The release of Cryptsetup 2.6 with support for the FileVault2 encryption mechanism.

The set of Cryptsetup 2.6 utilities has been released, designed for configuring disk partition encryption in Linux using the dm-crypt module. It supports working with dm-crypt, LUKS, LUKS2, BITLK, loop-AES, and TrueCrypt/VeraCrypt partitions. The set also includes the veritysetup and integritysetup utilities for configuring data integrity checks based on the dm-verity and dm-integrity modules.

Key Improvements:

  • Support has been added for storage devices encrypted using the FileVault2 mechanism, which is employed for full disk encryption in macOS. Cryptsetup, in combination with the hfsplus driver, can now access USB drives encrypted with FileVault2 in read and write mode on systems with a standard Linux kernel. Access is supported for drives formatted with HFS+ and with Core Storage partitions (partitions using APFS are not yet supported).
  • The libcryptsetup library has been free from global memory locking via the mlockall() call that was used to prevent sensitive data leakage into swap space. Due to exceeding limits on the maximum size of lockable memory when running without root privileges, the new version implements selective locking only on those memory areas where encryption keys are stored.
  • The priority of processes involved in key generation (PBKDF) has been increased.
  • Functions have been added to include LUKS2 tokens and binary keys in the LUKS keyslot, in addition to the previously supported passphrases and key files.
  • The ability to extract the partition key using a passphrase, key file, or token has been provided.
  • In veritysetup, the option '--use-tasklets' has been added to improve performance on some systems with the Linux 6.x kernel.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster