From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-wr1-x429.google.com (mail-wr1-x429.google.com [IPv6:2a00:1450:4864:20::429]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.server123.net (Postfix) with ESMTPS for ; Fri, 15 Nov 2019 11:00:39 +0100 (CET) Received: by mail-wr1-x429.google.com with SMTP id r10so10288732wrx.3 for ; Fri, 15 Nov 2019 02:00:39 -0800 (PST) References: <3e97eab84e794c604a03f49ce7c66a31ca266ade@webmail> From: Milan Broz Message-ID: <18dc5c33-f93c-d4ed-cbbc-badfc0479bb8@gmail.com> Date: Fri, 15 Nov 2019 11:00:36 +0100 MIME-Version: 1.0 In-Reply-To: <3e97eab84e794c604a03f49ce7c66a31ca266ade@webmail> Content-Type: text/plain; charset="utf-8"; format="flowed" Content-Language: en-US Content-Transfer-Encoding: 8bit Subject: Re: [dm-crypt] Two questions List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: mgreger@cinci.rr.com, "'dm-crypt@saout.de'" On 13/11/2019 16:15, mgreger@cinci.rr.com wrote: > 1)   Should it be possible to use a detached header and --integrity options to cryptsetup at the same time? When I try, I get a message 'No integrity superblock detected on header.' The current design is that integrity metadata will stay on the data device (even with detached LUKS header), and these are not encrypted (encryption is not implemented, but has some support in the kernel). So with the current code, we are not going to support the detached header for authenticated encryption (integrity protection), we should fix the code to explicitly print a warning about it. (The message above is misleading.) There is still note about --integrity option being experimental, and it stays this way some time... (Maybe forever, if we find that the model that allows reply attacks on the sector level is just inadequate.) Milan