tripl - single or multiple encryption with loop-aes

Version v0.71  Sun Sept 20 2009

Copyright 2006-2009 by wdef <wdef200 at users dot sourceforge dot net>


Description

Tripl is a wrapper for loop-aes v3.x aimed at simplifying set up,
(u)mounting and maintaining of one or more single or multiple-encrypted
partitions. It automates GnuPG key generation, allocation and
setup/pulldown of loops, layered embedding of keys, filesystem checking
etc.


Why

loop-aes does not contain an interface for the transparent setup and use
of multiple encryption layers using chained loop devices. Also, some
new users find loop-aes difficult.  If you already have loop-aes-v3.x
on your system (eg Knoppix) you can begin using tripl immediately. It
is not necessary to know what a loop is.

Usage

You need loop-aes v3.x and associated patched utils on your system -
see 'Requirements' below. Before using tripl, set your chosen options
in $HOME/.triplrc, where $HOME is root's home. Place tripl somewhere in
PATH. The first layer will be encrypted using CIPHER[1], the second with
CIPHER[2], and so on. Blowfish is not supported since it does not work
with multiline keychains in loop-aes and because it is not recommended
for use with large amounts of data.

To install tripl, just check the script is executable:

# chmod +x tripl

and put it somewhere in PATH.

Tripl has two modes of operation as regards 65-line GnuPG-encrypted
keys.  It can either use an individual external (detached) key for
each encryption layer (EMBED=no), or it can use a single external key
for the first layer plus a unique embedded key for each subsequent
layer of encryption (EMBED=yes). If EMBED is set to yes, tripl -n will
automatically create these internal keys, prompting for the user to set
passwords. Each key is embedded in the encryption layer (loop) prior to
that being set up. This means the user only need provide one external
gpg-encrypted key - the other encrypted keys are nested inside the loop
devices. This simplifies key management and means that an attacker must
crack the first layer of encryption in order to obtain the gpg-encrypted
keys for the second, and so on. External keys can be made using tripl -k.

Note: multiple encryption can use a lot of cpu. Single or double
encryption with a good password is sufficient (really!). If the user is
mad/paranoid, more layers of encryption (up to the number of available
loop devices) can be carried out just by extending the number of elements
in the array CIPHER accordingly and setting (eg) MODE=4.  This is not
recommended. The more layers of encryption applied, the more friable
(prone to loss) the original data becomes, and the greater the CPU load.
The usual weaknesses of encryption with well-known ciphers are insecure
treatment of plaintext, weak passwords, or weak system security or
privacy.  Multiple encryption achieves nothing if the user is careless
in one of these areas.  Remember that plaintext can leak to swap -
either disable swap or encrypt it (see the loop-aes readme).

Tripl does not use /etc/fstab. Tripl skips loops that are already in
use and only pulls down encrypted loops chained to the particular device
when umounting.

Quickstart

Tripl must be run as the root user. To make an external key:

tripl -k

(Then set the location of the new key at the top of the script).

To set up the encrypted partition or device:

tripl -n

To mount the encrypted partition:

tripl -m

Now open the mountpoint directory - it will be empty except for
lost+found. Place your stuff to be encrypted in the mountpoint
directory. When you are finished, dismount the encrypted partition with:

tripl -u

To fsck the encrypted filesystem (advisable to do this once in a while,
and always after an improper dismount):

tripl -r


More than one partition

You can mount more than one encrypted partition at once by using separate
configuration files for each partition and pointing tripl at the pertinent
config file with the -f option:

tripl -f /path/to/someconfigfile -m

Obviously you must continue to pass someconfigfile to tripl with the -f
option for all tripl actions on that partition.

Without the -f switch, tripl will look for settings in ~/.triplrc.
If that does not exist, tripl will create it on first run.


Other user settings

If FORCE is set to GENTLE or BRUTE, all processes accessing the mountpoint
when the user tries to umount the encrypted partition with tripl -u will
be killed (including file managers etc).  This is to ensure a rapid umount
(instead of a "device is busy" error).

If unsure, choose GENTLE; this will signal processes politely before
resorting to SIGKILL.  See Known Issues below.

VERBOSE=yes is best when learning to use tripl.  If you prefer less
information to be printed to the terminal, turn this off later.

Requirements

loop-aes v3.x and GnuPG must be properly compiled and installed on your
system. Mount, umount, losetup, swapon and swapoff must be properly
patched and installed as per the instructions in the loop-aes README.
tripl was written using bash 2.05b.0(1)-release and has been tested
with bash-3.2.


Known issues

Don't mount a file-backed cloop or loop device inside a mounted encrypted
partition (for example, a Damnsmalllinux uci extension) or if you do,
be sure to umount it before trying to umount the partition.  Reason:
fuser doesn't see this as a process on the partition and so GENTLE
or FORCE cannot kill the (c)loop, so you won't be able to umount the
encrypted partition.

Kludges

tripl tries to workaround the limitations of bash's getopts for validating
command line switches.  These kludges seem to work.

Acknowledgements

Many thanks to Jari Russu for loop-aes.

Comments, bugs, suggestions

Send to wdef200 at users dot sourceforge dot net
