Help needed, new install, FDE+ Keyfile/Passphrase+ Yubikey

I currently have Endeavor running for the last 3 years.

It runs great with no issues whatsoever.

I want to install luks FDE as I have no protection now.

Ultimate goal is something very secure.

Through my reading the password is the weakest point, but Yubikey and keyfiles also have weakness. I am thinking a passphrase + Yubikey I wear around my neck would be good enough. Unless others here think different. I have read up on how to setup the new install but its a bit over my head. Is there someone here that can walk me through it and maybe help if I get stuck?

I would also like an opinion on the security of the above lockdown methods.

Thanks

Why the heck do you need that kind of security? “Very Secure” is very user-unfriendly. (Op)security is the natural enemy of usability. If you really need that amount of protection I would use something that is tailored for exactly that.

Let me guess, you have nothing to hide so let them look.

Anyone else?

Looking for a systemd-cryptsetup

Luks2

Argon2

Enforced touch fido2 challange-Yubikey

Do you always treat someone who wants to help like this? I guess I am out of here, enough internets for today…

Help? I didnt read that as help. Did you read my reply as help?

Maybe google “fog reveal”. The app fedgov uses without search warrants to track 300 million people for the last 14 years of your every move. Guilty until their illegal tracking proves you innocent.

And if you have “nothing” to hide, who decides what “nothing” means? The current president might not have the same meaning as a communist dictator.

I should just ask AI to give me a step by step I guess. Asking a simple question in a forum has now become a 3 page argument instead of a simple answer. You act as if I asked for a weeks work when a simple answer would suffice. Youve already wasted more time arguing.

“NEED” isnt a reason.

Do people with cars that do 200mph NEED that speed?

Same goes for 200mph motorcycles, boats that do 150, 50 bmg rifles that shoot 3 miles, etc. No one NEEDS that, they want it. But I can see you do not believe in freedom.

Let me guess, your password is “password” or “12345”?

And for the record there are 100’s of thousands of people with the same setup I asked about. Should we ask all of them why they “need” it?

Most of my computers don’t have passwords because they are air gapped and if someone has local access to those machines I have much greater concerns.

Your attitude is poor but if you are serious I’ve no doubt someone will still be willing to help you. Sorry but you rubbed me the wrong way instantly.

You “rubbed” me the wrong way with your first reply. Being tracked by AD-ID every where I go for 15 years “rubs me the wrong way”. Having phones that listen to our every word “rubs me the wrong way”. Having to use vpns and encrypted dns so the internet providers doesnt monitor my every key stroke “rubs me the wrong way”. Having flock cameras on every corner “rubs me the wrong way”. Having all my meta data stored in data centers “rubs me the wrong way”.

Do I need to continue?

Do you have a deadbolt on your front door? No one needs that kind of security and if they do they know exactly what they are doing.

Hi @ogi,

first of all, a warm welcome to the EndeavourOS community! It’s great to hear that your current installation has been running smoothly for 3 years.

To get your thread back on a constructive track and focus on the technical implementation, let’s leave the philosophical debate aside. Everyone has different threat models and security requirements, and wanting a robust Full Disk Encryption (FDE) setup with physical multi-factor authentication (like a Yubikey via FIDO2/systemd-cryptsetup) is a completely valid goal.

To help the community guide you through the setup without getting stuck, could you provide a bit more technical detail on your current plan?

If you can share these details, i am sure it will be possible to help.

I’m no master of security, but what if you lose your key? Do you have backup or other means of getting into your computer? Because otherwise you are going to have an expensive anchor. Eons ago I was taught simple rule: “One is zero, two is one etc.” This was on backups, but I think it goes with this one as well.

I say this because I am expert on misplacing my things and then I spend sometimes great amount of time for looking them. I fret about losing my keys, so I can’t imagine myself putting access to my computer into something that I can lose or that can get stolen.

So my advice is that whatever you choose as your security solution, always have some other way to have access your files.

I have two fido2 gen 5 keys.

I can probably do most if not all of what is required. AI said that having a “forced touch” requirement of the Yubikey would effectively stop brute force attacks. It also said to use systemd instead of grub. It said argon2 and fido2 were what I wanted with enforced yubikey touch and not to leave the key in a slot.

I have a 1tb ssd laptop that I will install this on. Its going to be blank when I start off. I can get AI to give me a step by step. Should I just get the steps and post back here to see if its correct. I am fine with cmd line stuff so I really just needed someone to make sure I was on the right track and not making a mistake that leaves a vulnerability open like grub vs systemd.

I’m posting this in case anyone else wants to have a secure machine. AI talked me out of yubikey + passphrase being required because of a custom install and possible update issues. Instead it said using ONLY a yubikey + touch + LONG pin would be just as secure and a much simpler install. The long pin is guarded by an 8 strikes your out yubikey hardware lock. So no one gets to guess more then 8x before the laptop is a brick, an encrypted brick with no encryption possible.

Core security setup (unchanged)

  • UEFI boot only
  • LUKS2 full-disk encryption
  • Argon2id
  • systemd-cryptsetup
  • FIDO2 unlock with:
    • YubiKey #1
    • YubiKey #2
    • long FIDO2 PIN
    • touch required
  • Secure Boot
  • Signed UKIs

Welcome @ogi :waving_hand::smiley: :enos_flag:

I use LUKS2 full-disk encryption on most of my systems. In terms of the threat model, I’ve misplaced laptops in the past (left one on the air-plane) and have been broken into twice and had items stolen.

Not quite knowing what someone might have access to in those situations, is a legitimate concern.

Having full-disk encryption in place, means even in the event of theft, or loss, you know your sensitive data is not compromised.

Now in terms of implementation, I’ve generally opted for a passphrase-only. A short not-at-all obvious sentence is virtually un-crackable with modern hardware. It would require an unfeasible amount of resources and time to brute-force a LUKS2 (Argon2id) encrypted device (like millions+ years) with a short sentence-like passphrase.

I’m not familiar with the YubiKey’s, so if what you’re suggesting is that mis-using the YubiKey results in a bricked laptop, that’s an extreme measure that could easily work against you. For example, a kid, a curious nephew perhaps, decides to give it a try and fails 8 times: :brick:

Of course, you know better than us the threats you’re dealing with, but that one’s up there with secret agent level precaution :detective:

Uh looks like some work to set up.
I have a yubikey too, not research much on using it to unlock OS. UKI and secure boot can be setup on top of a EndeavorOS install.. and installer supports encrypted installs, plus installer has tons of manual setup options

Would be interesting to get details on how yubikey unlock actually will be done? Would this need hardware encrypted drive? What if someone extract hard drive from the notebook?

Or three-year old, who, when on specific mood, likes to smash keyboard when walking by. :keyboard: :see_no_evil_monkey:

If you are unlocking the LUKS device at boot with systemd (you probably are unless using GRUB instead), it’s pretty easy to configure a keyslot to use your Yubikey. Check out systemd-cryptenroll, which allows enrolling smartcards, FIDO2 tokens, and TPM chips into LUKS devices.

The explanation in the ArchWiki article is reasonably straightforward (there are only a few commands involved). There are also some examples at the bottom of the crypttab man page: https://man.archlinux.org/man/crypttab.5.en#EXAMPLES. If you get stuck, put your notes here into the thread and someone will take a look.

Note that adding a keyslot for your Yubikey, or any other keyslot, adds an additional method which can be used to unlock the device–not must be used. If you have a passphrase keyslot as well, either the passphrase or the Yubikey will unlock the device. You cannot set it up to require both.

If your Yubikey can be configured with a PIN, using the PIN with LUKS unlock is supported. Also keep in mind unless you have configured autologin, you still need to enter a passphrase to get past the display manager.

OK thanks. “You cannot set it up to require both.” I got open AI to write the step by step to actually do just that. I am going to practice once on a usb external drive.

OK, I am actually trying to find only that section to post. I will have to clarify with AI.

I am thinking using a 63 character PIN with required yubikey would serve as a 2FA and be good enough.

So propmt to insert Yubikey, Prompt for 63 character PIN, prompt for touch.

“FIDO2 PINs can be up to 63 alphanumeric characters (in other words, letters and numbers). For YubiKeys from the 5 FIPS Series,”

OK here is the section that requires BOT not either or…

FROM FREE -AI

You can configure Linux (specifically using systemd-cryptsetup or cryptsetup) to require both a LUKS2 passphrase AND a YubiKey (via FIDO2/U2F or PAM) to unlock the disk. This is known as “two-factor authentication” for disk encryption.

How it works

  1. LUKS2 Header: The LUKS2 header supports multiple keyslots. You can assign the passphrase to one keyslot and the YubiKey credential to another.
  2. Key Requirements: By default, LUKS2 only requires one valid keyslot to unlock. To require both, you need an additional layer that enforces the “AND” logic.
  3. Enforcement: This is typically done via:
    systemd-cryptsetup with luks2 and specific options.
    PAM (Pluggable Authentication Modules) in combination with cryptsetup.
    *Custom scripts or udev rules that check for both conditions before proceeding.

Recommended Approach: systemd-cryptsetup + PAM

The most robust and standard way on modern Linux distributions (like Fedora, Ubuntu, Debian) is to use systemd-cryptsetup along with PAM to enforce two-factor authentication.

Steps:

  1. Add YubiKey to LUKS2 (optional but recommended):*
    sudo cryptsetup luksAddKey /dev/sdX /dev/your-yubikey-device
    

Note: You can also use FIDO2/U2F directly with cryptsetup luksAddToken.*

  1. Configure PAM for Two-Factor:
    Edit /etc/pam.d/system-auth or /etc/pam.d/login to require both password and YubiKey. Example:*
    auth required pam_unix.so
    auth required pam_u2f.so cue
    

This ensures that even if someone steals your password, they can’t unlock the system without the YubiKey.

  1. Use systemd-cryptsetup with luks2:
    In /etc/crypttab, ensure your encrypted device uses luks2 and that the keyfile/passphrase is required. The PAM configuration above will enforce the second factor during the login process, which triggers the decryption.

Alternative: FIDO2/U2F Directly with cryptsetup

Newer versions of cryptsetup support FIDO2/U2F tokens directly as LUKS2 tokens. You can add a FIDO2 token and then configure the system to require both the passphrase and the token.
*

sudo cryptsetup luksAddToken /dev/sdX --token-id 0 --token-type fido2-with-pin

By also adding a strong PIN on your Yubikey they cannot use it wihout the PIN. So it becomes 3FA. A bit of overkill I guess. The yubikey PIN has a 8 guess brick mode. After 8 the key locks forever. Which totally screws over brute forcing.

AI said the entropy of a long and strong passphrase was the most important.