* Michael Hampton <error@xxxxxxxxxx> wrote: > It seems that clearing the keys from RAM, or replacing them in RAM with > random data, is something that should be done when a mapping is removed, > e.g. user runs cryptsetup luksClose mymapping. Wouldn't it be nice to use the in-kernel key-api (like ecryptfs)? cu, michael -- It's already too late! --------------------------------------------------------------------- dm-crypt mailing list - http://www.saout.de/misc/dm-crypt/ To unsubscribe, e-mail: dm-crypt-unsubscribe@xxxxxxxx For additional commands, e-mail: dm-crypt-help@xxxxxxxx