{"id":232,"date":"2016-08-25T17:28:26","date_gmt":"2016-08-25T15:28:26","guid":{"rendered":"http:\/\/blog.purplescreen.fr\/?p=232"},"modified":"2016-10-14T13:51:04","modified_gmt":"2016-10-14T11:51:04","slug":"ajouter-un-volume-crypter-avec-ssm-system-storage-manager","status":"publish","type":"post","link":"http:\/\/blog.purplescreen.fr\/?p=232","title":{"rendered":"Crypter un volume avec SSM (System Storage Manager)"},"content":{"rendered":"<h4>Introduction<\/h4>\n<p>Je vais vous exposer la mani\u00e8re dont j&#8217;ai proc\u00e9d\u00e9 pour ajouter un volume Crypter sous <span class=\"spellver\" title=\"Cent os, Cent-os, Cents, Lentos, Cent, Sentons, Benthos, Sentis, Endos, Lento, Kendos, Sentes, Sent, D'endos, L'endos\">Centos<\/span> 7 avec l&#8217;aide de <span class=\"spellver\" title=\"MS, DM, SA, SAS, SES, SIS, SUS, RMS, SUN, SON, SA\u00cf, SEN, CM, KM, MM, NM, SE, SI, SU, HUM, OHM, S'Y, SET, SOU, S'EN\">SSM.<\/span> Puis nous verrons comment monter le volume au d\u00e9marrage de la machine en modifiant les fichiers \/etc\/crypttab &amp; \/etc\/fstab.<\/p>\n<h4>Proc\u00e9dure<\/h4>\n<p>Une fois que vous avez ajout\u00e9 votre disque, il faudra cr\u00e9er une partition primaire avec\u00a0# fdisk. Pour cet exemple, nous allons crypter le disque sdc1 de 6 GB.<\/p>\n<pre>[root@localhost ~]# ssm list\r\n----------------------------------------------------------------------------\r\nDevice\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Free\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Used\u00a0\u00a0\u00a0\u00a0\u00a0 Total\u00a0 Pool\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Mount point\r\n----------------------------------------------------------------------------\r\n\/dev\/fd0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 4.00 KB\r\n\/dev\/sda\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.00 GB\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 PARTITIONED\r\n\/dev\/sda1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 572.00 MB\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \/boot\r\n\/dev\/sda2\u00a0 0.00 KB\u00a0\u00a0\u00a0 9.44 GB\u00a0\u00a0\u00a0 9.44 GB\u00a0 centos\r\n\/dev\/sdc\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 6.00 GB\r\n<strong>\/dev\/sdc1<\/strong>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 6.00 GB\r\n----------------------------------------------------------------------------\r\n<\/pre>\n<p>La cr\u00e9ation du volume se fera avec la commande # <span class=\"spellmod\" title=\"ms, dm, sa, sas, ses, sis, sus, RMS, Sun, son, sa\u00ef, sen, cm, km, mm, nm, se, si, su, hum, ohm, s'y, set, sou, s'en\">ssm<\/span> <span class=\"spellmod\" title=\"\">create.<\/span><\/p>\n<pre>[root@localhost ~]# ssm create --fstype xfs -p &lt;NomdeVotrePoolLVM&gt; -n &lt;NomdeVotreVolume&gt; -s6G -e luks \/dev\/sdc1 &lt;PointdeMontage&gt;\r\n<\/pre>\n<p><a href=\"http:\/\/blog.purplescreen.fr\/wp-content\/uploads\/2016\/08\/AddCryptSSM.png\"><img loading=\"lazy\" class=\"wp-image-266 size-full alignnone\" src=\"http:\/\/blog.purplescreen.fr\/wp-content\/uploads\/2016\/08\/AddCryptSSM.png\" alt=\"R\u00e9cup\u00e9rer les valeurs encadrer\" width=\"771\" height=\"272\" srcset=\"http:\/\/blog.purplescreen.fr\/wp-content\/uploads\/2016\/08\/AddCryptSSM.png 771w, http:\/\/blog.purplescreen.fr\/wp-content\/uploads\/2016\/08\/AddCryptSSM-300x106.png 300w, http:\/\/blog.purplescreen.fr\/wp-content\/uploads\/2016\/08\/AddCryptSSM-768x271.png 768w\" sizes=\"(max-width: 771px) 100vw, 771px\" \/><\/a><\/p>\n<p>Conserver\u00a0les valeurs encadrer, nous en aurons besoin pour le montage du volume au d\u00e9marrage.<\/p>\n<h4>Monter le volume au d\u00e9marrage de la machine<\/h4>\n<h5 style=\"padding-left: 30px;\">Le fichier\u00a0\/etc\/<span class=\"spellmod\" title=\"crypt\u00e2t, crypta, cryptas, cryptant, cryptai\">crypttab<\/span><\/h5>\n<p>Nous allons\u00a0modifier le fichier (\/etc\/<span class=\"spellmod\" title=\"crypt\u00e2t, crypta, cryptas, cryptant, cryptai\">crypttab)<\/span>.\u00a0Une fois configurer, nous aurons une invitation lors du d\u00e9marrage de la machine, il faudra saisir le mot de passe choisi lors de la cr\u00e9ation du volume crypter. Vous pouvez \u00e9galement cr\u00e9er un fichier crypter contenant la base de mot de passe pour ce(s) disque(s) \u00e0 mettre dans le troisi\u00e8me champs (voir la documentation).<\/p>\n<p>Champ 1 : Correspond au nom du volume logique. C&#8217;est lui que nous avons d\u00e9fini lors de la cr\u00e9ation du volume crypter avec l&#8217;option -n<\/p>\n<p>Champ 2\u00a0: Mettre le chemin du volume que vous avez r\u00e9cup\u00e9r\u00e9 au moment du cryptage. Vous pouvez r\u00e9cup\u00e9rer cette valeur \u00e9galement avec la commande # ssm list<\/p>\n<p>Champ 3\u00a0: Indiquer l&#8217;emplacement du fichier pour les clefs de d\u00e9cryptage du volume. Ce fichier vous permet d&#8217;\u00e9viter de saisir le mot de passe, au moment du d\u00e9marrage de la machine. Dans le cas ou vous n&#8217;avez pas et\/ou ne souhaitez pas en avoir un, il faudra indiquer la valeur &#8220;none&#8221;<\/p>\n<p>Champ 4\u00a0: c&#8217;est l&#8217;option de cryptage, elle a \u00e9t\u00e9 d\u00e9finie au moment du cryptage gr\u00e2ce \u00e0 l&#8217;option -e<\/p>\n<pre>[root@localhost ~]# cat \/etc\/crypttab\r\nconf\u00a0\u00a0\u00a0 \/dev\/confidentiel\/conf\u00a0 none\u00a0\u00a0\u00a0 luks<\/pre>\n<h5 style=\"padding-left: 30px;\">Le fichier \/etc\/fstab<\/h5>\n<p>Celui-ci permet d&#8217;effectuer le montage du volume au d\u00e9marrage de la machine.\u00a0Le premier champ peut \u00eatre r\u00e9cup\u00e9r\u00e9 lors du <span class=\"spellmod\" title=\"cryptasse, crypt\u00e2mes, crypt\u00e2tes, cryptasses\">cryptage<\/span> du volume. Si vous ne l&#8217;avez pas r\u00e9cup\u00e9r\u00e9, il faudra indiquer \/<span class=\"spellmod\" title=\"d\u00e9c, de, d\u00e9, der, des, d\u00e8s, d\u00e9s, dey, div, d\u00e9p, lev, d'ex, d'en\">dev\/<\/span><span class=\"spellmod\" title=\"napper, nappe, napp\u00e9, nappes, napp\u00e9s, happer, japper, napp\u00e9e, nappez, happe, happ\u00e9, caper, jappe, japp\u00e9, laper, maser, mater, mazer, m\u00e2ter, r\u00e2per, saper, taper, happes, happ\u00e9s, m'axer\">mapper\/<\/span>&lt;nom du volume &#8220;option -n&#8221; &gt;<\/p>\n<pre>[root@localhost ~]# cat \/etc\/fstab\r\n (.......)\r\n <strong>\/dev\/mapper\/conf\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \/media\/backup_Qnap\/.Confidentiel\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 xfs\u00a0\u00a0\u00a0\u00a0 defaults\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 0 0<\/strong><\/pre>\n<p>Ensuite, vous pouvez red\u00e9marr\u00e9 votre machine et saisir votre clef de d\u00e9cryptage au moment du <span class=\"spellmod\" title=\"\">boot.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Je vais vous exposer la mani\u00e8re dont j&#8217;ai proc\u00e9d\u00e9 pour ajouter un volume Crypter sous Centos 7 avec l&#8217;aide de SSM. Puis nous verrons comment monter le volume au d\u00e9marrage de la machine en modifiant les fichiers \/etc\/crypttab &amp; \/etc\/fstab. Proc\u00e9dure Une fois que vous avez ajout\u00e9 votre disque, il faudra cr\u00e9er une partition&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[15],"tags":[18,35],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Crypter un volume avec SSM (System Storage Manager) - PurpleScreen<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/blog.purplescreen.fr\/?p=232\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ogosselin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/blog.purplescreen.fr\/?p=232\",\"url\":\"http:\/\/blog.purplescreen.fr\/?p=232\",\"name\":\"Crypter un volume avec SSM (System Storage Manager) - PurpleScreen\",\"isPartOf\":{\"@id\":\"http:\/\/blog.purplescreen.fr\/#website\"},\"datePublished\":\"2016-08-25T15:28:26+00:00\",\"dateModified\":\"2016-10-14T11:51:04+00:00\",\"author\":{\"@id\":\"http:\/\/blog.purplescreen.fr\/#\/schema\/person\/ad63980c08d122ffe9115ade81b21fd3\"},\"breadcrumb\":{\"@id\":\"http:\/\/blog.purplescreen.fr\/?p=232#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/blog.purplescreen.fr\/?p=232\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/blog.purplescreen.fr\/?p=232#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\/\/blog.purplescreen.fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Crypter un volume avec SSM (System Storage Manager)\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/blog.purplescreen.fr\/#website\",\"url\":\"http:\/\/blog.purplescreen.fr\/\",\"name\":\"PurpleScreen\",\"description\":\"by Olivier Gosselin\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/blog.purplescreen.fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"http:\/\/blog.purplescreen.fr\/#\/schema\/person\/ad63980c08d122ffe9115ade81b21fd3\",\"name\":\"ogosselin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/blog.purplescreen.fr\/#\/schema\/person\/image\/\",\"url\":\"http:\/\/0.gravatar.com\/avatar\/6a053a3dca3cccbeecd37d492189f38f?s=96&d=mm&r=g\",\"contentUrl\":\"http:\/\/0.gravatar.com\/avatar\/6a053a3dca3cccbeecd37d492189f38f?s=96&d=mm&r=g\",\"caption\":\"ogosselin\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/olivier-gosselin-30090498\/\"],\"url\":\"http:\/\/blog.purplescreen.fr\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Crypter un volume avec SSM (System Storage Manager) - PurpleScreen","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/blog.purplescreen.fr\/?p=232","twitter_misc":{"Written by":"ogosselin","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/blog.purplescreen.fr\/?p=232","url":"http:\/\/blog.purplescreen.fr\/?p=232","name":"Crypter un volume avec SSM (System Storage Manager) - PurpleScreen","isPartOf":{"@id":"http:\/\/blog.purplescreen.fr\/#website"},"datePublished":"2016-08-25T15:28:26+00:00","dateModified":"2016-10-14T11:51:04+00:00","author":{"@id":"http:\/\/blog.purplescreen.fr\/#\/schema\/person\/ad63980c08d122ffe9115ade81b21fd3"},"breadcrumb":{"@id":"http:\/\/blog.purplescreen.fr\/?p=232#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/blog.purplescreen.fr\/?p=232"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/blog.purplescreen.fr\/?p=232#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/blog.purplescreen.fr\/"},{"@type":"ListItem","position":2,"name":"Crypter un volume avec SSM (System Storage Manager)"}]},{"@type":"WebSite","@id":"http:\/\/blog.purplescreen.fr\/#website","url":"http:\/\/blog.purplescreen.fr\/","name":"PurpleScreen","description":"by Olivier Gosselin","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/blog.purplescreen.fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"http:\/\/blog.purplescreen.fr\/#\/schema\/person\/ad63980c08d122ffe9115ade81b21fd3","name":"ogosselin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/blog.purplescreen.fr\/#\/schema\/person\/image\/","url":"http:\/\/0.gravatar.com\/avatar\/6a053a3dca3cccbeecd37d492189f38f?s=96&d=mm&r=g","contentUrl":"http:\/\/0.gravatar.com\/avatar\/6a053a3dca3cccbeecd37d492189f38f?s=96&d=mm&r=g","caption":"ogosselin"},"sameAs":["https:\/\/www.linkedin.com\/in\/olivier-gosselin-30090498\/"],"url":"http:\/\/blog.purplescreen.fr\/?author=1"}]}},"_links":{"self":[{"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=\/wp\/v2\/posts\/232"}],"collection":[{"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=232"}],"version-history":[{"count":65,"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=\/wp\/v2\/posts\/232\/revisions"}],"predecessor-version":[{"id":398,"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=\/wp\/v2\/posts\/232\/revisions\/398"}],"wp:attachment":[{"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=232"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=232"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.purplescreen.fr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}