-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
I would like to change the encryption password of my qubes
installation. And once I start to play with this, I would like to also:
- - set a higher encryption from qubes default to aes 512-bit full disk
encryption.
- - move the /boot partition to an external *USB device and install Grub
as described here
http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onio
n/wiki/Full_Disk_Encryption
Is this possible to do from within running qubes or will I need to
reinstall the QubesOS and do it all fresh?
Cryptsetup seems pretty straightforward with just executing sudo
cryptsetup luksChangeKey /dev/sdX with sdX to be the luks partition
like for example sd3 in case of default qubes installation procedure.
Is that case from inside of qubes too?
I am a newbie in this area. How would I do that in both cases (fresh
installation of QubesOS; and from within running QubesOS)?
Could one use the Nitrokey Storage as that *USB with /boot partition
and grub installed, or it must be normal, unencrypted USB device?
Are there any pros/cons of this setup?
- --
Kind regards
taran1s
gpg: 12DDA1FE5FB39C110F3D1FD5A664B90BD3BE59B3
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEjkk+SHr9i12eT1pa5k6hqPgAy0QFAl7jea4ACgkQ5k6hqPgA
y0SLCQ//QmsiNYx3LfA40bqzU5QfgND7wIBhMWuNRhDx0UCfXieGFLk/KJd+kC4/
EJ+gat09bRHhFT/eBY+VkyF0RjSEuGQHuIh8iaStpBxalI3p9/5saxJfTZU0C/Uq
MXeskuYMht2IKrBoxO+4cJvHyPWqkN4eA/YUaNHafKj3xnJP+HsiL9i2WyCjimIG
rcMnUi/Y4K6bzbHzjSU/auGs2niAfW1tP4JO+P1TS9A/BeG+8bpSLwpf8ocQqGyX
J+7e9WqS+Zg8QDMXad/k8z64jCoTLlhw6mA1w7hp30NC0UK+hdSvqAh05j7KAMlI
B5AuSAZaX3Thn+iOYy9XbtrYVJtdWy4FmLvf5Y+XQOdtKfkiJ9ChigUSYQQ1s5vH
nAmU4mpNcRBWgNonC2lK4hDuW6ikSl1hj3LwQXBPr41Rsx82JVkaIxluvHqTsFsb
g35mr5oYfx1IEr29dVSVD6X0MOQEVFP1ep2E7gHOVbzMQcTpm2PTEtvRpI6oM0bW
xTXbrFwgZfXHvvYgMiEhpfanPH9XPM8bi5HILbleA23+v+QHFiV6nLbMQr0kP3nF
v0Cwzr4iHNFZXJRdDu4cK+IWIRbQjeCh6a3MvcF9uye+62+yqvQN1x7Vfdunxaib
4hkaQXhe/njKMZti89/4oV5hiWJuS1ffVfIgj+BUQlN5tFP2uKk=
=7sH5
-----END PGP SIGNATURE-----