[pkg-cryptsetup-devel] Bug#949888: Bug#949888: cryptsetup-initramfs: cryptroot hook doesn't recognize devices with authenticated encryption

Guilhem Moulin guilhem at debian.org
Wed Jan 29 19:17:28 GMT 2020


Hi,

On Sun, 26 Jan 2020 at 17:34:50 +0000, hede wrote:
> I've switched to Authenticated Encryption, i.e:
> […]
> Nevertheless, the initramfs doesn't get created as expected. 

Given upstream's loud warning in cryptsetup(8) “WARNING: All support for
authenticated modes is experimental”, fixing this is not personally
really high on my list for the moment :-P

On Sun, 26 Jan 2020 at 18:44:28 +0100, hede wrote:
> cryptsetup: WARNING: Couldn't determine cipher modules to load for sdXX_crypt 
>   (kernel crypto API format isn't supported yet)
> 
> -- it seems also here the sdXX_crypt_dif should be used!?

No, the source device is fine AFAICT, but `dmsetup table` lists its
cipher in crypto API format, for which we have no parser yet.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/admin-guide/device-mapper/dm-crypt.rst#n34

Cheers,
-- 
Guilhem.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-cryptsetup-devel/attachments/20200129/e963e523/attachment.sig>


More information about the pkg-cryptsetup-devel mailing list