mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
The commands 'zkey cryptsetup' generates commands for formatting and opening volumes of type PLAIN and LUKS2. For LUKS2, if there exists an HMAC key that is associated to the same volume as the AES key, generate a 'cryptsetup luksFormat' command for combined encryption and integrity protection. This uses the '--integrity' and '--integrity-key-size' options of the 'cryptsetup luksFormat' command to specify the integrity settings. The volume key specified with '--master-key-file' must contain the encryption key and the integrity key concatenated to each other. The size of the volume key specified with '--key-size' however must be the size of the encryption key only, in bits. The 'cryptsetup luksFormat' command will internally read the whole file, use the first part as encryption key, and the second part as integrity key. The size of the second part must be specified with the '--integrity-key-size'. Note: This requires 'wrapped integrity key' support in the cryptsetup package, as well as in the dm-crypt kernel module. Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Reviewed-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>