding of freed file blocks using TRIM operation (useful for SSD devices). -
inode_cache: enable free inode number caching (may cause an overflow problem when the free space checksums do not match one page). -
noatime: allows measurable performance gains by eliminating the need for the system to write to the file system for files that are simply read. -
nodev: disallows creating and accessing device nodes (used in particular for special files in /dev). -
noexec: does not allow the execution of executable binaries in the mounted file system. -
nosuid: specifies that the filesystem cannot contain set userid files. -
rw: allows reading and writing. -
space_cache: control the free space cache. This greatly improves performance when reading block group free space into memory. -
ssd: by default, Btrfs will enable or disable SSD allocation heuristics depending on whether a rotational or non-rotational device is in use.
NOTE: some of these options are not useful to you, for example if you don't use an SSD.