New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
Separate virtual luks volume for sensitive data + ipsec + ssh to mount it manually?
But the keys are exposed at rest for the initially booted OS.
Hmm...
For luks, there is https://recompile.se/mandos so you don't have to be at datacenter. But then you may want to worry about MITM, ip hijacking, etc. etc.
That is exactly my point.. If an adversary has physical access they can mount the decrypted part and copy your keys to MITM your decryption, which is one of the reasons your server would be encrypted in the first place. One could also use IPMI to unlock the system, the same applies, tap the USB communication between the IPMI and server.
I'm hoping a truely secure way to unlock the system but I haven't thought of a way yet..