Release of Cryptsetup 2.7 with support for OPAL hardware disk encryption

A set of Cryptsetup 2.7 utilities has been released, intended for configuring disk partition encryption in Linux using the dm-crypt module. It supports working with dm-crypt partitions, LUKS, LUKS2, BITLK, loop-AES, and TrueCrypt/VeraCrypt. It also includes utilities veritysetup and integritysetup for configuring data integrity verification tools based on the dm-verity and dm-integrity modules.

Key Improvements:

  • The ability to use the OPAL hardware encryption mechanism is now implemented, supporting self-encrypting drives (SEDs) on SATA and NVMe drives with the OPAL2 TCG interface, where the hardware encryption device is directly built into the controller. On one hand, OPAL encryption is tied to proprietary hardware and is not available for public audit, but on the other hand, it can be used as an additional layer of protection over software encryption, without degrading performance or putting load on the CPU.

    To use OPAL in LUKS2, a Linux kernel build with the CONFIG_BLK_SED_OPAL option is required, along with enabling it in Cryptsetup (by default, OPAL support is disabled). Configuring LUKS2 OPAL is done similarly to software encryption — metadata is saved in the LUKS2 header. The key is split into a partition key for software encryption (dm-crypt) and an unlock key for OPAL. OPAL can be used either together with software encryption (cryptsetup luksFormat —hw-opal ) or separately (cryptsetup luksFormat —hw-opal-only ). Activation and deactivation of OPAL is performed in the same way (open, close, luksSuspend, luksResume) as for LUKS2 devices.

  • In plain mode, where the master key and header are not stored on the disk, the aes-xts-plain64 cipher and sha256 hashing algorithm are used by default (instead of the CBC mode, which has performance issues, XTS is employed, and sha256 is used instead of the outdated ripemd160 hash).
  • In the open and luksResume commands, it is allowed to store the partition key in a user-selected keyring in the kernel. To access the keyring, many cryptsetup commands have been added with the "—volume-key-keyring" option (for example, 'cryptsetup open —link-vk-to-keyring "@s::%user:testkey" tst').
  • On systems without a swap partition, when formatting or creating a key slot for PBKDF Argon2, only half of the free memory is now used, which resolved the issue of running out of available memory on systems with limited RAM.
  • The option ‘--external-tokens-path’ has been added to specify a directory for external LUKS2 token handlers (plugins).
  • Support for the Blake2 hashing algorithm has been added to tcrypt for VeraCrypt.
  • Support for the Aria block cipher has been added.
  • Support for Argon2 in implementations of OpenSSL 3.2 and libgcrypt has been added, allowing for operation without using libargon.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster