ÔõÑùʹÓüÓÃÜ´æ´¢ºÍ´«Êä±£»¤CentOSϵͳÖеÄÃô¸ÐÊý¾Ý
ÔõÑùʹÓüÓÃÜ´æ´¢ºÍ´«Êä±£»¤centosϵͳÖеÄÃô¸ÐÊý¾Ý
СÐò
ÔÚµ±½ñÊý×Ö»¯Ê±´ú£¬±£»¤Ãô¸ÐÊý¾ÝºÍÒþ˽±äµÃÓÈΪÖ÷Òª¡£ÔÚCentOSϵͳÖУ¬ÎÒÃÇ¿ÉÒÔʹÓüÓÃÜ´æ´¢ºÍ´«ÊäÀ´ÓÐÓõر£»¤Ãô¸ÐÊý¾Ý¡£±¾ÎĽ«ÏÈÈÝÔõÑùʹÓüÓÃÜÊÖÒÕÀ´±£»¤CentOSϵͳÖеÄÃô¸ÐÊý¾Ý£¬²¢ÌṩÏìÓ¦µÄ´úÂëʾÀý¡£
¼ÓÃÜ´æ´¢
ÔÚCentOSϵͳÖУ¬ÎÒÃÇ¿ÉÒÔʹÓÃLUKS£¨Linux Unified Key Setup£©ÊÖÒÕÀ´¼ÓÃÜ´ÅÅÌ¡£ÒÔÏÂÊÇʹÓÃLUKS¼ÓÃÜCentOSϵͳÖеÄÊý¾ÝµÄ°ì·¨£º
×°ÖÃcryptsetupÈí¼þ°ü£º
sudo yum install cryptsetup
µÇ¼ºó¸´ÖÆ
½¨ÉèÒ»¸ö¿ÕȱµÄ¼ÓÃÜ×°±¸£º
sudo cryptsetup luksFormat /dev/sdb
µÇ¼ºó¸´ÖÆ
´ËÏÂÁÔÚ/dev/sdbÉϽ¨ÉèÒ»¸ö¼ÓÃÜ×°±¸¡£
·¿ª¼ÓÃÜ×°±¸£º
sudo cryptsetup luksOpen /dev/sdb encrypted_device
µÇ¼ºó¸´ÖÆ
Õ⽫·¿ª¼ÓÃÜ×°±¸²¢½«ÆäÓ³Éäµ½encrypted_device¡£
ÃûÌû¯×°±¸£º
sudo mkfs.ext4 /dev/mapper/encrypted_device
µÇ¼ºó¸´ÖÆ
Õâ»áÔÚ¼ÓÃÜ×°±¸ÉϽ¨ÉèÒ»¸öÎļþϵͳ¡£
¹ÒÔØ×°±¸£º
sudo mkdir /mnt/encrypted sudo mount /dev/mapper/encrypted_device /mnt/encrypted
µÇ¼ºó¸´ÖÆ
Õ⽫½«×°±¸¹ÒÔص½/mnt/encryptedĿ¼¡£
ÏÖÔÚ£¬Äú¿ÉÒÔ½«Ãô¸ÐÊý¾Ý´æ´¢ÔÚ/mnt/encryptedĿ¼Ï¡£µ±¸Ã×°±¸Î´¹ÒÔØʱ£¬Êý¾Ý½«±»¼ÓÃܱ£»¤¡£
¼ÓÃÜ´«Êä
ÔÚCentOSϵͳÖУ¬ÎÒÃÇ¿ÉÒÔʹÓÃOpenSSL¿âÀ´ÊµÏÖ¼ÓÃÜ´«Êä¡£ÒÔÏÂÊÇʹÓÃOpenSSL¿âÔÚCentOSϵͳÖб£»¤Êý¾Ý´«ÊäµÄ°ì·¨£º
×°ÖÃOpenSSL¿â£º
sudo yum install openssl
µÇ¼ºó¸´ÖÆ
ÌìÉú¹«Ô¿ºÍ˽Կ£º
openssl genrsa -out private.key 2048 openssl rsa -in private.key -pubout -out public.key
µÇ¼ºó¸´ÖÆ
Õ⽫ÌìÉúÃûΪprivate.keyºÍpublic.keyµÄ˽ԿºÍ¹«Ô¿¡£
¼ÓÃÜÊý¾Ý£º
openssl rsautl -encrypt -in input.txt -inkey public.key -pubin -out encrypted.txt
µÇ¼ºó¸´ÖÆ
Õ⽫ʹÓù«Ô¿½«input.txtÎļþ¼ÓÃÜ£¬²¢½«Ð§¹ûÉúÑÄÔÚencrypted.txtÎļþÖС£
½âÃÜÊý¾Ý£º
openssl rsautl -decrypt -in encrypted.txt -inkey private.key -out output.txt
µÇ¼ºó¸´ÖÆ
Õ⽫ʹÓÃ˽Կ½«encrypted.txtÎļþ½âÃÜ£¬²¢½«Ð§¹ûÉúÑÄÔÚoutput.txtÎļþÖС£
ÏÖÔÚ£¬Äú¿ÉÒÔʹÓÃencrypted.txtÎļþ¾ÙÐÐÇå¾²µÄÊý¾Ý´«Êä¡£Ö»ÓÐÓµÓÐ˽ԿµÄÈ˲Żª½âÃÜÊý¾Ý¡£
½áÂÛ
±£»¤CentOSϵͳÖеÄÃô¸ÐÊý¾Ý¹ØÓÚ±£»¤Ð¡ÎÒ˽ÈËÒþ˽ºÍ±£ÃÜÐÅÏ¢ÖÁ¹ØÖ÷Òª¡£Í¨¹ýʹÓÃLUKSÊÖÒÕ¾ÙÐмÓÃÜ´æ´¢ºÍʹÓÃOpenSSL¿â¾ÙÐмÓÃÜ´«Ê䣬ÎÒÃÇ¿ÉÒÔÔÚCentOSϵͳÖÐÓÐÓõر£»¤Ãô¸ÐÊý¾Ý¡£Ï£ÍûÕâƪÎÄÕ¶ÔÄúÓÐËù×ÊÖú£¡
ÒÔÉϾÍÊÇÔõÑùʹÓüÓÃÜ´æ´¢ºÍ´«Êä±£»¤CentOSϵͳÖеÄÃô¸ÐÊý¾ÝµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡