-
Notifications
You must be signed in to change notification settings - Fork 10
Installation
Create a bootable UEFI USB — Before installation — Disk partitioning — Setup disk encryption
After using Ubuntu and Debian for a while, I decided to switch to Arch Linux to provide a simple and lightweight OS. In addition, Arch Linux allows me to keep up to date with the latest versions of packages, which I greatly appreciate.
First of all, you should know that I'm willing to bring a new tutorial to bring my knowledge on some details. After reading about it, I found that the right compromise between safety and comfort was still LVM on LUKS.
The main reason for this choice of encryption is that I like to have a key to unlock all the volumes of the LVM, without going through one (or more) USB keys and risk losing them.
NOTE: don't forget that Arch Wiki remains the ultimate reference.
After this installation, you will have the following disk layout:
+-----------------------------------------------------------------------+ +----------------+
| Logical volume 1 | Logical volume 2 | Logical volume 3 | | Boot partition |
| | | | | |
| [SWAP] | / | /home | | /boot |
| | | | | |
| /dev/MyVolGroup/swap | /dev/MyVolGroup/root | /dev/MyVolGroup/home | | |
|_ _ _ _ _ _ _ _ _ _ _ _|_ _ _ _ _ _ _ _ _ _ _ _|_ _ _ _ _ _ _ _ _ _ _ _| | (may be on |
| | | other device) |
| LUKS2 encrypted partition | | |
| /dev/sda1 | | /dev/sdb1 |
+-----------------------------------------------------------------------+ +----------------+
where only the /boot partition is not encrypted.
On the assumption that:
- X is the volume ID;
- Y is the partition ID.
sudo fdisk /dev/sdX
sudo mkfs.vfat -F32 /dev/sdXY
sudo mlabel -i /dev/sdXY ::LABEL
Replace archlinux by the name of your ISO image of Arch Linux:
sudo dd bs=4M if=archlinux.iso of=/dev/sdX status=progress && sync
-
bs(block size): on modern equipment (less than 5 years old), 4MB is a good bet; -
if: source of the ISO image of Arch Linux; -
of: destination to install the ISO image of Arch Linux; -
status: automatically print periodic updates in the standard output.
To do that, checks the following things:
- USB Flash Drive is first on the priority of boot;
- Secure Boot is disabled.
Before proceeding with the installation of Arch Linux, it is important to check if you have:
- an Internet access;
- booted in UEFI mode or not.
To verify that your system has Internet access, you can check it by pinging to any site (e.g. Google):
ping -c 3 www.google.com
To find out if you started in UEFI mode (recommended), simply check that the following command returns a list of defined UEFI variables. Otherwise, it means you have started in BIOS Legacy mode:
efivar -l
Before the disk partitioning we need to avoid cryptographic attacks or unwanted file recovery. This is done by performing a secure erasure from the disk by overwriting the entire drive with random data.
NOTE: overwriting the entire drive with random data can take hours or even days, according to the size of your drive.
If like me you have an SSD, consider performing a SSD memory cell clearing to minimize flash memory cache artifacts.
Since I use a Lenovo ThinkPad, I have a different name for the SSD:
| SSD name | Commonly used SSD name |
|---|---|
| /dev/nvme0n1 | /dev/sdx1 |
Replace /dev/nvme0n1 with your SSD name.
hdparm -I /dev/nvme0n1 | grep frozen
If it is indicated non frozen, then you can continue. Otherwise, I invite you to read the documentation and resolve this issue before going any further.
This will allow the SSD to be locked until the next power-up cycle, denying normal access until it is unlocked with the correct password:
dparm --user-master u --security-set-pass ihateWindows /dev/nvme0n1 security_password="ihateWindows"
NOTE: this password is only temporary because after the secure deletion, the password will be reset to NULL.
Before going any further, check that the command below displays enabled:
hdparm -I /dev/nvme0n1
Let's notify the SSD's BIOS to perform its secure erase:
dparm --user-master u --security-erase ihateWindows /dev/nvme0n1
Finally, after a successful deletion, the security of the SSD must be automatically disabled . the command below must displays enabled:
hdparm -I /dev/nvme0n1
The partitioning that follows concerns the UEFI installation. Be careful if you want to install Arch Linux in a Legacy BIOS mode.
First of all, I have different names for the partitions, but don't be lost for so little:
| Partition name | Commonly used partition name |
|---|---|
| /dev/nvme0n1p1 | /dev/sdx1 |
| /dev/nvme0n1p2 | /dev/sdx2 |
Our Arch Linux will have two partitions:
| Mount point | Partition name | Partition type | Bootable flag | Suggested size |
|---|---|---|---|---|
| /efi | /dev/nvme0n1p1 | EFI System | Yes | 512 Mo |
| / | /dev/nvme0n1p2 | Linux LVM | No | Remainder of the device |
Where / will be a LVM encrypted partition having a group volume containing a physical volume and two logical volumes:
swaproot
Finally, we will format the root volume in Btrfs and create two sub-volume:
/mnt/root/mnt/home
NOTE: according to Theodore Ts'o, principal developer of ext3 and ext4 file systems, ext4 has improved features, it is not a major advance; it uses old technology and is a stop-gap. He adds that Btrfs is the best direction because "it offersimprovements in scalability, reliability and ease of management".
Without going into details, Btrfs is stable, allows for better data compression, easily handles snapshots and RAIDs.
In order to know the name of your disk, it is necessary to list the partition tables for the specified devices:
fdisk -l
Let's select our disk to build the table:
gdisk /dev/nvme0n1
Then, create a new empty GTP partition table by pressing the o key.
Partition number (1-128, default 1):
First sector (2048-2000409230, default = 2048) or {+-}size{KMGTP}:
Last sector (2048-2000409230, default = 2000409230) or {+-}size{KMGTP}: 512M
Current type is'Linux filesystem'
Hex code or GUID (L to show codes, Enter = 8300): ef00
Changed type of partition to 'EFI System'
Partition number (2-128, default 2):
First sector (1050624-2000409230, default = 1050624) or {+-}size{KMGTP}:
Last sector (1050624-2000409230, default = 2000409230) or {+-}size{KMGTP}:
Current type is'Linux filesystem'Hex code or GUID (L to show codes, Enter = 8300): 8e00
Changed type of partition to'Linux LVM'
Before writing the two partitions, check that they are correct by pressing the p key.
You should have such a partition table:
| Number | Start (sector) | End (sector) | Size | Code | Name |
|---|---|---|---|---|---|
| 1 | 2048 | 1050623 | 512.0 MiB | EF00 | EFI System |
| 2 | 1050624 | 2000409230 | 953.4 GiB | 8E00 | Linux LVM |
Now that the partition table is created, all you have to do is write it to the disk by pressing the w key.
In order to enable disk encryption, we will first create a root LUKS volume, open it and then format it.
To keep it short, LUKS is a container format that will be used to encrypt containers, where our encryption key will be stored.
To encrypt our / partition, we will use the cryptsetup tool:
cryptsetup --hash sha512 --use-random --verify-passphrase luksFormat /dev/nvme0n1p2
Are you sure? YES
Enter passphrase (twice)
NOTE: the majority of current CPU platforms being 64 bits, I recommend using SHA-512 which allows better performance than the SHA-256 for keys of size ≥ 256 bytes (default size for cryptsetup).
The / partition being encrypted, we will open the LUKS container on /dev/nvme0n1p2 disk and name it cryptlvm:
cryptsetup luksOpen /dev/nvme0n1p2 cryptlvm
Enter passphrase
pvcreate /dev/mapper/cryptlvm
vgcreate MyVolGroup /dev/mapper/cryptlvm
lvcreate -L 8G MyVolGroup -n swap
lvcreate -l 100%FREE MyVolGroup -n root
mkswap /dev/MyVolGroup/swap
mkfs.ext4 /dev/MyVolGroup/root
mkfs.ext4 /dev/MyVolGroup/home
swapon /dev/MyVolGroup/swap
mount /dev/MyVolGroup/root /mnt
mkdir /mnt/home
mount /dev/MyVolGroup/home /mnt/home