I propose that we start creating new LUKS devices using the newer XTS cipher mode with the maximum key size of 512 bits. Unless there is some performance reason that I am not aware of, I think we should default to the highest security level possible. My understanding is that cryptsetup defaults to CBC for reasons involving backwards compatibility. Comments? _______________________________________________ Anaconda-devel-list mailing list Anaconda-devel-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/anaconda-devel-list