dm-crypt is the kernel's transparent block-device encryption (device-mapper target). cryptsetup is its management tool, and LUKS is the standard on-disk header format that holds the key slots. References: dm-crypt (Wikipedia), cryptsetup section.
luksFormatdestroys everything on the target. Confirm the device withlsblkand back up first.
# One-time: create the encrypted container on a partition
sudo cryptsetup luksFormat /dev/sdX1
# Unlock it: creates /dev/mapper/secure
sudo cryptsetup open /dev/sdX1 secure
# Create a filesystem inside (first time only) and mount it
sudo mkfs.ext4 /dev/mapper/secure
sudo mkdir -p /mnt/secure
sudo mount /dev/mapper/secure /mnt/secure
# Lock it again
sudo umount /mnt/secure
sudo cryptsetup close secure
Manage keys¶
sudo cryptsetup luksDump /dev/sdX1 # header info and key slots
sudo cryptsetup luksAddKey /dev/sdX1 # add another passphrase
sudo cryptsetup luksRemoveKey /dev/sdX1 # remove a passphrase
sudo cryptsetup luksHeaderBackup /dev/sdX1 --header-backup-file luks-header.img
Back up the LUKS header and keep it offline: if the header is damaged, the data is unrecoverable even with the right passphrase.
Unlock at boot¶
List the device in /etc/crypttab (by UUID) and the mapped device in /etc/fstab. See mount. For secure disposal of an encrypted disk, destroying the header (luksErase) or all key slots renders the data unreadable, much faster than overwriting the whole disk. See also shred and scrub.