LUKS for dm-crypt is implemented in cryptsetup. cryptsetup-luks is intended as a complete replacement for the original cryptsetup. It provides all the functionally of the original version plus all LUKS features, that are accessable by luks* action.
cryptsetup-luks-1.0.4.tar.bz2 - Stable source tarball
cryptsetup-1.0-3-i686-pc-linux-gnu-static.bz2 - Precompiled binary, version 1.0.3 for x86
cryptsetup-1.0.3-x86_64-pc-linux-gnu-static.bz2 - Precompiled binary, version 1.0.3 for amd64
(2006/10/13) |
Version 1.0.4
|
(2006/04/05) |
Version 1.0.3
|
(2006/03/15) |
Version 1.0.3-rc3
|
(2006/02/25) |
Version 1.0.3-rc2
|
(2006/02/22) |
Version 1.0.3-rc1
|
(2006/02/21) |
Version 1.0.2 - incompatible semantic change. Do not use.
|
(2005/06/20) |
Version 1.0.1
|
(2005/03/25) |
Version 1.0
|
(2005/02/10) |
Version 0.993.
|
(2005/02/09) |
Version 0.992.
|
(2005/02/08) |
Version 0.991. Changes:
|
(2005/02/05) |
Version 0.99 is out! Changes:
|
(2004/10/11) |
POC Version 5: |
(2004/07/30) |
POC Version 4: Stripped the internal Twofish implementation in favour of directly using dm-crypt. Better error handling, code cleanups aiming for ``merge-ability''. Include regression tests. |
(2004/06/22) |
POC Version 3: Proper handling of endianness for Twofish. |
(2004/06/20) |
The roadmap changed a bit: I'm not aiming for LILO/GRUB in the first place, but I will go for cryptsetup, a tool used to setup dm-crypt mappings similar to what's losetup been for cryptoloop. But since I will declare cryptoloop deprecated in a few months, I'm focusing on cryptsetup to implement a key setup procedure according to TKS1. The following patch is horrible wrt to error handling and spaghetti coding, but it is purpose is to serve as proof-of-concept patch to show, that the methods proposed are applicable. |
LUKS works by prepending a partition header (luks_phdr) to the partition, where setup information like cipher, keysize is stored as well as key slots. A key slots is holding an encrypted version of the master key. The master key is used to encrypt bulk data. It will never be stored to disk directly, but encrypted version of the master key will be stored. To be more precise, every version of the master key is encrypted by a different passphrase and stored a separate key slot. The user needs to provide one passphrase only, since any correct passphrase will restore a copy of the master key.
For simplicity, LUKS is using a fixed number of key slots. To add a new passphrase, the user has to provide an old, correct one to recover a copy of the master key, which can be encrypted to a free key slot with the new passphrase. Of course any key slot can be disabled by purging the data any time.
LUKS add 4 actions to cryptsetup, namely luksFormat, luksOpen, luksAddKey and luksDelKey. Although the names are quite self-explanatory I'll give brief examples of how to use them:
To test LUKS, you can use loop to make a blockdev out of any container file. The only requirement is that it's larger than 1mb. I'll use /dev/loop5 in the following examples.
# cryptsetup luksFormat /dev/loop5 Enter LUKS password: foobar # cryptsetup luksOpen myvolumename /dev/loop5 Enter LUKS password: foobar key slot 0 unlocked. # ls -l /dev/mapper/myvolumename brw-r----- 1 root root 254, 0 Jan 1 1970 /dev/mapper/myvolumename # cryptsetup luksClose myvolumename
# cryptsetup luksAddKey /dev/loop5 Enter any existing LUKS password: foobar key slot 0 unlocked. Enter new password for key slot: katze # cryptsetup luksOpen myvolume /dev/loop5 Enter LUKS password: katze key slot 1 unlocked.
# cryptsetup luksDelKey /dev/loop5 1 # cryptsetup luksOpen myvolume /dev/loop5 Enter LUKS password: katze Command failed: No key available with this passphrase.
cryptsetup-luks can also deal with key files. In general, files supplied by the -d switch are used for opening, and key files supplied as additional positional argument are treated to set keys. For instance, to set a key file on partition creation, call cryptsetup luksFormat blockdev keyfile. If you want to open a partition via a key file, call cryptsetup -d keyfile luksOpen blockdev mapping name. If you want add another key file using an existing key file, call cryptsetup -d existingkeyfile luksAddKey newkeyfile.
At the moment there is no way, to convert to LUKS with an in-place dd.