Re: encrypting existing filesystem without aes-pipe?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

| The 'dd if=/dev/hda1 of=/dev/loop0' is the classic method to encrypt a
file
| system in place. Ancient versions of loop-AES used that method to encrypt
| root file system in-place. But since root file system encryption had to be
| done using rescue boot-CD or boot-floppy kernel, all of which didn't have
| encrypted loop device support, not everyone was able to do the encryption.
| Aespipe has the advantage that is does not require any encrypted loop
device
| support from the kernel, and as such works with all kernels, even
non-linux
| kernels.

Thanks for clarification. I didn't take into account compatibility with
kernels without loop-aes support; indeed it is strong feature of
aes-pipe method.
However, good to see the "classic" method is secure, so I can use it in
my app, where kernel support for loop-aes is assumed.

Greetings
Pawel Pokrywka

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQD1AwUBQTnhIQYJ6m8RUpKnAQIUoAcAi/LvE4ohoYom+BrwuX7QbhcsJhzO1AwU
Mqh7KI86cYScDlfKfCTVpTKbrJLKTSl11kbPUi3vkO1GavLhMor0NCn0gIBsz/+E
XNR1qft3bCDMnKuY1Xw8NRfHAqW0kuz21WXpIao0oSnFuT37yI31R+NjWUy5cA7U
5I2znRBMc45uDQE36vIdLsYwXxoFoCUZCuX3yvD6/LkFrtal8+dYPDSKbBRjRrgH
G7XRQ50BY26ekjbBRk55FsS+p83rF51kU6sUfsvFdMwm6i7tdnKpU1U/48YKlKSd
X+VljntOjF4=
=UvyP
-----END PGP SIGNATURE-----

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/


[Index of Archives]     [Kernel]     [Linux Crypto]     [Gnu Crypto]     [Gnu Classpath]     [Netfilter]     [Bugtraq]
  Powered by Linux