Hey. I just wondered the following: - Are there any security concerns (e.g. simplified statistical attacks or whatever), when one places a RAID (e.g. btrfs RAID or MD RAID) on top of dmcrypt devices? - Are there any security concerns when different dm-crypt devices (with different master-keys), e.g. ones that form a RAID as above, are created with the same keyslot passphrase/key? (Of course apart the obvious one, that one can decrypt all with the single key)? If so, does it depend on the cipher/mode/etc? I'd use aes-xts-plain64. I wouldn't think so, but just for confirmation... Perhaps in addition: As you can imagine the setup I'd like to do is e.g. something like n physical devices, each holding a LUKS container (with different master key, but all with the same keyslot key), on top of them some btrfs RAID5/6 (should that ever get stable before I die ;-) )... Probably I'll do LVM between dmcrypt and btrfs, because I'd actually want to create two independent btrfs filesystems on top of dmcrypt. Any performance or stability issues with such setup? Thanks, Chris.
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ dm-crypt mailing list dm-crypt@xxxxxxxx http://www.saout.de/mailman/listinfo/dm-crypt