Encrypted Home Directory Offered to All Users
The Encrypted Home Directory option is currently only available in the alternate installer, or on the desktop installer *with a preseed option* (user-setup/
This was pulled from the Jaunty desktop installer due to a few minor usability concerns. This Blueprint suggests that we define those concerns now, and show this option in the Karmic desktop installer.
Discussion Points:
* security: need encrypted swap space (see ecryptfs-
* usability: need a very clean mechanism for getting the user to record their randomly generated passphrase (currently implementation is passable, but could be improved)
* usability: need a couple of graphic utilities for managing some options (see other blueprint for Jaunty, ecryptfs-ui)
* migration: would be nice to offer a migration utility for enabling/disabling encrypted-home after installation
* security: create a 700 ~/Private directory for all users. expose an easy option to set this up for encryption (if home is not already encrypted). ensure that ~/Private is translatable (xdg-user-dirs?)
* install ecryptfs-utils by default on all ubuntu servers and desktops, such that users can run ecryptfs-
* ... anything else?
:-Dustin
Blueprint information
- Status:
- Complete
- Approver:
- Rick Clark
- Priority:
- Undefined
- Drafter:
- Dustin Kirkland
- Direction:
- Needs approval
- Assignee:
- Dustin Kirkland
- Definition:
- Approved
- Series goal:
- Proposed for karmic
- Implementation:
- Implemented
- Milestone target:
- karmic-alpha-5
- Started by
- Dustin Kirkland
- Completed by
- Dustin Kirkland
Related branches
Related bugs
Whiteboard
= Status =
* Encrypted Swap is now in the desktop installer
* Time for testing!
-- Dustin Kirkland
Infrastructure needed:
* encrypted swap
* ui utilities
* remove liboobs (which breaks encrypted private/home on forced password change)
* in graphical adduser utility, should offer an encrypted home option
* migration utility? (should not block on this)
* better internationaliz
Installer:
* unify encryption options, e.g. a radio button showing: none, whole-disk, home directory, ~/Private
* Consider allowing selection of password-assisted swap encryption (luks based) so that hibernation works again -- Miron Cuperman
Bugs:
* https:/
* https:/
Work Items
Dependency tree
* Blueprints in grey have been implemented.