Comment on Simple safe encryption for a server?
thayer@lemmy.ca 5 months ago
As mentioned elsewhere, the easiest method is to encrypt only the data drives. This way you can secure shell into the server upon restart and decrypt the data. I’ve been using this method for years now without issue.
ShortN0te@lemmy.ml 4 months ago
I am not seeing any benefit over this solution lemmings.world/comment/10027984 , were even the root is encrypted. With dropbear installed on initramfs you can also just ssh into the server to unlock everything.
thayer@lemmy.ca 4 months ago
The dropbear method is more secure overall, and I plan to incorporate it as well when I find the time to wipe/reinstall my server, but it’s arguably not as easy or simple, which is what OP requested.