Cryptsetup 2.8 is available with support for inline metadata storage mode.

A set of Cryptsetup 2.8 utilities has been released, designed for configuring disk partition encryption in Linux using the dm-crypt module. It supports working with dm-crypt, LUKS, LUKS2, BITLK, loop-AES, and TrueCrypt/VeraCrypt partitions. Also included are the veritysetup and integritysetup utilities for configuring data integrity checks based on dm-verity and dm-integrity modules.

Key Improvements:

  • Support for inline mode has been added, allowing the use of extended sectors with an additional area for metadata storage. Such sectors are supported by some NVMe drives, enabling both data and a metadata block (for example, 4096 bytes for data + 64 bytes for metadata) to be placed in a sector.

    Cryptsetup can utilize the metadata area in the sector to store operational information, eliminating the need for an additional layer based on dm-integrity that is responsible for allocating space for metadata. As a result, it is possible to forgo maintaining a dm-integrity log, which serves as a bottleneck negatively affecting performance. The Linux kernel has the capabilities required for inline mode starting from release 6.11. An option ā€˜ā€”integrity-inline’ has been added to enable inline mode.

  • The API Keyslot Context has been prepared for manipulating key slots. The new API has expanded the functionality of many existing commands with features such as token activation, resuming work with a suspended encrypted device, and performing re-encryption.
  • The cryptsetup utility has been updated with the options ā€˜ā€”key-description’ and ā€˜ā€”new-key-description’ for attaching descriptions to keys.
  • A feature to resume a suspended re-encryption operation has been added, using a token and partition keys.
  • A check for corruption of LUKS keyslot areas has been added to the ā€˜repair’ command implementation.
  • The veritysetup command now includes the option ā€˜ā€”error-as-corruption’, where any errors are handled as data corruption, allowing for either a reboot or a transition to a panic state when using the ā€˜ā€”restart-on-corruption’ and ā€˜ā€”panic-on-corruption’ options.
  • An optional capability to use the Mbed-TLS library as a crypto backend has been added (enabled when built with the option ā€˜ā€”with-crypto_backend=mbedtls’).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers šŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster