From: "Jorge Fábregas" <jorge.fabregas@gmail.com>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] MK Digest Size
Date: Sun, 10 Jul 2011 12:59:51 -0400 [thread overview]
Message-ID: <4E19DA87.5060000@gmail.com> (raw)
In-Reply-To: <4E19D356.7020504@gmail.com>
On 07/10/2011 12:29 PM, Jorge Fábregas wrote:
> I still get to see 20 HEX characters (160 bits) for the MK digest?
I'm sorry. I meant 20 pairs of HEX characters (40 chars) as they appear
nicely formatted in the luksDump output.
> Shouldn't I see 32 HEX chars (256 bits)?
Same here (64 hex characters ).
> Or is that sha256 is used in the PBKDF2 process but the function is
> instructed to deliver just 160 bits?
Ok, I'm going to try to answer myself as I just read again the latest
specification. It appears this is the case (just 160 bits even if you
use sha256) because there are just 20 bytes available for "mk-digest" in
the header.
I'm just curious: is having just 20 bytes for the digest a limitation
here? Are there any plans to expand this field in the future?
> One final thing just to make sure: is the algorithm that appears under
> "Hash spec" in the header..is this the same hash-algorithm used (along
> with PBKDF2) for the user-keys? as well as the one used with PBKDF2 for
> the MK digest?
Apparently yes.
Sorry for the noise!
Regards,
Jorge
next prev parent reply other threads:[~2011-07-10 16:59 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-07-10 16:29 [dm-crypt] MK Digest Size Jorge Fábregas
2011-07-10 16:59 ` Jorge Fábregas [this message]
2011-07-10 18:17 ` Milan Broz
2011-07-10 18:26 ` Jorge Fábregas
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4E19DA87.5060000@gmail.com \
--to=jorge.fabregas@gmail.com \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.