Milan Broz
8da37ce4b0
Update test (removal of get_last_error).
2015-11-20 09:18:58 +01:00
Milan Broz
9cbe74c2db
Remove last error handling (error is logged).
2015-11-20 09:18:58 +01:00
Milan Broz
002ba59ff1
Simplify tools_get_key.
2015-11-20 09:18:31 +01:00
Milan Broz
d293de579a
Fix various backward incompatibilities in password processing.
2015-11-20 09:18:31 +01:00
Milan Broz
4aea3b81ee
Remove password callback interface.
...
This was a design mistake and should not be handled inside libcryptsetup code.
2015-11-20 09:18:31 +01:00
Milan Broz
5293f5aae1
Move terminal handling to tools wrapper.
2015-11-20 09:18:31 +01:00
Milan Broz
39698fa6b7
Remove terminal input from libcryptsetup API calls.
2015-11-20 09:18:31 +01:00
Milan Broz
e80f9b5c65
Remove key_from_file wrapper.
2015-11-20 09:18:31 +01:00
Milan Broz
f0986be2e3
Export crypt_keyfile_read().
2015-11-20 09:18:31 +01:00
Milan Broz
252cdef110
Extract keyfile read from get_key wrapper.
2015-11-20 09:18:31 +01:00
Milan Broz
8ab9c9dc68
Update po files.
2015-11-20 08:55:36 +01:00
Milan Broz
a5363f184c
Set devel version.
2015-11-03 13:41:14 +01:00
Milan Broz
e2637c5d49
Prepare version 1.7.0.
v1_7_0
2015-11-03 13:32:24 +01:00
Milan Broz
4a72695241
Update README.md.
2015-11-03 13:15:42 +01:00
Milan Broz
af31af5e3d
Add 1.7.0 Release notes.
2015-11-03 13:03:55 +01:00
Milan Broz
2aa0bb7eac
Update LUKS default hash and kernel crypto api hash check.
2015-11-02 21:07:49 +01:00
Milan Broz
8ae62715a8
Update po files.
2015-11-02 21:07:20 +01:00
Arno Wagner
506ba27358
Synced to Wiki version with new markup stripper.
2015-11-02 20:37:47 +01:00
Milan Broz
4384e50578
Decrease iteration time for compat tests.
2015-10-29 12:44:15 +01:00
Milan Broz
1623ee71ab
Remove experimental warning for reencrypt tool.
2015-10-29 12:16:37 +01:00
Milan Broz
f425d07ec7
Switch to sha256 and 2s iteration time for LUKS devices defaults.
...
Note that no longer using SHA1 is just to prevent situation
when it is no longer available on hardened systems, there is
no known security problem (finding collisions is not a problem for LUKS).
Increasing iteration time is in combination with PBKDF2 benchmark
fixes try to keep PBKDF2 iteration count still high enough and
also acceptable for users.
(Long term is to replace PBKDF2 algorithm with Password Hashing
Competiton winner.).
N.B. distributions can change these defaults in compilation time.
2015-10-29 12:08:14 +01:00
Ondrej Kozina
d260be02d4
tcrypt: fix potential memory leak on error path
2015-10-29 12:06:40 +01:00
Milan Broz
4609fd87d7
Fix PBKDF2 iteration benchmark for longer key sizes.
...
The previous PBKDF2 benchmark code did not take into account
output key length.
For SHA1 (with 160-bits output) and 256-bit keys (and longer)
it means that the final value was higher than it should be.
For other hash algorithms (like SHA256 or SHA512) it caused
that iteration count was smaller (in comparison to SHA1) than
expected for the requested time period.
This patch fixes the code to use key size for the formatted device
(or default LUKS key size if running in informational benchmark mode).
Thanks to A.Visconti, S.Bossi, A.Calo and H.Ragab
(http://www.club.di.unimi.it/ ) for point this out.
(Based on "What users should know about Full Disk Encryption
based on LUKS" paper to be presented on CANS2015).
2015-10-29 11:52:18 +01:00
Milan Broz
9e90d91446
Update da.po.
2015-10-12 15:16:25 +02:00
Milan Broz
7bbf0796b5
Merge branch 'glebfm/cryptsetup-passwdqc'
2015-10-12 14:17:55 +02:00
Milan Broz
fe3148f074
Tweak passwdqc use.
2015-10-12 14:15:03 +02:00
Gleb Fotengauer-Malinovskiy
5e9c27118e
Add optional libpasswdqc support for new LUKS passwords
...
If password is entered through terminal (no keyfile specified) and
cryptsetup is compiled with --enable-passwdqc[=/etc/passwdqc.conf],
default system passwdqc settings are used to check password quality.
2015-10-08 17:30:26 +00:00
Milan Broz
c362ba9293
Update it.po.
2015-09-24 10:20:31 +02:00
Milan Broz
e97048dd32
Set devel version.
2015-09-08 15:17:16 +02:00
Milan Broz
5ea0ba61be
Add release notes for 1.6.7 link.
2015-09-08 13:11:36 +02:00
Milan Broz
7ae863e380
Prepare version 1.6.8.
v1_6_8
2015-09-08 12:53:48 +02:00
Milan Broz
f238e8c075
Add 1.6.8 release notes.
2015-09-08 12:26:54 +02:00
Milan Broz
7d9a14fd24
Fix some signed/unsigned compiler warnings.
2015-09-08 08:12:07 +02:00
Milan Broz
2f964d95d8
Fix benign warning in clang analysis output.
2015-09-08 07:54:03 +02:00
Milan Broz
00f419e5ea
Add zh_CN.po.
2015-09-05 13:07:05 +02:00
Milan Broz
cc698dcde3
Update es.po.
2015-08-31 10:08:36 +02:00
Milan Broz
edced6cfed
Update nl.po.
2015-08-30 12:58:33 +02:00
Milan Broz
4fb11976d2
Update po files.
2015-08-28 12:59:59 +02:00
Milan Broz
68ba5b2b36
Update fr.po.
2015-08-27 16:22:13 +02:00
Milan Broz
65fa22ff23
Override password quality check if used cipher is cipher_null.
2015-08-27 16:21:07 +02:00
Milan Broz
c25d81d2a1
Update po files.
2015-08-27 07:53:13 +02:00
Milan Broz
57d16a7a55
Fix misleading error messages in reencrypt.
2015-08-26 16:15:11 +02:00
Milan Broz
def397d0c8
Update libcryptsetup.h comments.
2015-08-26 16:10:10 +02:00
Milan Broz
7843415243
Move string_to_size to userspace tools.
2015-08-26 12:42:25 +02:00
Milan Broz
5a8b045bdd
Properly support stdin "-" handling for luksAddKey.
2015-08-26 12:41:20 +02:00
Milan Broz
ab62f45d57
Use stdin and "-" file check wrapper.
2015-08-26 10:54:33 +02:00
Milan Broz
e521edd6ca
Print cryptsetup library version in crypto init.
2015-08-26 10:42:47 +02:00
Milan Broz
3a0293a299
Do not link FIPS helper to cryptsetup anymore.
...
Just print info about FIPS mode in RNG init.
2015-08-26 10:36:49 +02:00
Milan Broz
8a4db1ad7b
Ingore Whirlpool test instead of failing.
2015-08-26 10:35:38 +02:00
Milan Broz
1aba9ab444
Cryptsetup resize will try resize also underlying device.
...
If encrypted device is file-backed, resize should try to resize
underlying loop device as well.
2015-08-19 14:16:42 +02:00