Converting to LUKS2

This forum is dedicated to advanced help and support :

Ask here your questions about advanced usage of Mageia. For example you may post here all your questions about network and automated installs, complex server configurations, kernel tuning, creating your own Mageia mirrors, and all tasks likely to be touchy even for skilled users.

Converting to LUKS2

Postby htgoebel » Jun 4th, '23, 20:05

Hi,

recently there have been quite some recommendations to convert from LUKS1 to LUKS2 and changing PDKDF to e.g. argon2id.

Is it expected to be safe converting a Mageia 8 system partition to LUKS2?

Thanks in advance.
htgoebel
 
Posts: 15
Joined: Sep 9th, '11, 20:36

Re: Converting to LUKS2

Postby doktor5000 » Jun 4th, '23, 21:39

When did you create your LUKS devices and can you post the output as root of
Code: Select all
dmsetup table
and
Code: Select all
cryptsetup luksDump
for one of those (you can obviously omit the salt and digest parts in the latter)?

Conversion should be safe but you can't always convert back to LUKS1:
https://unix.stackexchange.com/question ... -version-1
https://wiki.archlinux.org/title/dm-cry ... 2_and_back
https://curius.de/2021/01/verschuesselt ... vertieren/
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 18054
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: Converting to LUKS2

Postby morgano » Jun 4th, '23, 23:24

My device was set up using Mageia 8, and here I get

$ sudo cryptsetup luksDump /dev/sda2 | grep Version
Version: 2
At home & work Mandriva since 2006, Mageia 2011. Thinkpad T40, T43, T60, T400, T510, Dell M4400, M6300, Acer Aspire 7. Workstation using LVM, LUKS, VirtualBox, BOINC
morgano
 
Posts: 1492
Joined: Jun 15th, '11, 17:51
Location: Kivik, Sweden

Re: Converting to LUKS2

Postby htgoebel » Jun 5th, '23, 12:50

The disk was propably set up in 2016 and here is the requested output:
Code: Select all
# dmsetup table
crypt_sdaX 0 474102361 crypt aes-xts-benbi 000…00 0 8:X 4096
# cryptsetup luksDump /dev/sda6
LUKS header information for /dev/sda6

Version:        1
Cipher name:    aes
Cipher mode:    xts-benbi
Hash spec:      sha1
Payload offset: 4096



I'm curious how this additional information effects whether converting to LUKS2. Can you please explain so I learn something.

I would expect the capability to convert to depend on the capability of the Mageia kernel images and tools included in initrd, not on the age of the setup?!
htgoebel
 
Posts: 15
Joined: Sep 9th, '11, 20:36

Re: Converting to LUKS2

Postby sturmvogel » Jun 5th, '23, 15:46

htgoebel wrote:
I'm curious how this additional information effects whether converting to LUKS2. Can you please explain so I learn something.

I would expect the capability to convert to depend on the capability of the Mageia kernel images and tools included in initrd, not on the age of the setup?!

Actual Mageia versions already use LUKS 2. That‘s why Morgan asked you for your informations if you not already use LUKS 2. You installed your system 7 years ago when LUKS 1 was standard. But as you can see Mageia supports and uses LUKS 2.
sturmvogel
 
Posts: 741
Joined: Jul 30th, '12, 00:39

Re: Converting to LUKS2

Postby doktor5000 » Jun 5th, '23, 16:42

htgoebel wrote:The disk was propably set up in 2016 and here is the requested output:
Code: Select all
# cryptsetup luksDump /dev/sda6
LUKS header information for /dev/sda6

Version:        1


I'm curious how this additional information effects whether converting to LUKS2. Can you please explain so I learn something.

Your sda6 is still LUKS1 and you'd need to convert that (if you want that).
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 18054
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: Converting to LUKS2

Postby htgoebel » Jun 5th, '23, 18:49

Well, I know and this is why I asked whether is it save to convert :-\

sturmvogel wrote:Actual Mageia versions already use LUKS 2.

This was the relevant information I need. Many thnaks.
Last edited by isadora on Jun 5th, '23, 18:54, edited 1 time in total.
Reason: Quoting the former message is not appropriate
htgoebel
 
Posts: 15
Joined: Sep 9th, '11, 20:36


Return to Advanced support

Who is online

Users browsing this forum: No registered users and 1 guest