One. Partition encryption
1. Create encryption
Cryptsetup LUKSFORMAT/DEV/VDB2
This would overwrite data on/dev/vdb2 irrevocably.
Is you sure? (Type uppercase Yes): Yes # #确定加密
Enter Passphrase: # #密码大于8位, and can't be too simple
Verify Passphrase: # #确认密码
650) this.width=650; "src=" Https://s5.51cto.com/wyfs02/M00/9D/CC/wKioL1mGkfyjmAEqAAA3nzAL7J4683.png "title=" Screenshot from 2017-08-06 10-52-15.png "alt=" Wkiol1mgkfyjmaeqaaa3nzal7j4683.png "/>
2. Decrypt the partition and use
Cryptsetup open/dev/vdb2 Westos Decryption
Mkfs.xfs/dev/mapper/westos Formatting devices
mount/dev/mapper/westos/mnt/Mounting Equipment
Umount/dev/mapper/westos Uninstalling the device
Cryptsetup close Westos to turn off the encryption layer of the device
650) this.width=650; "src=" Https://s3.51cto.com/wyfs02/M02/9D/CC/wKiom1mGklHTl2qnAAEJbfIZfzY185.png "style=" float : none; "title=" screenshot from 2017-08-06 10-56-05.png "alt=" Wkiom1mgklhtl2qnaaejbfizfzy185.png "/>
650) this.width=650; "src=" Https://s5.51cto.com/wyfs02/M02/9D/CC/wKioL1mGklGhF3knAABAvX4Vpf4011.png "style=" float : none; "title=" screenshot from 2017-08-06 10-59-35.png "alt=" Wkiol1mgklghf3knaabavx4vpf4011.png "/>
3. Automatic mount encryption device on boot
Vim/etc/crypttab Edit profile Settings auto-decrypt on boot
Decrypt name device holds encrypted password file
Westos/dev/vdb2/root/lukspsfile
Vim/root/lukspsfile password for input partition encryption
chmod 600/root/lukspsfile to execute permissions
Focus: Cryptsetup luksaddkey/dev/vdb2/root/lukspsfile allow device and partition password to store file associations for automatic decryption
Vim/etc/fstab edit configuration file to automatically mount the boot
Format:/dev/mapper/westos/mnt XFS defaults 0 0
Here are 6 columns: 1. Disk set other file name
2. Mount point
3. File system for disk partitioning
4. File system parameters are set to defaults by default
5. Whether the dump backup command function 0 means no dump backup, 1 for daily dump backup, 2 for the indefinite date backup
6. Whether to check sector 0 with fsck indicates that 1 is not required for the first check 2 to be checked but will be more than 1 nights
Reboot restart
Df-h See if the mount is successful
650) this.width=650; "src=" Https://s2.51cto.com/wyfs02/M01/9D/CC/wKiom1mGko6j5Tj3AAALpVV5PII767.png "style=" float : none; "title=" screenshot from 2017-08-06 11-04-50.png "alt=" Wkiom1mgko6j5tj3aaalpvv5pii767.png "/>
650) this.width=650; "src=" Https://s1.51cto.com/wyfs02/M01/9D/CC/wKioL1mGko_jaS9KAABD5iCxd5A643.png "style=" float : none; "title=" screenshot from 2017-08-06 11-08-37.png "alt=" Wkiol1mgko_jas9kaabd5icxd5a643.png "/>
650) this.width=650; "src=" Https://s2.51cto.com/wyfs02/M02/9D/CC/wKiom1mGko-Q-tGaAABeIlISoGE265.png "style=" float : none; "title=" screenshot from 2017-08-06 11-13-32.png "alt=" Wkiom1mgko-q-tgaaabeilisoge265.png "/>
Two. Disk quotas
1. Set the Quota function
Mount-o usrquota/dev/vdb2/mnt Activation quota feature
Quota-uv/dev/vdb2
Edquota-u Student setting student the size of the file content that users can write in the/mnt directory
650) this.width=650; "src=" Https://s1.51cto.com/wyfs02/M02/9D/CC/wKiom1mGkvbw8WOFAAChwQbyl6g561.png "title=" Screenshot from 2017-08-06 11-33-54.png "alt=" Wkiom1mgkvbw8wofaachwqbyl6g561.png "/>
Enter the interface settings:
Filesystem blocks soft hard inodes soft hard
/DEV/VDB2 0 0 204800 0 0
The first hard expression writes the maximum value of a single file, set here as 200M
The second hard expression limits the number of write files, 0 means no Limit
650) this.width=650; "src=" Https://s2.51cto.com/wyfs02/M01/9D/CC/wKiom1mGkyGhXNoxAAAj8mwvpP8685.png "title=" Screenshot from 2017-08-06 11-33-05.png "alt=" Wkiom1mgkyghxnoxaaaj8mwvpp8685.png "/>
Su-student
DD If=/dev/zero of=/mnt/file bs=1m count=200
Quota viewing student user's files under/mnt
Size
650) this.width=650; "src=" Https://s3.51cto.com/wyfs02/M00/9D/CC/wKiom1mGk1TQTDC6AAETa1vpB0Y173.png "title=" Screenshot from 2017-08-06 11-36-42.png "alt=" Wkiom1mgk1tqtdc6aaeta1vpb0y173.png "/>
2. Configure the power on auto-activate quota feature
Vim/etc/fstab
Format:/dev/vdb2/mnt xfs defaults, Usrquota 0 0
Reboot restart
DF to see if the boot automatically mounts and activates the quota function successfully
650) this.width=650; "src=" Https://s4.51cto.com/wyfs02/M02/9D/CC/wKioL1mGk4LQUQ7SAAE6j4zAVDw064.png "style=" float : none; "title=" screenshot from 2017-08-06 11-38-47.png "alt=" Wkiol1mgk4lquq7saae6j4zavdw064.png "/>
650) this.width=650; "src=" Https://s4.51cto.com/wyfs02/M02/9D/CC/wKiom1mGk4Owol7oAABt_DQJH_c618.png "style=" float : none; "title=" screenshot from 2017-08-06 11-45-52.png "alt=" Wkiom1mgk4owol7oaabt_dqjh_c618.png "/>
650) this.width=650; "src=" Https://s1.51cto.com/wyfs02/M00/9D/CC/wKiom1mGk4OC63zKAABunClnQtk702.png "style=" float : none; "title=" screenshot from 2017-08-06 11-48-33.png "alt=" Wkiom1mgk4oc63zkaabunclnqtk702.png "/>
This article is from the "13122425" blog, please be sure to keep this source http://13132425.blog.51cto.com/13122425/1953957
Linux Cloud Automation Operations Basics 19 (partition encryption, disk quotas)