public inbox for dm-crypt@saout.de
 help / color / mirror / Atom feed
* [dm-crypt] detached LUKS header size
@ 2019-11-23  5:43 Fourhundred Thecat
  2019-11-23  8:21 ` Arno Wagner
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Fourhundred Thecat @ 2019-11-23  5:43 UTC (permalink / raw)
  To: dm-crypt

Hello,

I am using full-disk encryption with detached LUKS header.

The LUKS header file itself is stored on an initrd image which I boot
from USB, and then I decrypt the cryptsetup partition on my disk and
chroot into it.

The initrd system that I boot is very minimal, around 8MB in size.

The LUKS image, being 2MB, is making the initrd image needlessly bigger.

And the new LUKS2 format seems to use even larger header (10MB ?)

From what I understand, the keyslots themselves only use up 4KB of
space, and the rest is used for "antiforensic stripes".

This is probably a good idea when LUKS header is stored on disk together
with the cryptsetup partition.

But when using detached header, which is never stored on disk, this
makes less sense

Thus my question:

is it possible, somehow, to reduce the size of the LUKS header to
absolute minimum (4KB ?), when I don't need the antiforensic stripes ?

thank you,

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2019-11-25 15:27 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-11-23  5:43 [dm-crypt] detached LUKS header size Fourhundred Thecat
2019-11-23  8:21 ` Arno Wagner
2019-11-24  6:34   ` Fourhundred Thecat
2019-11-24  8:16     ` Arno Wagner
2019-11-24  8:39       ` Milan Broz
2019-11-23  8:48 ` Milan Broz
2019-11-25  4:34   ` Fourhundred Thecat
2019-11-25 13:55     ` Milan Broz
2019-11-25 15:17       ` Fourhundred Thecat
2019-11-25 15:27         ` Milan Broz
2019-11-24 11:46 ` Michael Kjörling

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox