Skip to Content

Disk Encryption

Disk encryption is a critical measure for protecting data security. Even if a device is lost or stolen, encrypted data cannot be read by unauthorized parties. This article covers various disk encryption options in Ubuntu 26.04.

Caution

The encryption password is the only credential for accessing your data. If you forget the password and have no backup key file or LUKS header backup, encrypted data will be permanently unrecoverable. Be sure to save your password in a password manager and store a LUKS header backup in a secure external location.

LUKS Full-Disk Encryption

LUKS (Linux Unified Key Setup) is the standard disk encryption solution for Linux.

Enabling Full-Disk Encryption During Installation

Enabling full-disk encryption during Ubuntu 26.04 installation is the simplest approach:

  1. Start the installer
  2. In the “Installation type” step, select “Advanced features”
  3. Check “Use LVM” and “Encrypt the installation for security”
  4. Set an encryption password (be sure to remember it)
  5. Complete the installation

After installation, you will need to enter the encryption password at every boot to unlock the disk.

TPM-backed Full-Disk Encryption (TPM-backed FDE)

The Ubuntu 26.04 desktop installer supports TPM-backed full-disk encryption: the encryption key is sealed into the motherboard’s TPM 2.0 chip and bound to Secure Boot measurements. At boot, if the system integrity is intact, the TPM releases the key to unlock the disk automatically, without requiring a password every time.

Enabling During Installation

  1. In the installer’s “Installation type” step, enable full-disk encryption
  2. If a usable TPM 2.0 is detected and Secure Boot is enabled, the installer offers an option to “unlock with this computer’s TPM”
  3. The installer generates a recovery key — store it offline; it is the only fallback when the TPM cannot unlock the disk
Caution

The TPM-sealed key is bound to boot measurements. Replacing the motherboard, clearing the TPM, disabling Secure Boot, or a major firmware update can cause the TPM to refuse to unlock. In that case you must use the recovery key to unlock manually, or the data is inaccessible. Keep the recovery key in a secure location separate from the device.

Note

Starting with 26.04.1, the mandatory TPM/FDE PIN can be disabled on hardware whose firmware cannot be verified automatically. The official documentation warns that this lowers protection against firmware tampering, so decide based on your threat model.

Viewing and Managing TPM FDE Status

# Check whether a TPM device is present ls /dev/tpm* 2>/dev/null sudo systemd-cryptenroll --tpm2-device=list # View the unlock methods bound to a LUKS device (password / TPM / recovery key) sudo systemd-cryptenroll /dev/sda3 # Re-seal / rotate the TPM binding (e.g., after a firmware update) sudo systemd-cryptenroll --wipe-slot=tpm2 --tpm2-device=auto /dev/sda3

On the desktop, you can also view the FDE/TPM status and confirm whether the recovery key has been backed up in the Security Center.

Checking Encryption Status

# View LUKS devices sudo dmsetup status # View LUKS details sudo cryptsetup luksDump /dev/sda3 # View encrypted volume status sudo cryptsetup status luks-volume-name # View block devices and encryption relationships lsblk -f

Encrypting External Storage Devices

Encrypting a USB Drive with LUKS

# Confirm the device name (very important -- avoid encrypting the wrong device) lsblk # Encrypt the partition (this will erase all data!) sudo cryptsetup luksFormat /dev/sdb1 # Confirm by typing YES (uppercase), then set a password # Open the encrypted partition sudo cryptsetup luksOpen /dev/sdb1 encrypted_usb # Format sudo mkfs.ext4 /dev/mapper/encrypted_usb # Mount sudo mkdir -p /mnt/encrypted sudo mount /dev/mapper/encrypted_usb /mnt/encrypted # Unmount when done sudo umount /mnt/encrypted sudo cryptsetup luksClose encrypted_usb

Daily Use of Encrypted USB Devices

In the GNOME desktop environment, a password prompt will automatically appear when you plug in an encrypted USB device. Command-line operations:

# Open the encrypted device sudo cryptsetup luksOpen /dev/sdb1 encrypted_usb # Mount sudo mount /dev/mapper/encrypted_usb /mnt/encrypted # ... use ... # Unmount and close sudo umount /mnt/encrypted sudo cryptsetup luksClose encrypted_usb

LUKS Key Management

Adding Keys

Ubuntu 26.04 uses LUKS2 by default, which supports up to 32 key slots (LUKS1 supported only 8, 0-7):

# Add a new password sudo cryptsetup luksAddKey /dev/sda3 # You must first enter an existing password, then enter the new one # Add a key file sudo dd if=/dev/urandom of=/root/luks-keyfile bs=4096 count=1 sudo chmod 600 /root/luks-keyfile sudo cryptsetup luksAddKey /dev/sda3 /root/luks-keyfile

Removing Keys

# Remove a specific key slot sudo cryptsetup luksKillSlot /dev/sda3 1 # Remove a specific password (enter the password to remove) sudo cryptsetup luksRemoveKey /dev/sda3

Viewing Key Slot Status

sudo cryptsetup luksDump /dev/sda3 | grep "Key Slot" # Example output: # Key Slot 0: ENABLED # Key Slot 1: ENABLED # Key Slot 2: DISABLED # ...

Changing a Password

# Change an existing password sudo cryptsetup luksChangeKey /dev/sda3 # Enter the old password first, then enter the new one

Auto-Unlock with Key Files

Configuring Auto-Unlock for Data Partitions

If the system disk is already encrypted, you can use a key file to automatically unlock data partitions after the system disk is unlocked:

# Generate a key file sudo dd if=/dev/urandom of=/root/.luks-data-key bs=4096 count=1 sudo chmod 400 /root/.luks-data-key # Add the key file to the LUKS device sudo cryptsetup luksAddKey /dev/sdb1 /root/.luks-data-key # Get the UUID sudo blkid /dev/sdb1 # Configure /etc/crypttab sudo nano /etc/crypttab

Add to /etc/crypttab:

# <name> <device> <key file> <options> data_encrypted UUID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx /root/.luks-data-key luks

Add mount configuration to /etc/fstab:

/dev/mapper/data_encrypted /mnt/data ext4 defaults 0 2
# Test the configuration sudo cryptdisks_start data_encrypted sudo mount /mnt/data

Encrypting the Home Directory

Using fscrypt for Home Directory Encryption

Ubuntu 26.04 recommends fscrypt for directory-level encryption:

# Install fscrypt sudo apt install fscrypt libpam-fscrypt # Initialize fscrypt (on the filesystem) sudo fscrypt setup sudo fscrypt setup /home # Encrypt a new user's home directory sudo fscrypt encrypt /home/newuser --user=newuser

Enabling Encryption for Existing Directories

# Create an encrypted directory mkdir ~/Private fscrypt encrypt ~/Private # Choose a protection method (password, PAM login, etc.) # PAM login protection is recommended -- auto-unlocks on login # Lock the directory fscrypt lock ~/Private # Unlock the directory fscrypt unlock ~/Private # Check encryption status fscrypt status ~/Private

Encrypting Swap

Encrypting Swap with a Random Key

# Edit /etc/crypttab sudo nano /etc/crypttab

Add:

cryptswap /dev/sdXN /dev/urandom swap,cipher=aes-xts-plain64,size=256

Update /etc/fstab:

/dev/mapper/cryptswap none swap sw 0 0

Using a Swap File (on a LUKS-Encrypted Disk)

If the system already uses LUKS full-disk encryption, the swap file is already protected by encryption:

# Create a swap file sudo fallocate -l 4G /swapfile sudo chmod 600 /swapfile sudo mkswap /swapfile sudo swapon /swapfile # Persist echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

LUKS Performance Optimization

Checking Encryption Performance

# View current encryption algorithm sudo cryptsetup luksDump /dev/sda3 | grep "Cipher" # Benchmark encryption performance sudo cryptsetup benchmark # Example output: # PBKDF2-sha1 1200000 iterations per second # PBKDF2-sha256 800000 iterations per second # Algorithm | Key | Encryption | Decryption # aes-cbc 128b 1200.0 MiB/s 3500.0 MiB/s # aes-cbc 256b 900.0 MiB/s 2800.0 MiB/s # aes-xts 256b 2500.0 MiB/s 2600.0 MiB/s # aes-xts 512b 2100.0 MiB/s 2200.0 MiB/s

Optimization Options

# Use AES-NI hardware acceleration (most modern CPUs support it) grep aes /proc/cpuinfo # Specify high-performance parameters when creating an encrypted partition sudo cryptsetup luksFormat --type luks2 --cipher aes-xts-plain64 --key-size 512 --hash sha256 /dev/sdb1

Backing Up the Encryption Header

LUKS header corruption can lead to complete data loss; always back it up:

# Back up the LUKS header sudo cryptsetup luksHeaderBackup /dev/sda3 --header-backup-file /safe/location/luks-header-backup # Restore the LUKS header (for data recovery) sudo cryptsetup luksHeaderRestore /dev/sda3 --header-backup-file /safe/location/luks-header-backup

Store the LUKS header backup in a secure external location (such as a USB device in a safe).

Emergency Data Erasure

If you need to urgently destroy encrypted data:

# Wipe the LUKS header (data will be permanently unrecoverable!) sudo cryptsetup luksErase /dev/sda3 # Or overwrite the LUKS header area sudo dd if=/dev/urandom of=/dev/sda3 bs=1M count=2

This takes only a few seconds because you only need to destroy the encryption keys, not erase all the data.

Troubleshooting

Forgotten Password

If you have forgotten the LUKS password and have no backup key file, the data cannot be recovered. Preventive measures:

  • Save the encryption password in a password manager
  • Set up multiple key slots as backups
  • Back up the LUKS header

Unable to Unlock at Boot

# Boot from a Live USB # Open the encrypted partition sudo cryptsetup luksOpen /dev/sda3 recovery # Mount sudo mount /dev/mapper/recovery /mnt # Check and repair sudo fsck /dev/mapper/recovery # When done sudo umount /mnt sudo cryptsetup luksClose recovery
Last updated on