# Encrypt an external HD an mount it at boot

**URL:** https://community.zymbit.com/t/encrypt-an-external-hd-an-mount-it-at-boot/443
**Category:** ZYMKEY4
**Created:** [March 5, 2019, 5:30pm UTC](https://community.zymbit.com/t/encrypt-an-external-hd-an-mount-it-at-boot/443 "2019-03-05T17:30:50Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![srandoux](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@srandoux](https://community.zymbit.com/u/srandoux)
#### Post date: [March 5, 2019, 5:30pm UTC](https://community.zymbit.com/t/encrypt-an-external-hd-an-mount-it-at-boot/443/1 "2019-03-05T17:30:50Z")

</div>

Hi,

I’d like to store encrypted data on an external hard drive plugged to a Rapberry pi. For the moment, only my rootfs is crypted and secured via Zymkey.

I found a python script create\_zk\_crypt\_vol which seems to be out of date.

I’d like the encryption key to be the same as the one used to crypt the root fs on the SD card and mount it once the system is booted.

How can I do that?

thanks,

---

<div class="post-metadata">

### Author: ![srandoux](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@srandoux](https://community.zymbit.com/u/srandoux)
#### Post date: [March 6, 2019, 10:03am UTC](https://community.zymbit.com/t/encrypt-an-external-hd-an-mount-it-at-boot/443/2 "2019-03-06T10:03:00Z")

</div>

I managed to do it.😀

---

<div class="post-metadata">

### Author: ![Phil\_S\_Zymbit\_1](https://avatars.discourse-cdn.com/v4/letter/p/45deac/32.png) [@Phil\_S\_Zymbit\_1](https://community.zymbit.com/u/Phil_S_Zymbit_1)
#### Post date: [March 6, 2019, 4:55pm UTC](https://community.zymbit.com/t/encrypt-an-external-hd-an-mount-it-at-boot/443/3 "2019-03-06T16:55:05Z")

</div>

Great ! Can you share the python script you used ?

---

<div class="post-metadata">

### Author: ![srandoux](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@srandoux](https://community.zymbit.com/u/srandoux)
#### Post date: [March 6, 2019, 5:13pm UTC](https://community.zymbit.com/t/encrypt-an-external-hd-an-mount-it-at-boot/443/4 "2019-03-06T17:13:46Z")

</div>

Actually,

I had a look in Zymbit installation shell scripts to understand and I did via bash command line.

The prerequisite is of course that everything is configured properly and the rootfs is crypted as documented by Zymbit.

I will also assume that a USB Disk in connected to a USB port on the RPI and that it has 1 partition called /dev/sda1.  
Also, we will call the crypted device cryptfs

#first you unlock the key  
/sbin/zkunlockifs /var/lib/zymbit/key.bin.lock \>key.bin

#set the key to partition  
cat ./key.bin | cryptsetup -q -v luksFormat /dev/sda1 -

#open the device  
cryptsetup luksOpen -q -v --debug /dev/sda1 cryptfs --key-file=$PWD/key.bin

#crypt the partition  
mkfs.ext4 -j /dev/mapper/cryptfs

#check it worked  
mount /dev/mapper/cryptfs /media
