Re: LUKS2 support for null/plaintext target
Chris Murphy <lists-zXQU9YWDTqjmlV4oE/1sFAC/[email protected]>
| Newsgroups | gmane.linux.kernel.device-mapper.dm-crypt |
|---|---|
| Message-ID | <CAJCQCtTPZHhxNv6xRB-rwVTzcS_Z6KgJtLOoJ4ZWoSiiei1nuQ@mail.gmail.com> |
On Sat, Dec 7, 2019 at 2:42 AM Michael Kjörling <[email protected]> wrote: > > On 6 Dec 2019 16:10 -0700, from [email protected] (Chris Murphy): > > The use case is to make it possible for software installers to make > > future encryption possible for a volume without need to > > repartition/reformat. > > Wouldn't a normal LUKS container with an empty passphrase meet that > use case just as well? Maybe? The main idea is to enable a distro/OS installer to avoid interactivity and UI for setting up encrypted volumes, but make it possible to setup and enabled post-install. I haven't tried it, but does 'cryptsetup luksFormat' permit an empty passphrase? And if it's empty, would 'cryptsetup luksOpen' open it without a passphrase or keyfile? -- Chris Murphy _______________________________________________ dm-crypt mailing list [email protected] https://www.saout.de/mailman/listinfo/dm-crypt