Disk Encryption
Disk encryption is a critical measure for protecting data security. Even if a device is lost or stolen, encrypted data cannot be read by unauthorized parties. This article covers various disk encryption options in Ubuntu 26.04.
The encryption password is the only credential for accessing your data. If you forget the password and have no backup key file or LUKS header backup, encrypted data will be permanently unrecoverable. Be sure to save your password in a password manager and store a LUKS header backup in a secure external location.
LUKS Full-Disk Encryption
LUKS (Linux Unified Key Setup) is the standard disk encryption solution for Linux.
Enabling Full-Disk Encryption During Installation
Enabling full-disk encryption during Ubuntu 26.04 installation is the simplest approach:
- Start the installer
- In the “Installation type” step, select “Advanced features”
- Check “Use LVM” and “Encrypt the installation for security”
- Set an encryption password (be sure to remember it)
- Complete the installation
After installation, you will need to enter the encryption password at every boot to unlock the disk.
TPM-backed Full-Disk Encryption (TPM-backed FDE)
The Ubuntu 26.04 desktop installer supports TPM-backed full-disk encryption: the encryption key is sealed into the motherboard’s TPM 2.0 chip and bound to Secure Boot measurements. At boot, if the system integrity is intact, the TPM releases the key to unlock the disk automatically, without requiring a password every time.
Enabling During Installation
- In the installer’s “Installation type” step, enable full-disk encryption
- If a usable TPM 2.0 is detected and Secure Boot is enabled, the installer offers an option to “unlock with this computer’s TPM”
- The installer generates a recovery key — store it offline; it is the only fallback when the TPM cannot unlock the disk
The TPM-sealed key is bound to boot measurements. Replacing the motherboard, clearing the TPM, disabling Secure Boot, or a major firmware update can cause the TPM to refuse to unlock. In that case you must use the recovery key to unlock manually, or the data is inaccessible. Keep the recovery key in a secure location separate from the device.
Starting with 26.04.1, the mandatory TPM/FDE PIN can be disabled on hardware whose firmware cannot be verified automatically. The official documentation warns that this lowers protection against firmware tampering, so decide based on your threat model.
Viewing and Managing TPM FDE Status
# Check whether a TPM device is present
ls /dev/tpm* 2>/dev/null
sudo systemd-cryptenroll --tpm2-device=list
# View the unlock methods bound to a LUKS device (password / TPM / recovery key)
sudo systemd-cryptenroll /dev/sda3
# Re-seal / rotate the TPM binding (e.g., after a firmware update)
sudo systemd-cryptenroll --wipe-slot=tpm2 --tpm2-device=auto /dev/sda3On the desktop, you can also view the FDE/TPM status and confirm whether the recovery key has been backed up in the Security Center.
Checking Encryption Status
# View LUKS devices
sudo dmsetup status
# View LUKS details
sudo cryptsetup luksDump /dev/sda3
# View encrypted volume status
sudo cryptsetup status luks-volume-name
# View block devices and encryption relationships
lsblk -fEncrypting External Storage Devices
Encrypting a USB Drive with LUKS
# Confirm the device name (very important -- avoid encrypting the wrong device)
lsblk
# Encrypt the partition (this will erase all data!)
sudo cryptsetup luksFormat /dev/sdb1
# Confirm by typing YES (uppercase), then set a password
# Open the encrypted partition
sudo cryptsetup luksOpen /dev/sdb1 encrypted_usb
# Format
sudo mkfs.ext4 /dev/mapper/encrypted_usb
# Mount
sudo mkdir -p /mnt/encrypted
sudo mount /dev/mapper/encrypted_usb /mnt/encrypted
# Unmount when done
sudo umount /mnt/encrypted
sudo cryptsetup luksClose encrypted_usbDaily Use of Encrypted USB Devices
In the GNOME desktop environment, a password prompt will automatically appear when you plug in an encrypted USB device. Command-line operations:
# Open the encrypted device
sudo cryptsetup luksOpen /dev/sdb1 encrypted_usb
# Mount
sudo mount /dev/mapper/encrypted_usb /mnt/encrypted
# ... use ...
# Unmount and close
sudo umount /mnt/encrypted
sudo cryptsetup luksClose encrypted_usbLUKS Key Management
Adding Keys
Ubuntu 26.04 uses LUKS2 by default, which supports up to 32 key slots (LUKS1 supported only 8, 0-7):
# Add a new password
sudo cryptsetup luksAddKey /dev/sda3
# You must first enter an existing password, then enter the new one
# Add a key file
sudo dd if=/dev/urandom of=/root/luks-keyfile bs=4096 count=1
sudo chmod 600 /root/luks-keyfile
sudo cryptsetup luksAddKey /dev/sda3 /root/luks-keyfileRemoving Keys
# Remove a specific key slot
sudo cryptsetup luksKillSlot /dev/sda3 1
# Remove a specific password (enter the password to remove)
sudo cryptsetup luksRemoveKey /dev/sda3Viewing Key Slot Status
sudo cryptsetup luksDump /dev/sda3 | grep "Key Slot"
# Example output:
# Key Slot 0: ENABLED
# Key Slot 1: ENABLED
# Key Slot 2: DISABLED
# ...Changing a Password
# Change an existing password
sudo cryptsetup luksChangeKey /dev/sda3
# Enter the old password first, then enter the new oneAuto-Unlock with Key Files
Configuring Auto-Unlock for Data Partitions
If the system disk is already encrypted, you can use a key file to automatically unlock data partitions after the system disk is unlocked:
# Generate a key file
sudo dd if=/dev/urandom of=/root/.luks-data-key bs=4096 count=1
sudo chmod 400 /root/.luks-data-key
# Add the key file to the LUKS device
sudo cryptsetup luksAddKey /dev/sdb1 /root/.luks-data-key
# Get the UUID
sudo blkid /dev/sdb1
# Configure /etc/crypttab
sudo nano /etc/crypttabAdd to /etc/crypttab:
# <name> <device> <key file> <options>
data_encrypted UUID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx /root/.luks-data-key luksAdd mount configuration to /etc/fstab:
/dev/mapper/data_encrypted /mnt/data ext4 defaults 0 2# Test the configuration
sudo cryptdisks_start data_encrypted
sudo mount /mnt/dataEncrypting the Home Directory
Using fscrypt for Home Directory Encryption
Ubuntu 26.04 recommends fscrypt for directory-level encryption:
# Install fscrypt
sudo apt install fscrypt libpam-fscrypt
# Initialize fscrypt (on the filesystem)
sudo fscrypt setup
sudo fscrypt setup /home
# Encrypt a new user's home directory
sudo fscrypt encrypt /home/newuser --user=newuserEnabling Encryption for Existing Directories
# Create an encrypted directory
mkdir ~/Private
fscrypt encrypt ~/Private
# Choose a protection method (password, PAM login, etc.)
# PAM login protection is recommended -- auto-unlocks on login
# Lock the directory
fscrypt lock ~/Private
# Unlock the directory
fscrypt unlock ~/Private
# Check encryption status
fscrypt status ~/PrivateEncrypting Swap
Encrypting Swap with a Random Key
# Edit /etc/crypttab
sudo nano /etc/crypttabAdd:
cryptswap /dev/sdXN /dev/urandom swap,cipher=aes-xts-plain64,size=256Update /etc/fstab:
/dev/mapper/cryptswap none swap sw 0 0Using a Swap File (on a LUKS-Encrypted Disk)
If the system already uses LUKS full-disk encryption, the swap file is already protected by encryption:
# Create a swap file
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
# Persist
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstabLUKS Performance Optimization
Checking Encryption Performance
# View current encryption algorithm
sudo cryptsetup luksDump /dev/sda3 | grep "Cipher"
# Benchmark encryption performance
sudo cryptsetup benchmark
# Example output:
# PBKDF2-sha1 1200000 iterations per second
# PBKDF2-sha256 800000 iterations per second
# Algorithm | Key | Encryption | Decryption
# aes-cbc 128b 1200.0 MiB/s 3500.0 MiB/s
# aes-cbc 256b 900.0 MiB/s 2800.0 MiB/s
# aes-xts 256b 2500.0 MiB/s 2600.0 MiB/s
# aes-xts 512b 2100.0 MiB/s 2200.0 MiB/sOptimization Options
# Use AES-NI hardware acceleration (most modern CPUs support it)
grep aes /proc/cpuinfo
# Specify high-performance parameters when creating an encrypted partition
sudo cryptsetup luksFormat --type luks2 --cipher aes-xts-plain64 --key-size 512 --hash sha256 /dev/sdb1Backing Up the Encryption Header
LUKS header corruption can lead to complete data loss; always back it up:
# Back up the LUKS header
sudo cryptsetup luksHeaderBackup /dev/sda3 --header-backup-file /safe/location/luks-header-backup
# Restore the LUKS header (for data recovery)
sudo cryptsetup luksHeaderRestore /dev/sda3 --header-backup-file /safe/location/luks-header-backupStore the LUKS header backup in a secure external location (such as a USB device in a safe).
Emergency Data Erasure
If you need to urgently destroy encrypted data:
# Wipe the LUKS header (data will be permanently unrecoverable!)
sudo cryptsetup luksErase /dev/sda3
# Or overwrite the LUKS header area
sudo dd if=/dev/urandom of=/dev/sda3 bs=1M count=2This takes only a few seconds because you only need to destroy the encryption keys, not erase all the data.
Troubleshooting
Forgotten Password
If you have forgotten the LUKS password and have no backup key file, the data cannot be recovered. Preventive measures:
- Save the encryption password in a password manager
- Set up multiple key slots as backups
- Back up the LUKS header
Unable to Unlock at Boot
# Boot from a Live USB
# Open the encrypted partition
sudo cryptsetup luksOpen /dev/sda3 recovery
# Mount
sudo mount /dev/mapper/recovery /mnt
# Check and repair
sudo fsck /dev/mapper/recovery
# When done
sudo umount /mnt
sudo cryptsetup luksClose recovery