/usr/share/doc/cryptsetup
NameSizeModeActions
examples/-0755rm
AUTHORS1370644editdlrm
changelog.Debian.gz22510644editdlrm
copyright92920644editdlrm
FAQ.gz489900644editdlrm
Keyring.txt27240644editdlrm
LUKS2-locking.txt27110644editdlrm
NEWS.Debian.gz10570644editdlrm
README.Debian.gz56800644editdlrm
README.debug27310644editdlrm
README.gnupg18480644editdlrm
README.gnupg-sc23540644editdlrm
README.keyctl35830644editdlrm
README.md.gz22230644editdlrm
README.opensc.gz22190644editdlrm
v1.0.7-ReleaseNotes29210644editdlrm
v1.1.0-ReleaseNotes.gz22750644editdlrm
v1.1.1-ReleaseNotes17960644editdlrm
v1.1.2-ReleaseNotes15940644editdlrm
v1.1.3-ReleaseNotes4820644editdlrm
v1.2.0-ReleaseNotes.gz21240644editdlrm
v1.3.0-ReleaseNotes.gz21340644editdlrm
v1.3.1-ReleaseNotes4210644editdlrm
v1.4.0-ReleaseNotes.gz22530644editdlrm
v1.4.1-ReleaseNotes8890644editdlrm
v1.4.2-ReleaseNotes16300644editdlrm
v1.4.3-ReleaseNotes23590644editdlrm
v1.5.0-ReleaseNotes.gz33200644editdlrm
v1.5.1-ReleaseNotes12950644editdlrm
v1.6.0-ReleaseNotes.gz38180644editdlrm
v1.6.1-ReleaseNotes10410644editdlrm
v1.6.2-ReleaseNotes9850644editdlrm
v1.6.3-ReleaseNotes18590644editdlrm
v1.6.4-ReleaseNotes20360644editdlrm
v1.6.5-ReleaseNotes24790644editdlrm
v1.6.6-ReleaseNotes10930644editdlrm
v1.6.7-ReleaseNotes33330644editdlrm
v1.6.8-ReleaseNotes20610644editdlrm
v1.7.0-ReleaseNotes31010644editdlrm
v1.7.1-ReleaseNotes13710644editdlrm
v1.7.2-ReleaseNotes14870644editdlrm
v1.7.3-ReleaseNotes8110644editdlrm
v1.7.4-ReleaseNotes6570644editdlrm
v1.7.5-ReleaseNotes8330644editdlrm
v2.0.0-ReleaseNotes.gz97280644editdlrm
v2.0.1-ReleaseNotes.gz22260644editdlrm
v2.0.2-ReleaseNotes.gz19920644editdlrm
v2.0.3-ReleaseNotes.gz24480644editdlrm
v2.0.4-ReleaseNotes.gz23250644editdlrm
v2.0.5-ReleaseNotes.gz20680644editdlrm
v2.0.6-ReleaseNotes.gz19600644editdlrm
v2.1.0-ReleaseNotes.gz34840644editdlrm
v2.2.0-ReleaseNotes.gz45820644editdlrm
v2.2.1-ReleaseNotes14130644editdlrm
v2.2.2-ReleaseNotes21510644editdlrm
v2.3.0-ReleaseNotes.gz32500644editdlrm
v2.3.1-ReleaseNotes17700644editdlrm
v2.3.2-ReleaseNotes14990644editdlrm
v2.3.3-ReleaseNotes13960644editdlrm
v2.3.4-ReleaseNotes.gz20010644editdlrm
v2.3.5-ReleaseNotes.gz31290644editdlrm
v2.3.6-ReleaseNotes23160644editdlrm
v2.4.0-ReleaseNotes.gz47660644editdlrm
v2.4.1-ReleaseNotes19420644editdlrm
v2.4.2-ReleaseNotes13750644editdlrm
v2.4.3-ReleaseNotes.gz19960644editdlrm
Edit: /usr/share/doc/cryptsetup/v1.7.0-ReleaseNotes (3101B)
Cryptsetup 1.7.0 Release Notes ============================== The cryptsetup 1.7 release changes defaults for LUKS, there are no API changes. Changes since version 1.6.8 * Default hash function is now SHA256 (used in key derivation function and anti-forensic splitter). Note that replacing SHA1 with SHA256 is not for security reasons. (LUKS does not have problems even if collisions are found for SHA1, for details see FAQ item 5.20). Using SHA256 as default is mainly to prevent compatibility problems on hardened systems where SHA1 is already be phased out. Note that all checks (kernel crypto API availability check) now uses SHA256 as well. * Default iteration time for PBKDF2 is now 2 seconds. Increasing iteration time is in combination with PBKDF2 benchmark fixes a try to keep PBKDF2 iteration count still high enough and also still acceptable for users. N.B. Long term is to replace PBKDF2 algorithm with Password Hashing Competition winner - Argon2. Distributions can still change these defaults in compilation time. You can change iteration time and used hash function in existing LUKS header with cryptsetup-reencrypt utility even without full reencryption of device (see --keep-key option). * Fix PBKDF2 iteration benchmark for longer key sizes. The previous PBKDF2 benchmark code did not take into account output key length properly. For SHA1 (with 160-bits output) and 256-bit keys (and longer) it means that the final iteration value was higher than it should be. For other hash algorithms (like SHA256 or SHA512) it caused that iteration count was lower (in comparison to SHA1) than expected for the requested time period. The PBKDF2 benchmark code is now fixed to use the key size for the formatted device (or default LUKS key size if running in informational benchmark mode). Thanks to A.Visconti, S.Bossi, A.Calo and H.Ragab (http://www.club.di.unimi.it/) for point this out. (Based on "What users should know about Full Disk Encryption based on LUKS" paper to be presented on CANS2015). * Remove experimental warning for reencrypt tool. The strong request for full backup before using reencryption utility still applies :) * Add optional libpasswdqc support for new LUKS passwords. If password is entered through terminal (no keyfile specified) and cryptsetup is compiled with --enable-passwdqc[=/etc/passwdqc.conf], configured system passwdqc settings are used to check password quality. * Update FAQ document. Cryptsetup API NOTE: Direct terminal handling and password calling callback for passphrase entry will be removed from libcryptsetup in next major (2.x) version (application should handle it itself). It means that application have to always provide password in API calls. Functions returning last error will be removed in next major version (2.x). These functions did not work properly for early initialization errors and application can implement better function easily using own error callback. See comments in libcryptsetup.h for more info about deprecated functions.