• Bug#1109117: release-notes: cryptsetup: Document cipher and password ha

    From Guilhem Moulin@21:1/5 to All on Fri Jul 11 18:20:01 2025
    XPost: linux.debian.doc

    Package: release-notes
    Severity: normal

    Hi,

    cryptsetup ≥2:2.7.0~ has new default default cipher and password hashing algorithms for plain mode, which might break some existing setups and
    therefore should be mentioned in the release notes. The following text
    from cryptsetup=2:2.7.0~rc0-1's NEWS entry can probably be copied
    verbatim.

    --8<--------------------------------------------------------------------->8--

    Default cipher and password hashing for plain mode have respectively
    been changed to aes-xts-plain64 and sha256 (from aes-cbc-essiv:sha256
    resp. ripemd160).

    The new values matches what is used for LUKS, but the change does NOT
    affect LUKS volumes.

    This is a backward incompatible change for plain mode when relying on
    the defaults, which (for plain mode only) is strongly advised against.
    For many releases the Debian wrappers found in the ‘cryptsetup’ binary
    package have spewed a loud warning for plain devices from crypttab(5)
    where ‘cipher=’ or ‘hash=’ are not explicitly specified. The
    cryptsetup(8) executable now issue such a warning as well.

    --8<--------------------------------------------------------------------->8--

    --
    Guilhem.

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmhxOIIACgkQ05pJnDwh pVK8uRAAw7UiNrpa0B3kPlhQmqFS43LyWpJwS5k3Se+W7OMy0XJplDHIk86I4y1K a4Grz41fSU7odxoOKDjQqW17PBd5PYbfpU7wUm1wZYy7K5FgXGzRUB6fb9Xh5z/z DvGKghlHz+fi/PA7f3X5GffYuQS3IlAvoexVkpmU2FwWTEEq4WJfVA0EsJt+sAkD zCwBM1wuRvV2ftrDWd2Z92AFk3V86gDR0PE7Fdlfd8ayDyI2ytDZ8H5sBqatSZTl 9Qt6VsSq/gMtnUkF/tNODimK9eJchSpcWLUGpnlIkThuVBIfbQUpjirQm5M/u65+ Ub1bGY0cpzdElRcIWi4HjMiy++eTiSnPD5KHNcKPuQHy09cVXlmUp1psv+JkpNO8 0GScHjpnxA6jgFsrfwcyCeySKx7IDMPmTc9Bq/z9HnbEiOiDiSty2tJfA5z5uASK VBifI4gLz+PhNJ4+6V5n6Hr1zcTIkOBSaO139EBYN6K5fOU8UsVJ1Ipv1/Fl5DGQ 370E0RDzfhLKv0S5DqWhiOhwhNn8s88PsIUSeRNSjXyjANuwL9IP1DE3vsd+WdX7 jLNWr8cOcR1xdr/xBRrgANuF/7QcU5mo1oob7K7lgC8rS8GcqRG2lMrNcRYs5+rS TufnxuWBFBwzXG30YZ5cSIveFd9XMa0NSDCUo23jzXlijdfSq3k=
    =XHwK
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)