[pkg-cryptsetup-devel] Bug#714331: Bug#714331: cryptsetup: switch to "more secure" defaults?

Jonas Meurer jonas at freesources.org
Fri Jun 28 19:57:51 UTC 2013


tag 714331 pending
thanks

Hello Christoph

Am 28.06.2013 18:19, schrieb Christoph Anton Mitterer:
> I guess you've overseen
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=714331#10
> 
> Now that 1.6 uses new defaults... shouldn't we also adapt all
> recipes/readmes to that?
> Reopening therefore.

I don't get it. Do you even check the things you claim before sending
bugreports? Defaults for plain dm-crypt devices didn't change within the
last releases. And only examples with hardcoded ciphers, hashes,
keysizes and that kind of options _are_ plain dm-crypt devices.

I found one exception though: the luksformat script for some reason had
cipher, keysize and hash hardcoded as options for luksFormat. This is
changed in the svn repository now.

In case that you're aware of any other exceptions, please point me to
them _directly_. General statements like 'all recipes/readmes' don't
help at all.

Regards,
 jonas



More information about the pkg-cryptsetup-devel mailing list