* [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6
@ 2014-08-16 10:49 Milan Broz
2014-08-16 10:59 ` .. ink ..
2014-08-16 11:25 ` Arno Wagner
0 siblings, 2 replies; 4+ messages in thread
From: Milan Broz @ 2014-08-16 10:49 UTC (permalink / raw)
To: dm-crypt
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
The stable cryptsetup 1.6.6 release is available at
https://code.google.com/p/cryptsetup/
Please note that release packages are now located on kernel.org
https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/
Feedback and bug reports are welcomed.
Cryptsetup 1.6.6 Release Notes
==============================
Changes since version 1.6.5
* LUKS: Fix keyslot device access for devices which
do not support direct IO operations. (Regression in 1.6.5.)
* LUKS: Fallback to old temporary keyslot device mapping method
if hash (for ESSIV) is not supported by userspace crypto
library. (Regression in 1.6.5.)
* Properly activate device with discard (TRIM for SSDs)
if requested even if dm_crypt module is not yet loaded.
Only if discard is not supported by the old kernel then
the discard option is ignored.
* Fix some static analysis build warnings (scan-build).
* Report crypto lib version only once (and always add kernel
version) in debug output.
Cryptsetup API NOTE:
The direct terminal handling for passphrase entry will be removed from
libcryptsetup in next major version (application should handle it itself).
It means that you have to always either provide password in buffer or set
your own password callback function through crypt_set_password_callback().
See API documentation (or libcryptsetup.h) for more info.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJT7zcvAAoJENmwV3vZPpj8+/wQAKJ6pynllNWEsIJr0cUlibui
Ta2VZwpI9t1Dked/vmuB2Z2PoLqTQ7ykuH3JFR9nJogBXXMH/iJWGhWlEOY3AcMz
LwPTu2dE4Wa2SUdYFvtjX6BnjcxVCFZ2O02ZMDyY0N/uv6CBs+vKXbu8vCnP/LOo
6aXqU8X82AceRiK4MEvE5tSM+H6kO6idRtchFmh4pJg/W3YjFHKkIoMAxmDepiIT
1t4ALHrUKhNDLJv6b2xvRySvsd3pMHHBpYRIM5l/8+p87k/ngDNVYPeTBJhlVSZO
Q8NHPaK2lQO9aD1IazPvw9ibpBwdg0mHcfDJcPDGpum1CXy+svECh0ySK+dkNfvH
204jgD9D7IrADWnToOThmYPLkAmwIqTytniw9kl4eKYjimC/TzjeO83dmhB24Hhe
PEuFUc8xx7/8f/XJkB+oSeD/FXZGU9/nAaGOkirsiF69p85i6llRE6ADc0iDUzUD
08Wywl+9jZfbNh6w4i53EId8pZIj5NvlbikdDy/LMiZiw2s98tfXtw1x02d/2k6H
JvTWyz0L1B88ieS/jumdCwHnVRdIxh6G1Ls2SxneKIgsFpU6dhKtEiNZSpZA30fn
wc58TPU6JelAw85wV8qXXS/Ws4RNb17Vwh0Y8KO+eM2gVhGHqhrgEJ3S1iQ37rqK
y39R6EFlS4HqBymC72rF
=cXwx
-----END PGP SIGNATURE-----
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6
2014-08-16 10:49 [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6 Milan Broz
@ 2014-08-16 10:59 ` .. ink ..
2014-08-16 11:56 ` Milan Broz
2014-08-16 11:25 ` Arno Wagner
1 sibling, 1 reply; 4+ messages in thread
From: .. ink .. @ 2014-08-16 10:59 UTC (permalink / raw)
To: dm-crypt
[-- Attachment #1: Type: text/plain, Size: 569 bytes --]
On Sat, Aug 16, 2014 at 6:49 AM, Milan Broz <gmazyland@gmail.com> wrote:
> Cryptsetup API NOTE:
> The direct terminal handling for passphrase entry will be removed from
> libcryptsetup in next major version (application should handle it itself).
>
> It means that you have to always either provide password in buffer or set
> your own password callback function through crypt_set_password_callback().
> See API documentation (or libcryptsetup.h) for more info.
>
Any reason why this API is being remove?
Any new APIs will be introduced in the next major version?
[-- Attachment #2: Type: text/html, Size: 963 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6
2014-08-16 10:49 [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6 Milan Broz
2014-08-16 10:59 ` .. ink ..
@ 2014-08-16 11:25 ` Arno Wagner
1 sibling, 0 replies; 4+ messages in thread
From: Arno Wagner @ 2014-08-16 11:25 UTC (permalink / raw)
To: dm-crypt
On Sat, Aug 16, 2014 at 12:49:30 CEST, Milan Broz wrote:
> The stable cryptsetup 1.6.6 release is available at
[...]
> Cryptsetup API NOTE:
> The direct terminal handling for passphrase entry will be removed from
> libcryptsetup in next major version (application should handle it itself).
>
> It means that you have to always either provide password in buffer or set
> your own password callback function through crypt_set_password_callback().
> See API documentation (or libcryptsetup.h) for more info.
I think this is an excellent idea. Direct terminal handling is
not the job of a disk-encryption library. The way it is done
may also have quite a few details that are not readily obvious,
but can have security implications.
It may be a good idea to put the old way into the documentation
though and have some source-code fragment for it. If not too
long, I could use that as the start of a libcryptsetup section
in the FAQ or as the start of a libcryptsetup-specific FAQ.
Arno
--
Arno Wagner, Dr. sc. techn., Dipl. Inform., Email: arno@wagner.name
GnuPG: ID: CB5D9718 FP: 12D6 C03B 1B30 33BB 13CF B774 E35C 5FA1 CB5D 9718
----
A good decision is based on knowledge and not on numbers. - Plato
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6
2014-08-16 10:59 ` .. ink ..
@ 2014-08-16 11:56 ` Milan Broz
0 siblings, 0 replies; 4+ messages in thread
From: Milan Broz @ 2014-08-16 11:56 UTC (permalink / raw)
To: .. ink .., dm-crypt
On 08/16/2014 12:59 PM, .. ink .. wrote:
>
> On Sat, Aug 16, 2014 at 6:49 AM, Milan Broz <gmazyland@gmail.com <mailto:gmazyland@gmail.com>> wrote:
>
>
>
> Cryptsetup API NOTE:
> The direct terminal handling for passphrase entry will be removed from
> libcryptsetup in next major version (application should handle it itself).
>
> It means that you have to always either provide password in buffer or set
> your own password callback function through crypt_set_password_callback().
> See API documentation (or libcryptsetup.h) for more info.
>
>
>
> Any reason why this API is being remove?
In fact this was a design mistake while I was rewriting API from legacy code.
No direct terminal handling should be in library this way and AFAIK there are no
extensive users for this part of API (except cryptsetup binary itself).
So in fact this should not cause any problem at all, except need for rebuild.
(IOW it is only removal of "NULL" option in password param in API functions,
functions will stay the same - grep for deprecated warnings in libcryptsetup.h.)
> Any new APIs will be introduced in the next major version?
Probably yes, depends on which planned features we will be able to implement.
The most important task I would like to see is support for new KDF algorithms
for LUKS, based on Password hashing competition finalist.
This will require some header extension but maybe it is possible that we will
have complete new LUKS2 on-disk header version.
There will be some experimental branches for some time for testing and discussion.
Milan
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2014-08-16 11:56 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-08-16 10:49 [dm-crypt] [ANNOUNCE] cryptsetup 1.6.6 Milan Broz
2014-08-16 10:59 ` .. ink ..
2014-08-16 11:56 ` Milan Broz
2014-08-16 11:25 ` Arno Wagner
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox