/usr/share/doc/cryptsetup
NameSizeModeActions
examples/-0755rm
AUTHORS1370644editdlrm
changelog.Debian.gz22510644editdlrm
copyright92920644editdlrm
FAQ.gz489900644editdlrm
Keyring.txt27240644editdlrm
LUKS2-locking.txt27110644editdlrm
NEWS.Debian.gz10570644editdlrm
README.Debian.gz56800644editdlrm
README.debug27310644editdlrm
README.gnupg18480644editdlrm
README.gnupg-sc23540644editdlrm
README.keyctl35830644editdlrm
README.md.gz22230644editdlrm
README.opensc.gz22190644editdlrm
v1.0.7-ReleaseNotes29210644editdlrm
v1.1.0-ReleaseNotes.gz22750644editdlrm
v1.1.1-ReleaseNotes17960644editdlrm
v1.1.2-ReleaseNotes15940644editdlrm
v1.1.3-ReleaseNotes4820644editdlrm
v1.2.0-ReleaseNotes.gz21240644editdlrm
v1.3.0-ReleaseNotes.gz21340644editdlrm
v1.3.1-ReleaseNotes4210644editdlrm
v1.4.0-ReleaseNotes.gz22530644editdlrm
v1.4.1-ReleaseNotes8890644editdlrm
v1.4.2-ReleaseNotes16300644editdlrm
v1.4.3-ReleaseNotes23590644editdlrm
v1.5.0-ReleaseNotes.gz33200644editdlrm
v1.5.1-ReleaseNotes12950644editdlrm
v1.6.0-ReleaseNotes.gz38180644editdlrm
v1.6.1-ReleaseNotes10410644editdlrm
v1.6.2-ReleaseNotes9850644editdlrm
v1.6.3-ReleaseNotes18590644editdlrm
v1.6.4-ReleaseNotes20360644editdlrm
v1.6.5-ReleaseNotes24790644editdlrm
v1.6.6-ReleaseNotes10930644editdlrm
v1.6.7-ReleaseNotes33330644editdlrm
v1.6.8-ReleaseNotes20610644editdlrm
v1.7.0-ReleaseNotes31010644editdlrm
v1.7.1-ReleaseNotes13710644editdlrm
v1.7.2-ReleaseNotes14870644editdlrm
v1.7.3-ReleaseNotes8110644editdlrm
v1.7.4-ReleaseNotes6570644editdlrm
v1.7.5-ReleaseNotes8330644editdlrm
v2.0.0-ReleaseNotes.gz97280644editdlrm
v2.0.1-ReleaseNotes.gz22260644editdlrm
v2.0.2-ReleaseNotes.gz19920644editdlrm
v2.0.3-ReleaseNotes.gz24480644editdlrm
v2.0.4-ReleaseNotes.gz23250644editdlrm
v2.0.5-ReleaseNotes.gz20680644editdlrm
v2.0.6-ReleaseNotes.gz19600644editdlrm
v2.1.0-ReleaseNotes.gz34840644editdlrm
v2.2.0-ReleaseNotes.gz45820644editdlrm
v2.2.1-ReleaseNotes14130644editdlrm
v2.2.2-ReleaseNotes21510644editdlrm
v2.3.0-ReleaseNotes.gz32500644editdlrm
v2.3.1-ReleaseNotes17700644editdlrm
v2.3.2-ReleaseNotes14990644editdlrm
v2.3.3-ReleaseNotes13960644editdlrm
v2.3.4-ReleaseNotes.gz20010644editdlrm
v2.3.5-ReleaseNotes.gz31290644editdlrm
v2.3.6-ReleaseNotes23160644editdlrm
v2.4.0-ReleaseNotes.gz47660644editdlrm
v2.4.1-ReleaseNotes19420644editdlrm
v2.4.2-ReleaseNotes13750644editdlrm
v2.4.3-ReleaseNotes.gz19960644editdlrm
Edit: /usr/share/doc/cryptsetup/README.keyctl (3583B)
decrypt_keyctl ============== A passphrase caching script to be used in `/etc/crypttab` on Debian and Ubuntu. When there are multiple cryptsetup (either plain or LUKS) volumes with the same passphrase, it is an unnecessary task to input the passphrase more than once. Just add this script as keyscript to your `/etc/crypttab` and it will cache the passphrase of all crypttab entries with the same identifier. Either copy decrypt_keyctl into the default search path for keyscripts from cryptsetup /lib/cryptdisks/scripts/. So you can just write `keyscript=decrypt_keyctl` in `/etc/crypttab`, or use a random path of your choice and give the full path e.g `keyscript=/sbin/decrypt_keyctl`. Requirements ------------ * Debian cryptsetup package with `/etc/crypttab` handling and keyscript option * Tested with Debian Lenny, Squeeze and Sid * Installed and working keyutils package (`keyctl`) * Needs `CONFIG_KEYS=y` in your kernel configuration What For? --------- In old (pre 2.6.38) kernels, dm-crypt used to be single threaded. Thus every dm-crypt mapping only used a single core for crypto operations. To use the full power of your many-core processor it is was necessary to split the dm-crypt device. For Linux software raid arrays the easiest segmentation was to just put the dm-crypt layer below the software raid layer. But with a 5 disk raid5 it is a rather daunting task to input the passphrase five times. This is what this keyscripts solve for you. Usage ----- Best shown by example: * 5 disks * Linux software raid5 Layer: sda sdb sdc ... sde +-----------+ +-----------+ | LUKS | | LUKS | | +-------+ | | +-------+ | | | RAID5 | | | | RAID5 | | | | ... | | | | ... | | Crypttab Entries: sda_crypt /dev/sda2 main_data_raid luks,discard,keyscript=decrypt_keyctl sdb_crypt /dev/sdb2 main_data_raid luks,discard,keyscript=decrypt_keyctl ... sde_crypt /dev/sde2 main_data_raid luks,discard,keyscript=decrypt_keyctl How does it work ---------------- Crypttab Interface: A keyscript is added to options including a keyfile definition as third parameter in the crypttab file. The keyscript is called with the keyfile as the first and only parameter. Additionally there are a few environment variables set but currently are not used by this keyscript (man 5 crypttab for exact description). Keyscript: `decrypt_keyctl` uses the Linux kernel keyring facility to securely cache passphrases between multiple invocations. The keyfile parameter from crypttab is used to find the same passphrase between multiple invocations. The term used to described the key in the user keyring is `cryptsetup:$CRYPTTAB_KEY`, unless `$CRYPTTAB_KEY` is empty or has the special value `none`, in which case the description is merely `cryptsetup` (thus allowing compatibility with other tools like gdm and systemd-ask-password(1).) Currently the cache timeout is 60 seconds and not configurable (please report a bug if it is too low for you). Problems -------- Passphrase is piped between processes and could end up in unsecured memory, thus later swapped to disk! => Use of cryptoswap recommend! Hints ----- To remove all traces of this keyscript you may want to cleanup the keyring completely with the following command afterwards: sudo keyctl clear @u -- Jonas Meurer Mon, 27 Sep 2010 14:01:35 +0000 -- Guilhem Moulin Tue, 25 Dec 2018 01:12:24 +0100