I want to benefit from HW encryption on a Samsung SSD, meaning I want the SSD controller to handle decryption/encryption. I have 2 SSDs that i want to use, one with Windows, one with Debian. Steps I performed to get hw enc on SSD with Debian:
- Enable in SAMSUNG Magician Encrypted Drive. State is now Ready to enable.
- Created a USB bootable device in SAMSUNG Magician to perform Secure Erase.
- Disabled secure boot in BIOS, performed Secure Erase, re-enabled secure boot.
- Used Rufus to create a bootable USB drive with Debian 13.
- Set up debian installation with LVM and encryption.
- During installation, SSD gets written with random data.
- Selected separate partitions for /home /var /temp
- Partitions are created, OS files are written to SSD, all good, GRUB is installed also, dual boot works.
Problem: when I boot in windows and check in SAMSUNG Magician the drive with Debian installed, it still reports Ready to enable. If encryption was done properly it would've reported Enabled.
If the topic doesn't belong to unix stackexchange, please tell me where I can post it, thank you.
sedutilorhdparmin linux to accomplish such a thing, but then how do you unlock the SED to boot linux to then usesedutilto unlock? at best you would boot and run and a SED that never locks and then be able to usesedutil(which i've never done) to manually unlock a locked SED giving its controller the AK to unlock and then you could read the disk and mount as/datafor example.