From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mx4-phx2.redhat.com (mx4-phx2.redhat.com [209.132.183.25]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 16 Dec 2010 19:27:05 +0100 (CET) Received: from mail03.corp.redhat.com (zmail07.collab.prod.int.phx2.redhat.com [10.5.5.47]) by mx4-phx2.redhat.com (8.13.8/8.13.8) with ESMTP id oBGIR4rN022702 for ; Thu, 16 Dec 2010 13:27:04 -0500 Date: Thu, 16 Dec 2010 13:27:04 -0500 (EST) From: Matthew Mosesohn Message-ID: <1161837945.960861292524024535.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> In-Reply-To: <930971623.959051292522978225.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_36945_1980042151.1292524024534" Subject: [dm-crypt] Security of cloned disks (with changed passphrases) List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de ------=_Part_36945_1980042151.1292524024534 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit I am wondering if I perform this setup (cryptsetup version 1.1.2), how much risk do I expose my systems to? Step 1: Create a base install that is encrypted with a fixed passphrase Step 2: Create a disk image of this installed system Step 3: Deploy image on N number of other systems Step 4: Change the passphrase on all deployed systems What happens if the passphrase becomes compromised on one of these systems? Can that person gain the original LUKS AES key to the disk and therefore obtain a way to break into all of the other systems? If yes, is there anything to do on each cloned system to improve security? -- Best Regards, Matthew Mosesohn ------=_Part_36945_1980042151.1292524024534 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 7bit
I am wondering if I perform this setup (cryptsetup version 1.1.2), how much risk do I expose my systems to?

Step 1: Create a base install that is encrypted with a fixed passphrase
Step 2: Create a disk image of this installed system
Step 3: Deploy image on N number of other systems
Step 4: Change the passphrase on all deployed systems

What happens if the passphrase becomes compromised on one of these systems?  Can that person gain the original LUKS AES key to the disk and therefore obtain a way to break into all of the other systems?

If yes, is there anything to do on each cloned system to improve security?

--
Best Regards,
Matthew Mosesohn
------=_Part_36945_1980042151.1292524024534--