having the swap encrypted is not a big issue, something like the following

losetup -e AES128 /dev/loop0 /dev/hdax(your swap)
swapon /dev/loop0

This may not be the exact sequence but I read it some where

As for the root, I am curious as it is on CD so how can it be encrypted ? Or if you mean not booting from CD, I believe a scheme like the above would work, however you need at least 2 partition(not counting the swap), one is used to store the kernel image and initrd and in your linuxrc script, do something similar as the above for the root partition.

I haven't figured out a way to properly protected kernel image and initrd, just in case NSA slip in my door to replace those two which would break all encryption