How to Encrypt Drive with BitLocker in Linux?

BitLocker is is a full-disk encryption software developed by Microsoft for the Windows operating systems, Microsoft did not develop a version of BitLocker for the Linux operating system, so Linux users can only use third-party BitLocker solutions to encrypt the drives, and Hasleo BitLocker Anywhere For Linux is such a solution, and it is fully compatible with Microsoft's BitLocker. Here we will describe how to use Hasleo BitLocker Anywhere For Linux to encrypt drive with BitLocker Drive Encryption in Linux.

tips Tips:

  • Terminating the program, removing the drive or abnormal power off during encryption will result in data corruption, so it is recommended that you back up the files on the volume you want to encrypt before encrypting it.
  • Please keep the BitLocker password in mind and back up the BitLocker recovery key safely, losing both of them will cause the data to be inaccessible.

Download BitLocker For Linux Download BitLocker For Windows Download BitLocker For Mac

Tutorial to Encrypt Drive with BitLocker in Linux.

Step 1. Download and extract Hasleo BitLocker Anywhere For Linux.

Step 2. Open a terminal as a non-root user, go to the bin subfolder under the extract folder, then execute the 'run.sh' script to start the program.

Step 3. Right-click the drive you want to encrypt in main window, then click "Turn On BitLocker".

select the drive to encrypt

 

Step 4. In this step, you are required to specify a password for encrypting the drive, enter the password and click "Next". You should choose a password having a combination of upper and lower case letters, numbers, spaces, and special symbols. Once the encryption is complete, you can access the drive using this password.

enter encrypt password

  • Encrypt used disk space only: Allows you to encrypt only the disk space that is currently used by the drive file system, unused space will remain unencrypted, this option can help you save time spent on encryption. After you encrypt a drive with this option, all files that you added to the drive are automatically encrypted.
  • Compatible mode: If a drive that you plan to encrypt needs to be used on Windows operating systems prior to Windows 10 Version 1511, you should choose compatible mode. Windows 10 Version 1511 introduces a new disk encryption mode (XTS-AES) that is not compatible with older versions of Windows, the compatible mode (AES-CBC) is full compatible with older versions of Windows.
  • Use 256-bit encryption: Bitlocker supports 128-bit and 256-bit encryption strength. The 256-bit encryption is more secure but will take up more CPU resources, so you should choose different encryption strengths according to your needs. Please tick this checkbox if you want to use 256 encryption strength.

 

Step 5. Back up BitLocker recovery key, then click “Next” to move on. You can save the recovery key to a file or print a copy of it. Please note that anyone can use the recovery key to gain access to the drive, even if they do not know the password entered in the previous step, so please do not disclose it to others.

back up bitlocker recovery key

 

Step 6. Hasleo BitLocker Anywhere For Linux will now encrypt the contents of the selected drive using BitLocker drive encryption. The encryption process could take a long time to finish depending on the size of the drive, so please be patient to wait. If you don't want to wait until the encryption operation is finished, "Shut down the computer when the operation is completed" option is a good idea. Just check it.

encrypting drive with bitlocker

 

Step 7. After the encryption is complete, click the "Finish" button to return to the main window.

encryption is complete
 

Step 8. In main window, the status of the drive is now encrypted and locked, you have to mount the BitLocker encrypted drive before you can access it.

drive is encrypted and locked
 

Frequently Asked Questions (FAQ) for Encrypting Drive with BitLocker in Linux

Q: Can Linux natively encrypt drives with BitLocker?

A: No, Microsoft did not develop a version of BitLocker for Linux. You need third-party software like Hasleo BitLocker Anywhere For Linux to encrypt drives with BitLocker in Linux.

Q: Is Hasleo BitLocker Anywhere For Linux compatible with Microsoft's BitLocker?

A: Yes, Hasleo BitLocker Anywhere For Linux is fully compatible with Microsoft's BitLocker, meaning drives encrypted with it can be accessed on Windows systems.

Q: What is the difference between encrypting used disk space only and full drive encryption?

A: Encrypting used disk space only is faster as it only encrypts data currently on the drive. Unused space remains unencrypted but new files are automatically encrypted. Full encryption takes longer but secures all data.

Q: What is compatible mode in BitLocker encryption?

A: Compatible mode (AES-CBC) is for drives that need to be used on Windows versions prior to Windows 10 Version 1511. Newer Windows uses XTS-AES mode which is not compatible with older versions.

Q: Should I use 128-bit or 256-bit encryption for BitLocker in Linux?

A: 256-bit encryption is more secure but uses more CPU resources. Choose based on your security needs. For most users, either option provides adequate protection.

Q: What should I do before encrypting a drive with BitLocker in Linux?

A: It is recommended to back up the files on the volume before encrypting, as terminating the program, removing the drive, or abnormal power off during encryption can result in data corruption.

Q: How do I access a BitLocker encrypted drive after encryption in Linux?

A: After encryption, the drive status shows as encrypted and locked. You need to mount the BitLocker encrypted drive using Hasleo BitLocker Anywhere For Linux with your password before accessing it.

Q: What happens if I lose my BitLocker password and recovery key?

A: Losing both the password and recovery key will cause the data to be permanently inaccessible. It is crucial to keep the password in mind and safely back up the recovery key.