disabled
     �_’I|¥‰ÓMjqØ‚¦ð¬÷À¿      File not found.
  #   ˆl–ßi~”ÜZÔÒ€vã.\ÊbÑ¿Â„^y¯ÁÀ .l    Cryptsetup 2.2.0 Release Notes
==============================
Stable release with new experimental features and bug fixes.

Cryptsetup 2.2 version introduces a new LUKS2 online reencryption
extension that allows reencryption of mounted LUKS2 devices
(device in use) in the background.

Online reencryption is a complex feature. Please be sure you
have a full data backup before using this feature.

Changes since version 2.1.0
~~~~~~~~~~~~~~~~~~~~~~~~~~~

LUKS2 online reencryption
~~~~~~~~~~~~~~~~~~~~~~~~~

The reencryption is intended to provide a reliable way to change
volume key or an algorithm change while the encrypted device is still
in use.

It is based on userspace-only approach (no kernel changes needed)
that uses the device-mapper subsystem to remap active devices on-the-fly
dynamically. The device is split into several segments (encrypted by old
key, new key and so-called hotzone, where reencryption is actively running).

The flexible LUKS2 metadata format is used to store intermediate states
(segment mappings) and both version of keyslots (old and new keys).
Also, it provides a binary area (in the unused keyslot area space)
to provide recovery metadata in the case of unexpected failure during
reencryption. LUKS2 header is during the reencryption marked with
"online-reencryption" keyword. After the reencryption is finished,
this keyword is removed, and the device is backward compatible with all
older cryptsetup tools (that support LUKS2).

The recovery supports three resilience modes:

  - checksum: default mode, where individual checksums of ciphertext hotzone
    sectors are stored, so the recovery process can detect which sectors were
    already reencrypted. It requires that the device sector write is atomic.

  - journal: the hotzone is journaled in the binary area
    (so the data are written twice)

  - none: performance mode; there is no protection
    (similar to old offline reencryption)

These resilience modes are not available if reencryption uses data shift.

Note: until we have full documentation (both of the process and metadata),
please refer to Ondrej's slides (some slight details are no longer relevant)
https://okozina.fedorapeople.org/online-disk-reencryption-with-luks2-compact.pdf

The offline reencryption tool (cryptsetup-reencrypt) is still supported
for both LUKS1 and LUKS2 format.

Cryptsetup examples for reencryption
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The reencryption feature is integrated directly into cryptsetup utility
as the new "reencrypt" action (command).

There are three basic modes - to perform reencryption (change of already
existing LUKS2 device), to add encryption to plaintext device and to remove
encryption from a device (decryption).

In all cases, if existing LUKS2 metadata contains information about
the ongoing reencryption process, following reencrypt command continues
with the ongoing reencryption process until it is finished.

You can activate a device with ongoing reencryption as the standard LUKS2
device, but the reencryption process will not continue until the cryptsetup
reencrypt command is issued.


1) Reencryption
~~~~~~~~~~~~~~~
This mode is intended to change any attribute of the data encryption
(change of the volume key, algorithm or sector size).
Note that authenticated encryption is not yet supported.

You can start the reencryption process by specifying a LUKS2 device or with
a detached LUKS2 header.
The code should automatically recognize if the device is in use (and if it
should use online mode of reencryption).

If you do not specify parameters, only volume key is changed
(a new random key is generated).

# cryptsetup reencrypt <device> [--header <hdr>]

You can also start reencryption using active mapped device name:
  # cryptsetup reencrypt --active-name <name>

You can also specify the resilience mode (none, checksum, journal) with
--resilience=<mode> option, for checksum mode also the hash algorithm with
--resilience-hash=<alg> (onl