LUKS2 on disk format

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Monday, May 11, 2020 7:58 PM, Milan Broz <gmazyland@xxxxxxxxx> wrote:

> On 11/05/2020 21:07, Maksim Fomin wrote:
>
> > After reading LUKS2 on-disk format specification, I have one main
> > question - does LUKS2 data resides entirely on header, which occupies
> > first 16 mib (at most) of block device?
>
> Yes, all LUKS metadata are stored in th eLUKS heaer.
> But the LUKS header size is configurable (it is not fixed to 16MB,
> 16MB is just the default size)
> (And most of the area is reserved for keyslots, used in online reencryption.)

Can default size (16MiB) be extended after setting up LUKS partition? What is recommended size? What are reasons to increase default size?

> > Is is safe to assume that
> > there is no LUKS metadata somewhere in the middle or in the end of
> > the drive?
>
> Yes. There is small exception if you use experimental integrity protection
> (authenticated encryption) where dm-crypt is stacked over dm-integrity device.
> Then there is dm-integrity superblock in the beginning of data area.
> (But this superblovk contains only configuration of dm-integrity metadata;
> no LUKS metadata are stored there.
> This superblock is required by the kernel dm-integrity implementation.)
>
> Milan

Thanks.
_______________________________________________
dm-crypt mailing list
dm-crypt@xxxxxxxx
https://www.saout.de/mailman/listinfo/dm-crypt




[Index of Archives]     [Device Mapper Devel]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Packaging]     [Fedora SELinux]     [Yosemite News]     [KDE Users]     [Fedora Tools]     [Fedora Docs]

  Powered by Linux