From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from v4.tansi.org (ns.km33513-03.keymachine.de [87.118.94.3]) by mail.saout.de (Postfix) with ESMTP for ; Fri, 11 Feb 2011 21:14:45 +0100 (CET) Received: from gatewagner.dyndns.org (84-74-164-239.dclient.hispeed.ch [84.74.164.239]) by v4.tansi.org (Postfix) with ESMTPA id 0D0B9204E7E for ; Fri, 11 Feb 2011 21:14:45 +0100 (CET) Date: Fri, 11 Feb 2011 21:14:44 +0100 From: Arno Wagner Message-ID: <20110211201443.GA5111@tansi.org> References: <20110205065255.GB11953@tansi.org> <20110211134234.GA28853@tansi.org> <1297431885.13610.0.camel@gar-ws-etp71.garching.physik.uni-muenchen.de> <4D5557EE.1080501@redhat.com> <20110211180724.GA2366@tansi.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20110211180724.GA2366@tansi.org> Subject: Re: [dm-crypt] cryptsetup FAQ montly posting 2/2011 List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On Fri, Feb 11, 2011 at 07:07:24PM +0100, Arno Wagner wrote: > On Fri, Feb 11, 2011 at 04:38:22PM +0100, Milan Broz wrote: > > On 02/11/2011 02:44 PM, Christoph Anton Mitterer wrote: > > > On Fri, 2011-02-11 at 14:42 +0100, Arno Wagner wrote: > > >> Hmm. Does some distro use XTS mode with 512 bit keys as > > >> default? Which one? > > > Perhaps not distros, but I guess there are quite a few people using XTS > > > with two 256 bit keys. > > > > Even distros, Fedora and RHEL6 installers are using XTS with 512bit > > keys (thus AES256). > > > > (It is not crytpsetup default there, installer overrides it > > when encrypted install is selected.) > > > > Milan > > Ok, thanks. I will add a warning about non-default parameters > and also give the numbers for 512 bit in the layout section > and in the explanation on how to overwrite the keyslots. Fixed and hopefully correct. I verified the positions against a LUKS loopfile with aes-xts-plain and 512 bit keylength. Arno -- Arno Wagner, Dr. sc. techn., Dipl. Inform., CISSP -- Email: arno@wagner.name GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F ---- Cuddly UI's are the manifestation of wishful thinking. -- Dylan Evans If it's in the news, don't worry about it. The very definition of "news" is "something that hardly ever happens." -- Bruce Schneier