ืฉื—ืจื•ืจ ืฉืœ Cryptsetup 2.7 ืขื ืชืžื™ื›ื” ื‘ื”ืฆืคื ืช ื“ื™ืกืง ื—ื•ืžืจื” ืฉืœ OPAL

ืขืจื›ื” ืฉืœ ื›ืœื™ ืขื–ืจ Cryptsetup 2.7 ืคื•ืจืกืžื” ืœื”ื’ื“ืจืช ื”ืฆืคื ื” ืฉืœ ืžื—ื™ืฆื•ืช ื“ื™ืกืง ื‘ืœื™ื ื•ืงืก ื‘ืืžืฆืขื•ืช ืžื•ื“ื•ืœ dm-crypt. ืขื‘ื•ื“ื” ืขื ืžื—ื™ืฆื•ืช dm-crypt, LUKS, LUKS2, BITLK, loop-AES ื•ืžื—ื™ืฆื•ืช TrueCrypt/VeraCrypt ื ืชืžื›ืช. ื–ื” ื›ื•ืœืœ ื’ื ืืช ื›ืœื™ ื”ืขื–ืจ veritysetup ื•-integritysetup ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื‘ืงืจื•ืช ืฉืœืžื•ืช ื ืชื•ื ื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ื”ืžื•ื“ื•ืœื™ื dm-verity ื•-dm-integrity.

ืฉื™ืคื•ืจื™ื ืขื™ืงืจื™ื™ื:

  • ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ืžื ื’ื ื•ืŸ ื”ืฆืคื ืช ื“ื™ืกืง ื—ื•ืžืจื” OPAL, ื”ื ืชืžืš ื‘ื›ื•ื ื ื™ SED (Self-Encrypting Drives) SATA ื•-NVMe ืขื ืžืžืฉืง OPAL2 TCG, ื‘ื• ื”ืชืงืŸ ื”ืฆืคื ืช ื”ื—ื•ืžืจื” ืžื•ื‘ื ื” ื™ืฉื™ืจื•ืช ื‘ื‘ืงืจ. ืžืฆื“ ืื—ื“, ื”ืฆืคื ืช OPAL ืงืฉื•ืจื” ืœื—ื•ืžืจื” ืงื ื™ื™ื ื™ืช ื•ืื™ื ื” ื–ืžื™ื ื” ืœื‘ื™ืงื•ืจืช ืฆื™ื‘ื•ืจื™ืช, ืืš ืžืฆื“ ืฉื ื™ ื”ื™ื ื™ื›ื•ืœื” ืœืฉืžืฉ ื›ืจืžื” ื ื•ืกืคืช ืฉืœ ื”ื’ื ื” ืขืœ ื”ืฆืคื ืช ืชื•ื›ื ื”, ืฉืื™ื ื” ืžื‘ื™ืื” ืœื™ืจื™ื“ื” ื‘ื‘ื™ืฆื•ืขื™ื. ื•ืื™ื ื• ื™ื•ืฆืจ ืขื•ืžืก ืขืœ ื”ืžืขื‘ื“.

    ืฉื™ืžื•ืฉ ื‘-OPAL ื‘-LUKS2 ืžืฆืจื™ืš ื‘ื ื™ื™ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ืขื ืืคืฉืจื•ืช CONFIG_BLK_SED_OPAL ื•ื”ืคืขืœืชื” ื‘- Cryptsetup (ืชืžื™ื›ื” ื‘-OPAL ืžื•ืฉื‘ืชืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ). ื”ื’ื“ืจืช LUKS2 OPAL ืžืชื‘ืฆืขืช ื‘ืื•ืคืŸ ื“ื•ืžื” ืœื”ืฆืคื ืช ืชื•ื›ื ื” - ืžื˜ื ื ืชื•ื ื™ื ืžืื•ื—ืกื ื™ื ื‘ื›ื•ืชืจืช LUKS2. ื”ืžืคืชื— ืžื—ื•ืœืง ืœืžืคืชื— ืžื—ื™ืฆื” ืœื”ืฆืคื ืช ืชื•ื›ื ื” (dm-crypt) ื•ืžืคืชื— ื‘ื™ื˜ื•ืœ ื ืขื™ืœื” ืขื‘ื•ืจ OPAL. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-OPAL ื™ื—ื“ ืขื ื”ืฆืคื ืช ืชื•ื›ื ื” (cryptsetup luksFormat --hw-opal ), ื•ื‘ื ืคืจื“ (cryptsetup luksFormat โ€”hw-opal-only ). OPAL ืžื•ืคืขืœืช ื•ืžื•ืฉื‘ืชืช ื‘ืื•ืชื• ืื•ืคืŸ (ืคืชื™ื—ื”, ืกื’ื•ืจ, luksSuspend, luksResume) ื›ืžื• ืขื‘ื•ืจ ืžื›ืฉื™ืจื™ LUKS2.

  • ื‘ืžืฆื‘ ืจื’ื™ืœ, ืฉื‘ื• ืžืคืชื— ื”ืžืืกื˜ืจ ื•ื”ื›ื•ืชืจืช ืœื ืžืื•ื—ืกื ื™ื ื‘ื“ื™ืกืง, ืฆื•ืคืŸ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื•ื aes-xts-plain64 ื•ืืœื’ื•ืจื™ืชื ื”ื’ื™ื‘ื•ื‘ sha256 (ืžืฉืชืžืฉื™ื ื‘-XTS ื‘ืžืงื•ื ื‘ืžืฆื‘ CBC, ืฉื™ืฉ ืœื• ื‘ืขื™ื•ืช ื‘ื™ืฆื•ืขื™ื, ื•ื‘-sha160 ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžืงื•ื ื”-hash ื”ืžื™ื•ืฉืŸ ripemd256 ).
  • ื”ืคืงื•ื“ื•ืช open ื•-luksResume ืžืืคืฉืจื•ืช ืœืื—ืกืŸ ืืช ืžืคืชื— ื”ืžื—ื™ืฆื” ื‘ืžื—ื–ื™ืง ืžืคืชื—ื•ืช (ืžื—ื–ื™ืง ืžืคืชื—ื•ืช) ืฉื ื‘ื—ืจ ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ. ื›ื“ื™ ืœื’ืฉืช ืœืžื—ื–ื™ืง ื”ืžืคืชื—ื•ืช, ื”ืืคืฉืจื•ืช "--volume-key-ring" ื ื•ืกืคื” ืœืคืงื•ื“ื•ืช cryptsetup ืจื‘ื•ืช (ืœื“ื•ื’ืžื” 'cryptsetup open --link-vk-to-keyring "@s::%user:testkey" tst').
  • ื‘ืžืขืจื›ื•ืช ืœืœื ืžื—ื™ืฆืช ื”ื—ืœืคื”, ื‘ื™ืฆื•ืข ืคื•ืจืžื˜ ืื• ื™ืฆื™ืจืช ื—ืจื™ืฅ ืžืคืชื— ืขื‘ื•ืจ PBKDF Argon2 ืžืฉืชืžืฉ ื›ืขืช ืจืง ื‘ืžื—ืฆื™ืช ืžื”ื–ื™ื›ืจื•ืŸ ื”ืคื ื•ื™, ืžื” ืฉืคื•ืชืจ ืืช ื”ื‘ืขื™ื” ืฉืœ ืื–ืœ ื”ื–ื™ื›ืจื•ืŸ ื”ื–ืžื™ืŸ ื‘ืžืขืจื›ื•ืช ืขื ื›ืžื•ืช ืงื˜ื ื” ืฉืœ ื–ื™ื›ืจื•ืŸ RAM.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "--external-tokens-path" ื›ื“ื™ ืœืฆื™ื™ืŸ ืืช ื”ืกืคืจื™ื™ื” ืขื‘ื•ืจ ืžื˜ืคืœื™ ืืกื™ืžื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ืฉืœ LUKS2 (ืชื•ืกืคื™ื).
  • tcrypt ื”ื•ืกื™ืคื” ืชืžื™ื›ื” ื‘ืืœื’ื•ืจื™ืชื ื”ื’ื™ื‘ื•ื‘ Blake2 ืขื‘ื•ืจ VeraCrypt.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืฆื•ืคืŸ ื‘ืœื•ืง Aria.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ Argon2 ื‘-OpenSSL 3.2 ื•ืžื™ืžื•ืฉื™ื ืฉืœ libgcrypt, ื‘ื™ื˜ื•ืœ ื”ืฆื•ืจืš ื‘-libargon.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”