shield Recommended update for cryptsetup
SUSE-SLE-SERVER-12-SP5-2020-952


This update for cryptsetup fixes the following issues: - Update from version 2.0.5 to version 2.0.6 (jsc#SLE-5911, bsc#1165580): * Fix support of larger metadata areas in LUKS2 header. This release properly supports all specified metadata areas, as documented in LUKS2 format description (see docs/on-disk-format-luks2.pdf in archive). Currently, only default metadata area size is used (in format or convert). Later cryptsetup versions will allow increasing this metadata area size. * If AEAD (authenticated encryption) is used, cryptsetup now tries to check if the requested AEAD algorithm with specified key size is available in kernel crypto API. This change avoids formatting a device that cannot be later activated. For this function, the kernel must be compiled with the CONFIG_CRYPTO_USER_API_AEAD option enabled. Note that kernel user crypto API options (CONFIG_CRYPTO_USER_API and CONFIG_CRYPTO_USER_API_SKCIPHER) are already mandatory for LUKS2. * Fix setting of integrity no-journal flag. Now you can store this flag to metadata using --persistent option. * Fix cryptsetup-reencrypt to not keep temporary reencryption headers if interrupted during initial password prompt. * Adds early check to plain and LUKS2 formats to disallow device format if device size is not aligned to requested sector size. Previously it was possible, and the device was rejected to activate by kernel later. * Fix checking of hash algorithms availability for PBKDF early. Previously LUKS2 format allowed non-existent hash algorithm with invalid keyslot preventing the device from activation. * Allow Adiantum cipher construction (a non-authenticated length-preserving fast encryption scheme), so it can be used both for data encryption and keyslot encryption in LUKS1/2 devices. For benchmark, use: # cryptsetup benchmark -c xchacha12,aes-adiantum # cryptsetup benchmark -c xchacha20,aes-adiantum For LUKS format: # cryptsetup luksFormat -c xchacha20,aes-adiantum-plain64 -s 256 <device> The support for Adiantum will be merged in Linux kernel 4.21. For more info see the paper https://eprint.iacr.org/2018/720.

  • Release Date
    Apr 8 2020
  • References
    Bugzilla: 1165580
  • Type
    recommended
  • Severity
    moderate

cloud_download Downloads

SUSE Linux Enterprise Server 12.5 aarch64
  • Packages
    cryptsetup
    Set Up dm-crypt Based Encrypted Block Devices
    2.0.6-3.3.1
    lock rpm
    lock src
    libcryptsetup12
    Set Up dm-crypt Based Encrypted Block Devices
    2.0.6-3.3.1
    lock rpm
    libcryptsetup12-hmac
    Checksums for libcryptsetup4
    2.0.6-3.3.1
    lock rpm
SUSE Linux Enterprise Server 12.5 x86_64
SUSE Linux Enterprise Server 12.5 s390x
SUSE Linux Enterprise Server 12.5 ppc64le
  • Packages
    cryptsetup
    Set Up dm-crypt Based Encrypted Block Devices
    2.0.6-3.3.1
    lock rpm
    lock src
    libcryptsetup12
    Set Up dm-crypt Based Encrypted Block Devices
    2.0.6-3.3.1
    lock rpm
    libcryptsetup12-hmac
    Checksums for libcryptsetup4
    2.0.6-3.3.1
    lock rpm