<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Encryption on Kohanyi News</title><link>https://kohanyi.net/tags/encryption/</link><description>Recent content in Encryption on Kohanyi News</description><generator>Hugo</generator><language>en-us</language><copyright>&lt;a href="https://creativecommons.org/licenses/by-sa/4.0/" target="_blank" rel="noopener"&gt;CC BY-SA 4.0&lt;/a&gt;</copyright><lastBuildDate>Wed, 19 Aug 2026 09:30:00 +0000</lastBuildDate><atom:link href="https://kohanyi.net/tags/encryption/index.xml" rel="self" type="application/rss+xml"/><item><title>Debian with Encrypted Root and Automatic Unlock via Tang + Clevis</title><link>https://kohanyi.net/posts/2026/08/debian-with-encrypted-root-and-automatic-unlock-via-tang--clevis/</link><pubDate>Wed, 19 Aug 2026 09:30:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/debian-with-encrypted-root-and-automatic-unlock-via-tang--clevis/</guid><description>&lt;p&gt;A recipe for installing Debian with a LUKS-encrypted root filesystem and&#10;configuring it to unlock automatically at boot using Tang and Clevis&#10;(Network-Bound Disk Encryption).&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; This process will nuke all data on the drives you&#10;target. Back up anything you want to keep before you start.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;This works on plain ext4 on LUKS (Part 1 below) and on&#10;&lt;a href="https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/"&gt;ZFS on LUKS&lt;/a&gt;&#10;equally &amp;ndash; Clevis binds to the LUKS layer regardless of what is on top.&lt;/p&gt;</description></item><item><title>Debian 13 with Encrypted ZFS Root (ZFS on LUKS)</title><link>https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/</link><pubDate>Wed, 19 Aug 2026 09:00:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/</guid><description>&lt;p&gt;A step-by-step recipe for installing Debian 13 (Trixie) with a fully encrypted root filesystem using ZFS on top of LUKS.&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; This process will nuke all data on the drives you target. Back up anything you want to keep before you start.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;This gives you the integrity and snapshot features of ZFS, with the whole disk encrypted at rest. I use this on my home servers and VPS instances.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="prerequisites"&gt;Prerequisites&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Debian 13 &lt;strong&gt;Live&lt;/strong&gt; ISO (the standard live image, not the netinst)&lt;/li&gt;&#10;&lt;li&gt;Two disks for a mirror, or one disk if you are starting small&lt;/li&gt;&#10;&lt;li&gt;UEFI boot (recommended for modern systems)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="why-not-just-zfs-native-encryption"&gt;Why not just ZFS native encryption?&lt;/h2&gt;&#10;&lt;p&gt;ZFS native encryption (zencrypt) exists and works. But LUKS gives you a battle-tested crypto layer that GRUB, initramfs, and every Linux tool understand natively. Combined with ZFS on top, you get the best of both worlds.&lt;/p&gt;</description></item></channel></rss>