[ANNOUNCE] cryptsetup 2.3.1
Milan Broz <[email protected]>
| Newsgroups | gmane.linux.kernel.device-mapper.dm-crypt |
|---|---|
| Message-ID | <[email protected]> |
The cryptsetup 2.3.1 stable release is available at
https://gitlab.com/cryptsetup/cryptsetup
Please note that release packages are located on kernel.org
https://www.kernel.org/pub/linux/utils/cryptsetup/v2.3/
Feedback and bug reports are welcomed.
Cryptsetup 2.3.1 Release Notes
==============================
Stable bug-fix release.
All users of cryptsetup 2.x should upgrade to this version.
Changes since version 2.3.0
~~~~~~~~~~~~~~~~~~~~~~~~~~~
* Support VeraCrypt 128 bytes passwords.
VeraCrypt now allows passwords of maximal length 128 bytes
(compared to legacy TrueCrypt where it was limited by 64 bytes).
* Strip extra newline from BitLocker recovery keys
There might be a trailing newline added by the text editor when
the recovery passphrase was passed using the --key-file option.
* Detect separate libiconv library.
It should fix compilation issues on distributions with iconv
implemented in a separate library.
* Various fixes and workarounds to build on old Linux distributions.
* Split lines with hexadecimal digest printing for large key-sizes.
* Do not wipe the device with no integrity profile.
With --integrity none we performed useless full device wipe.
* Workaround for dm-integrity kernel table bug.
Some kernels show an invalid dm-integrity mapping table
if superblock contains the "recalculate" bit. This causes
integritysetup to not recognize the dm-integrity device.
Integritysetup now specifies kernel options such a way that
even on unpatched kernels mapping table is correct.
* Print error message if LUKS1 keyslot cannot be processed.
If the crypto backend is missing support for hash algorithms
used in PBKDF2, the error message was not visible.
* Properly align LUKS2 keyslots area on conversion.
If the LUKS1 payload offset (data offset) is not aligned
to 4 KiB boundary, new LUKS2 keyslots area in now aligned properly.
* Validate LUKS2 earlier on conversion to not corrupt the device
if binary keyslots areas metadata are not correct.
_______________________________________________
dm-crypt mailing list
[email protected]
https://www.saout.de/mailman/listinfo/dm-crypt
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEKikYJD/eRmSNBob52bBXe9k+mPwFAl5p+5sACgkQ2bBXe9k+ mPzP1A/7BeqRpVLOMeafb5eZjAsy/nF4IiKr4WmpHvCxGxfUOiV7/0prywzloFHH xRUp/MMwDz9DuLtnD8ciPOHHr+ehFfTASvM7ij6w8ZjZh4k1iBxR9nA0Xyd8DkkY NLHpHH3tTEOyLthvRUFoWroH7HhQje9jRJM/Opc6pDFyHzWKTwzpXjDWubTVee/c nLDwijWmtCUKwCHqFaKm9MMdLoj4d7RmpwFOUNHZKHkRZ4dsLu/zkKECxlUN3cQl jzd6et+EVwY1LHiPmaMvSA76ILWNlAJqOUMdK5HrJXX/6cZZIaZcDibSwjPKIFBp mXrZxXnFmGQaH4WwPWDlDgxIvd1SMGIRQVXb2V6OlVggyr6OmCRBtwYRvri8V9ek QdOduIXvGLg4rqwkH4rS/INdSnAd+08/zh0/4fPINUHXmfmQTXSTw1qfhvR4KxzU FeOh6YdkMYhW5KhIxIpZ0gAUAnOupckSkJhmtnrNe4aIScDJdn9i8pLCk1scXako wHrJDvynHUGoRT9RWzlZ18XN0vRRl5kCWhx/O5dBl3Vao48IXEIKof4HhQ47QdWt 1Lk6QWJYGnuGis7lRSOyF2AJDvhH2LoKPU4EMVxkx5iNOTaYir67STwGZS169blM tAkyFLM0W7XrQnj2oYCM+TgzDBGTb6z0EnkyMy38nD7iapLrrrw= =88tZ -----END PGP SIGNATURE-----