From: Milan Broz <gmazyland@gmail.com>
To: Erik Logtenberg <erik@logtenberg.eu>
Cc: dm-crypt@saout.de
Subject: Re: [dm-crypt] How to increase key size of existing volume
Date: Tue, 11 Dec 2012 16:48:00 +0100 [thread overview]
Message-ID: <50C755B0.8070902@gmail.com> (raw)
In-Reply-To: <50C75290.1060003@logtenberg.eu>
On 12/11/2012 04:34 PM, Erik Logtenberg wrote:
> So there are at least two methods of extracting a master key. Now if I
> would suspect that a machine, that has a luks volume mounted, was
> compromised to the extent that someone had temporaryly gained root
> access, I would not only have to reset (all) passwords after fixing the
> security hole, but also I would have to create a new master key to be sure.
So attacker had already access to your mounted backup in plaintext
and could change anything there.
>
> Is the cryptsetup-reencrypt tool also meant for that purpose?
yes, in fact changing volume (master) key was primary use for it.
Read http://asalor.blogspot.cz/2012/08/re-encryption-of-luks-device-cryptsetup.html
(But always be sure you have backup. Backup of backup in your case :)
Milan
next prev parent reply other threads:[~2012-12-11 15:48 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-12-11 14:46 [dm-crypt] How to increase key size of existing volume Erik Logtenberg
2012-12-11 15:09 ` Arno Wagner
2012-12-11 15:34 ` Erik Logtenberg
2012-12-11 15:48 ` Milan Broz [this message]
2012-12-11 16:34 ` Arno Wagner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=50C755B0.8070902@gmail.com \
--to=gmazyland@gmail.com \
--cc=dm-crypt@saout.de \
--cc=erik@logtenberg.eu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.