Nvidia Jetson - Enable filesystem encryption
You must recompile the Linux kernel for your Jetson AGX. The default NVIDIA L4T (Linux for Tegra) kernel does not include filesystem encryption support out of the box.
Identify your L4T Version
- Find your exact JetPack/L4T release so you can download the matching kernel source:
cat /etc/nv_tegra_release
Download the Kernel Source
- Navigate to the NVIDIA Jetson Linux Archive, select your specific L4T version, and download the Driver Package (BSP) Sources.
Extract and Configure the Kernel
- Extract the BSP sources and locate the
kernel_src.tbz2archive inside it. Extract that as well, then set up your configuration:
cd kernel/kernel-<version>
make ARCH=arm64 tegra_defconfig
make ARCH=arm64 menuconfig
- In the menu, navigate to File systems and enable FS Encryption. Alternatively, you can edit the
.configfile directly and ensure these lines are set:
CONFIG_FS_ENCRYPTION=y
CONFIG_BLK_INLINE_ENCRYPTION=y
Build the Kernel and Modules
- Compile the new kernel image and its corresponding modules:
make ARCH=arm64 -j$(nproc) Image
make ARCH=arm64 -j$(nproc) dtbs
make ARCH=arm64 -j$(nproc) modules
Install and Reboot
- Replace your current kernel and install the new modules. Make sure to back up your original kernel first just in case.
sudo cp /boot/Image /boot/Image.backup
sudo cp arch/arm64/boot/Image /boot/Image
sudo make ARCH=arm64 modules_install INSTALL_MOD_PATH=/
sudo depmod -a
sudo reboot
- Once the system reboots into the new kernel,
fscryptwill be able to interface with the filesystem.