A set of Cryptsetup 2.6 utilities has been released, designed for configuring disk partition encryption in Linux using the dm-crypt module. Support is provided for dm-crypt, LUKS, LUKS2, BITLK, loop-AES, and TrueCrypt/VeraCrypt partitions. The package also includes veritysetup and integritysetup utilities for configuring data integrity control mechanisms based on dm-verity and dm-integrity modules.
Belangrijke verbeteringen:
- Support has been added for storage devices encrypted using the FileVault2 mechanism, used for full disk encryption in macOS. Cryptsetup, in combination with the hfsplus driver, can now open FileVault2 encrypted USB drives in read and write mode on systems with a standard Linux kernel. Access is supported for drives with HFS+ file systems and Core Storage partitions (APFS partitions are not yet supported).
- The libcryptsetup library has removed the global memory lock through the mlockall() call, which was used to prevent sensitive data leakage to the swap area. Due to exceeding the maximum locked memory size limitation when running without root privileges, the new version applies selective locking only to the memory areas where encryption keys are stored.
- The priority of processes performing key generation (PBKDF) has been increased.
- Functions have been added for adding LUKS2 tokens and binary keys to LUKS keyslots, in addition to previously supported passphrases and key files.
- It is now possible to extract a partition key using a passphrase, key file, or token.
- The veritysetup command has added the "—use-tasklets" option, which allows for increased performance on certain systems with the Linux 6.x kernel.
Bron: opennet.ru
