From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mx4-phx2.redhat.com (mx4-phx2.redhat.com [209.132.183.25]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 16 Dec 2010 19:27:05 +0100 (CET) Received: from mail03.corp.redhat.com (zmail07.collab.prod.int.phx2.redhat.com [10.5.5.47]) by mx4-phx2.redhat.com (8.13.8/8.13.8) with ESMTP id oBGIR4rN022702 for ; Thu, 16 Dec 2010 13:27:04 -0500 Date: Thu, 16 Dec 2010 13:27:04 -0500 (EST) From: Matthew Mosesohn Message-ID: <1161837945.960861292524024535.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> In-Reply-To: <930971623.959051292522978225.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_36945_1980042151.1292524024534" Subject: [dm-crypt] Security of cloned disks (with changed passphrases) List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de ------=_Part_36945_1980042151.1292524024534 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit I am wondering if I perform this setup (cryptsetup version 1.1.2), how much risk do I expose my systems to? Step 1: Create a base install that is encrypted with a fixed passphrase Step 2: Create a disk image of this installed system Step 3: Deploy image on N number of other systems Step 4: Change the passphrase on all deployed systems What happens if the passphrase becomes compromised on one of these systems? Can that person gain the original LUKS AES key to the disk and therefore obtain a way to break into all of the other systems? If yes, is there anything to do on each cloned system to improve security? -- Best Regards, Matthew Mosesohn ------=_Part_36945_1980042151.1292524024534 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 7bit
I am wondering if I perform this setup (cryptsetup version 1.1.2), how much risk do I expose my systems to?

Step 1: Create a base install that is encrypted with a fixed passphrase
Step 2: Create a disk image of this installed system
Step 3: Deploy image on N number of other systems
Step 4: Change the passphrase on all deployed systems

What happens if the passphrase becomes compromised on one of these systems?  Can that person gain the original LUKS AES key to the disk and therefore obtain a way to break into all of the other systems?

If yes, is there anything to do on each cloned system to improve security?

--
Best Regards,
Matthew Mosesohn
------=_Part_36945_1980042151.1292524024534-- From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mx4-phx2.redhat.com (mx4-phx2.redhat.com [209.132.183.25]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 16 Dec 2010 19:52:06 +0100 (CET) Received: from mail03.corp.redhat.com (zmail07.collab.prod.int.phx2.redhat.com [10.5.5.47]) by mx4-phx2.redhat.com (8.13.8/8.13.8) with ESMTP id oBGI9cce020136 for ; Thu, 16 Dec 2010 13:09:38 -0500 Date: Thu, 16 Dec 2010 13:09:38 -0500 (EST) From: Matthew Mosesohn Message-ID: <930971623.959051292522978225.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> In-Reply-To: <175017369.959011292522941452.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_36882_1896975855.1292522978224" Subject: [dm-crypt] Security of cloned disks (with changed passphrases) List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de ------=_Part_36882_1896975855.1292522978224 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit I am wondering if I perform this setup (cryptsetup version 1.1.2), how much risk do I expose my systems to? Step 1: Create a base install that is encrypted with a fixed passphrase Step 2: Create a disk image of this installed system Step 3: Deploy image on N number of other systems Step 4: Change the passphrase on all deployed systems What happens if the passphrase becomes compromised on one of these systems? Can that person gain the original LUKS AES key to the disk and therefore obtain a way to break into all of the other systems? If yes, is there anything to do on each cloned system to improve security? -- Best Regards, Matthew Mosesohn ------=_Part_36882_1896975855.1292522978224 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 7bit
I am wondering if I perform this setup (cryptsetup version 1.1.2), how much risk do I expose my systems to?

Step 1: Create a base install that is encrypted with a fixed passphrase
Step 2: Create a disk image of this installed system
Step 3: Deploy image on N number of other systems
Step 4: Change the passphrase on all deployed systems

What happens if the passphrase becomes compromised on one of these systems?  Can that person gain the original LUKS AES key to the disk and therefore obtain a way to break into all of the other systems?

If yes, is there anything to do on each cloned system to improve security?

--
Best Regards,
Matthew Mosesohn
------=_Part_36882_1896975855.1292522978224-- From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) by mail.saout.de (Postfix) with ESMTP for ; Thu, 16 Dec 2010 20:11:27 +0100 (CET) Received: from int-mx02.intmail.prod.int.phx2.redhat.com (int-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.12]) by mx1.redhat.com (8.13.8/8.13.8) with ESMTP id oBGJBQLp032247 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Thu, 16 Dec 2010 14:11:26 -0500 Received: from [10.36.10.76] (vpn2-10-76.ams2.redhat.com [10.36.10.76]) by int-mx02.intmail.prod.int.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id oBGJBOn4005935 for ; Thu, 16 Dec 2010 14:11:25 -0500 Message-ID: <4D0A645C.7070908@redhat.com> Date: Thu, 16 Dec 2010 20:11:24 +0100 From: Milan Broz MIME-Version: 1.0 References: <1161837945.960861292524024535.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> In-Reply-To: <1161837945.960861292524024535.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Subject: Re: [dm-crypt] Security of cloned disks (with changed passphrases) List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On 12/16/2010 07:27 PM, Matthew Mosesohn wrote: > I am wondering if I perform this setup (cryptsetup version 1.1.2), > how much risk do I expose my systems to? > > Step 1: Create a base install that is encrypted with a fixed > passphrase Step 2: Create a disk image of this installed system Step > 3: Deploy image on N number of other systems Step 4: Change the > passphrase on all deployed systems > > What happens if the passphrase becomes compromised on one of these > systems? Can that person gain the original LUKS AES key to the disk > and therefore obtain a way to break into all of the other systems? Yes, cloning the whole device including LUKS header and changing just the passphrase keeps the same volume key exposes all system to risk. Everyone with any passphrase to any system can decrypt volume key and get access to all cloned systems. Moreover, everyone can check which sectors changed even without any passphrase knowledge as a bonus (just check which sectors changed). The proper way is create new LUKS header (with new passphrase and volume key) and clone _content_ (plaintext device) of encrypted disk. Still if you know origin disc content you are in better position that when you know nothing about the disc but this problem can be probably ignored in most use cases (secure stolen laptop etc) Milan From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mta-blr1.sasken.com (mta-blr1.sasken.com [203.200.200.72]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by mail.saout.de (Postfix) with ESMTPS for ; Fri, 17 Dec 2010 05:55:45 +0100 (CET) From: Nargis Khan Date: Fri, 17 Dec 2010 10:24:11 +0530 Message-ID: <91969FDC112D9742BC923801900F56611A157A9562@EXGMBX01.sasken.com> References: <930971623.959051292522978225.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com>, <1161837945.960861292524024535.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> In-Reply-To: <1161837945.960861292524024535.JavaMail.root@zmail07.collab.prod.int.phx2.redhat.com> Content-Language: en-US Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Subject: Re: [dm-crypt] Security of cloned disks (with changed passphrases) List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Matthew Mosesohn , "dm-crypt@saout.de" Hi Everyone, I have a dm-crypt compiled kernel image.I have also compiled Cryptsetup.Thr= ough what commands can I link both?? As I am quite new in this field,i have no idea at all. Please help. Regards, Nargis ________________________________________ From: dm-crypt-bounces@saout.de [dm-crypt-bounces@saout.de] On Behalf Of Ma= tthew Mosesohn [mmosesoh@redhat.com] Sent: Thursday, December 16, 2010 11:57 PM To: dm-crypt@saout.de Subject: [dm-crypt] Security of cloned disks (with changed passphrases) I am wondering if I perform this setup (cryptsetup version 1.1.2), how much= risk do I expose my systems to? Step 1: Create a base install that is encrypted with a fixed passphrase Step 2: Create a disk image of this installed system Step 3: Deploy image on N number of other systems Step 4: Change the passphrase on all deployed systems What happens if the passphrase becomes compromised on one of these systems?= Can that person gain the original LUKS AES key to the disk and therefore = obtain a way to break into all of the other systems? If yes, is there anything to do on each cloned system to improve security? -- Best Regards, Matthew Mosesohn SASKEN BUSINESS DISCLAIMER: This message may contain confidential, propriet= ary or legally privileged information. In case you are not the original int= ended Recipient of the message, you must not, directly or indirectly, use, = disclose, distribute, print, or copy any part of this message and you are r= equested to delete it and inform the sender. Any views expressed in this me= ssage are those of the individual sender unless otherwise stated. Nothing c= ontained in this message shall be construed as an offer or acceptance of an= y offer by Sasken Communication Technologies Limited ("Sasken") unless sent= with that express intent and with due authority of Sasken. Sasken has take= n enough precautions to prevent the spread of viruses. However the company = accepts no liability for any damage caused by any virus transmitted by this= email. Read Disclaimer at http://www.sasken.com/extras/mail_disclaimer.html