Bug 1438413 - Add option to encrypt a user's home directory
Add option to encrypt a user's home directory
Status: NEW
Product: Fedora
Classification: Fedora
Component: anaconda (Show other bugs)
26
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Anaconda Maintenance Team
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-04-03 07:48 EDT by Jan Niklas Hasse
Modified: 2017-11-10 02:24 EST (History)
9 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Niklas Hasse 2017-04-03 07:48:16 EDT
Description of problem:
Currently it's only possible to enable full disk encryption when installing Fedora. An option to encrypt only the user's home directory would be helpful for workstations with multiple user accounts.

Additional info:
A guide how to manually encrypt the home directory in Fedora: https://cloud-ninja.org/2014/04/05/fedora-encrypting-your-home-directory/
How Ubuntu does this: https://www.howtogeek.com/wp-content/uploads/2012/06/ximage83.png.pagespeed.gp+jp+jw+pj+ws+js+rj+rp+rw+ri+cp+md.ic.Q3l_7oXwbw.png
Comment 1 Rafal Luzynski 2017-06-08 12:37:17 EDT
I think I also saw OpenSUSE having this feature. It's worth mentioning because OpenSUSE is also RPM-based and thus similar to Fedora.
Comment 2 Steven Haigh 2017-11-09 05:19:39 EST
This is window-dressing at best.... The security improvements are almost zero.

Having an unencrypted / unprotected root partition means data can be exfiltrated easily by any method with root access - including being set up via a live USB image to copy all data that *was* encrypted to an unencrypted location when the user unlocks their home directory.

Looks like a good idea on paper (or screenshots), but is useless in providing any type of real protection.
Comment 3 Jan Niklas Hasse 2017-11-09 07:42:18 EST
The same is true for full disc encryption though: If someone can boot into a live USB image he could also replace the bootloader so that it sends the password over the internet.

Furthermore nobody said this this method can't be used in addition to encrypted /.
Comment 4 Jiri Konecny 2017-11-10 02:24:55 EST
Right now you can encrypt your specified partition in custom partitioning or in blivet-gui.

That means you have 2 installation methods how to encrypt only your home.

This can of course be added to the autopart option too, however, it is really not a priority because it is already doable by other methods.

So or so, thanks for the idea we will get back to it in future.

Jirka

Note You need to log in before you can comment on or make changes to this bug.