From: Arno Wagner <arno@wagner.name>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] How to increase key size of existing volume
Date: Tue, 11 Dec 2012 16:09:18 +0100 [thread overview]
Message-ID: <20121211150918.GB2194@tansi.org> (raw)
In-Reply-To: <50C7473B.5090208@logtenberg.eu>
On Tue, Dec 11, 2012 at 03:46:19PM +0100, Erik Logtenberg wrote:
> Dear list,
>
> I have been using luks for quite some time, and as a result I have
> several luks volumes in use that are still based on 128 bits key sizes.
> Current default in Fedora is already upped to 256 bits and RSA even
> advices key sizes of 1024 or even 2048 for highly secure stuff.
You are confusing symmetric and assymetric keys here. 2048 bit
asymmetric is (very roughly) equivalent to 128 bit symmetric.
Have a look here for currently recomended key sizes:
http://www.keylength.com/
There is no idication that anybody can break 128 but AES
at this time or in the next few decades. Your passphrase
has likely a lot less entropy anyways and is the better
target.
> So, how do I increase the key size? In man cryptsetup I see that the
> --key-size option only applies to the create, luksFormat and loopaesOpen
> commands. Is there any way I can make this happen?
It is unnecessary. If you really want to, use your normal
backup procedure, recreate a new LUKS volume and restore
(you do have backup, right?).
There is also a re-encryption in place tool by Milan, but that is
experimental and definitely requires a current backup.
It is called "cryptsetup-reencrypt" and part of the source package
as of version 1.5.0 (current version is 1.5.1).
Arno
--
Arno Wagner, Dr. sc. techn., Dipl. Inform., Email: arno@wagner.name
GnuPG: ID: CB5D9718 FP: 12D6 C03B 1B30 33BB 13CF B774 E35C 5FA1 CB5D 9718
----
One of the painful things about our time is that those who feel certainty
are stupid, and those with any imagination and understanding are filled
with doubt and indecision. -- Bertrand Russell
next prev parent reply other threads:[~2012-12-11 15:08 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-12-11 14:46 [dm-crypt] How to increase key size of existing volume Erik Logtenberg
2012-12-11 15:09 ` Arno Wagner [this message]
2012-12-11 15:34 ` Erik Logtenberg
2012-12-11 15:48 ` Milan Broz
2012-12-11 16:34 ` Arno Wagner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20121211150918.GB2194@tansi.org \
--to=arno@wagner.name \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox