Re: Question on LUKS master key digest and its effect on?security

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Heinz Diehl wrote:
> On 22.09.2009, Tero Pesonen wrote: 
> As far as I understand the source, MK iterations is the iterations used to
> derive the master key via PBKDF2 (mkDigestIterations), and what you can specify by using
> "--iter-time" is the iterations used to transform a passphrase into a key
> for one of the keyslots (passwordIterations), used to unlock the master key.

--iter-time applies to PBKDF2 in keyslot calculation, NOT to MK digest verification,
here is iteration count fixed.

See PBKDF2 use in LUKS_verify_master_key() vs LUKS_set_key().

Milan

_______________________________________________
dm-crypt mailing list
dm-crypt@xxxxxxxx
http://www.saout.de/mailman/listinfo/dm-crypt

[Index of Archives]     [Device Mapper Devel]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Packaging]     [Fedora SELinux]     [Yosemite News]     [KDE Users]     [Fedora Tools]     [Fedora Docs]

  Powered by Linux