Best configuration for encrypted software RAID 1 on CentOS

I'm setting up a computer with CentOS 6.4 and a mirrored software
RAID. I would like it to be encrypted so I was wondering what the best
configuration is. The only info I could find is
but it appears to be a bit old and the info on the wiki ( ) doesn't seem to
address RAIDs.

My main question is will it be better to encrypt the RAID itself or
the two partitions used by the RAID? Any other things I should be
aware of?

posted May 15, 2013

1 Answer

This depends on your use-case. Personally, I want my servers to be able
to boot headless, so I leave /boot, and / unencrypted, RAID or
not. Then I encrypt the LV (or partition) I am going to put data I care
about on. I don't think there is any benefit to encrypting the
partitions behind the MD device as it won't be able to form until you
decrypt the devices. I'd keep crypt on the resulting /dev/mdX, at the

answer May 15, 2013
