iSCSI + LUKS over insecure network

2011-06-09 Thread Γιώργος Πάλλας
A tough one (for me)! I use iSCSI (with CHAP authentication) to get a remote device over an insecure network, then I unlock the LUKS volume and finally I mount the ext4 FS. How (in)secure is that? Data I miss: 1. CHAP encrypts the iSCSI authentication password, but the actual iSCSI data go over

Re: iSCSI + LUKS over insecure network

2011-06-09 Thread Cal Leeming [Simplicity Media Ltd]
This might be a good time to get your hands dirty :) A combination of dd / wireshark / tcpdump should revile the answers you need! 2011/6/9 Γιώργος Πάλλας gp...@ccf.auth.gr A tough one (for me)! I use iSCSI (with CHAP authentication) to get a remote device over an insecure network, then I

Re: iSCSI + LUKS over insecure network

2011-06-09 Thread shawn wilson
is this a linux iscsi lun? if not and you've paid good money for a san, you've probably paid good money for their support. if not, call their sales and tell them that you'd like to look into the type of data encryption you can get for your iscsi lun, they'll get an engineer on it, and then you buy