Encrypted Optical Disc Guide


This guide provides step-by-step instructions for encrypting and burning data onto optical media (CDs, DVDs, Blu-rays) on Linux.

Optical media is read-only media. Standard read-write filesystems (like ext4) often fail to mount with errors like bad superblock because Linux attempts to replay journals or update access times. To prevent this, two recommended workflows are detailed below:


Method 1: LUKS + SquashFS (Best for Native Linux Filesystem Experience)

This method creates an encrypted block container with a read-only SquashFS filesystem inside. It mounts seamlessly from read-only media like CDs.

Step 1: Create the Container Image

  1. Create a blank image file (e.g., 650 MB for a standard CD):

    dd if=/dev/zero of=encrypted_cd.img bs=1M count=650
    
    # or Create an image sized specifically for 50MB of data (\~70MB total)
    truncate -s 70M cd_image.img
    
  2. Format the image file with LUKS encryption:

    sudo cryptsetup luksFormat encrypted_cd.img
    

    Type YES in all caps and enter a strong passphrase when prompted.

  3. Open the encrypted container mapping:

    sudo cryptsetup open encrypted_cd.img secure_cd
    

Step 2: Populate with a Read-Only Filesystem

  1. Package your source directory directly into the opened LUKS device using SquashFS:

    sudo mksquashfs /path/to/your/source_data /dev/mapper/secure_cd -noappend
    
  2. Close the LUKS mapped volume:

    sudo cryptsetup close secure_cd
    

Step 3: Burn the Image to CD

  1. Insert a blank CD into your burner drive.
  2. Burn the raw image using xorriso or wodim:

    # Using xorriso
    xorriso -as cdrecord -v dev=/dev/sr0 -dao encrypted_cd.img
    
    # OR using wodim
    wodim dev=/dev/sr0 -v -data encrypted_cd.img
    

Step 4: Mount and Read the CD

  1. Insert your burned CD.
  2. Open the LUKS volume directly off the optical drive:
    sudo cryptsetup open /dev/sr0 secure_cd
    
  3. Create a mount point and mount the volume:
    sudo mkdir -p /mnt/secure_cd
    sudo mount /dev/mapper/secure_cd /mnt/secure_cd
    
  4. Access your files under /mnt/secure_cd.

Step 5: Unmount and Lock

When finished, safely close the volume:

sudo umount /mnt/secure_cd
sudo cryptsetup close secure_cd

Method 2: GPG Encrypted Tarball (Simplest & Portable)

If you prefer a lightweight archive format without dealing with block devices and loop mounts, compress and encrypt your directory using GPG.

Step 1: Create & Encrypt Archive

tar -czf - /path/to/your/source_data | gpg --symmetric --cipher-algo AES256 -o encrypted_data.tar.gz.gpg

Step 2: Burn Archive File to CD

Burn the .gpg file to the CD as a standard data track:

xorriso -as cdrecord -v dev=/dev/sr0 -dao encrypted_data.tar.gz.gpg

Step 3: Decrypt and Extract Data

  1. Mount the CD using standard mounting:
    sudo mkdir -p /mnt/cdrom
    sudo mount /dev/sr0 /mnt/cdrom
    
  2. Decrypt and untar the archive to your desired location:
    gpg -d /mnt/cdrom/encrypted_data.tar.gz.gpg | tar -xzf - -C /path/to/destination/
    

Troubleshooting Existing Discs (ext4 on CD)

If you previously burned an ext4 filesystem to a CD and receive the following error:

mount: /mnt/secure_cd: wrong fs type, bad option, bad superblock...

You can mount it by forcing read-only mode and disabling journal replay (noload):

# 1. Open LUKS mapping
sudo cryptsetup open /dev/sr0 secure_cd

# 2. Mount with ro and noload flags
sudo mount -o ro,noload /dev/mapper/secure_cd /mnt/secure_cd