[pkg-cryptsetup-devel] contribution offer - LUKS system encryption with detached header

Jim F jfelyokees at shmem.com
Wed Oct 24 01:44:18 UTC 2012


Greetings:

I modified a couple of initramfs-tools scripts to allow system 
encryption with a detached LUKS header. Everything but /boot is 
encrypted and the header can be either a partition, or a file in the 
initrd in /boot. So /boot and the header can be on a separate device, 
e.g. a USB thumb drive, and the system drive can have only encrypted 
data with no indication that it's LUKS encrypted.

I'm writing to see if the changes can be made part of the cryptsetup package.

I did this some months ago so I have the modified 1.1.3 scripts working 
with the 1.4.1 cryptsetup I built which was the latest at the time. I 
was thinking about applying the changes to 1.4.3 which is what Debian 
testing currently has. But 1.5.1 has just been released so I thought 
I'd check to see which version you suggest making the changes to.

Jim





More information about the pkg-cryptsetup-devel mailing list