From patchwork Thu Mar 16 14:39:38 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Milan Broz X-Patchwork-Id: 9628419 X-Patchwork-Delegate: snitzer@redhat.com Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 3005760244 for ; Thu, 16 Mar 2017 14:40:29 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 239C72857D for ; Thu, 16 Mar 2017 14:40:29 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 17894285EE; Thu, 16 Mar 2017 14:40:29 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.3 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, RCVD_IN_DNSWL_HI, RCVD_IN_SORBS_SPAM, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id B14172857D for ; Thu, 16 Mar 2017 14:40:28 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 7DBEE7F359; Thu, 16 Mar 2017 14:40:27 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mx1.redhat.com 7DBEE7F359 Authentication-Results: ext-mx02.extmail.prod.ext.phx2.redhat.com; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ext-mx02.extmail.prod.ext.phx2.redhat.com; spf=pass smtp.mailfrom=dm-devel-bounces@redhat.com DKIM-Filter: OpenDKIM Filter v2.11.0 mx1.redhat.com 7DBEE7F359 Authentication-Results: mx1.redhat.com; dkim=fail reason="signature verification failed" (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="CawEPQH1" Received: from colo-mx.corp.redhat.com (colo-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.20]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 5896560319; Thu, 16 Mar 2017 14:40:26 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 147941853D04; Thu, 16 Mar 2017 14:40:25 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.12]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id v2GEeAf8029447 for ; Thu, 16 Mar 2017 10:40:10 -0400 Received: by smtp.corp.redhat.com (Postfix) id 10FD351DF8; Thu, 16 Mar 2017 14:40:10 +0000 (UTC) Delivered-To: dm-devel@redhat.com Received: from mx1.redhat.com (ext-mx02.extmail.prod.ext.phx2.redhat.com [10.5.110.26]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 08C5477D4B for ; Thu, 16 Mar 2017 14:40:04 +0000 (UTC) Received: from mail-wm0-f68.google.com (mail-wm0-f68.google.com [74.125.82.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id AF36E7E9E6 for ; Thu, 16 Mar 2017 14:40:03 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mx1.redhat.com AF36E7E9E6 Authentication-Results: ext-mx02.extmail.prod.ext.phx2.redhat.com; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: ext-mx02.extmail.prod.ext.phx2.redhat.com; spf=pass smtp.mailfrom=gmazyland@gmail.com DKIM-Filter: OpenDKIM Filter v2.11.0 mx1.redhat.com AF36E7E9E6 Received: by mail-wm0-f68.google.com with SMTP id x124so4468238wmf.3 for ; Thu, 16 Mar 2017 07:40:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :in-reply-to:references; bh=yycjbWfjASEZB/DjbPL+h4w0Rpab+RdYszshQqmNNx0=; b=CawEPQH187QaGO5zeMleAKmfOTEjTZY2fb92mn4ZszxiVdmJ3AGCkFlkHOHpS+EEG9 KtZgJbwmM7jATIQ4rk+uY3T85CYb7W+SK+7e0MM9f3mEHn3v2HI8OCkbyRwfkfVbNL8/ rOSeFFbb0MIZzf0BBX4kOWz9ltuZFZ1zde/iUVCElHe588tfJ8/aigFCRQ3/41rijQd1 JmdoL7rY2/niGMJSK5Qj3PxsBkmbBKYqWAp4csHzgPXJYSWZLm90P6gcu9oYWjRy0E/O kBkC80wxULUmK6fZyxKX9zlDDBifMTUewL+cMal+4EWgWbPr0Ywt6qyUUBUFcbfUjmJY K6Sg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:in-reply-to:references; bh=yycjbWfjASEZB/DjbPL+h4w0Rpab+RdYszshQqmNNx0=; b=eIcfu9uNdPTfp3nDM2DOtzWOmpw/JYdQcJTru+PCPCfwT54JSDYlM9IBW/DLQBqmZy 1PjYqlyoYKNoHYvIAoEdODKzYtqVsGZ+1lRvDR+4f5A1U2XimTT3s3XDO52gFUsR8jAh 4c/80IZ79eor4DuCphofmDDsj6nr9H+j45ZfzTZzMfYJnShQlR4YHzbCTXrbafyZBEHg L03PKoKKWzpODXA3WX+kDLX/aOqacK3SluGsC0CGtSfsH/j8WKCcKdQtGe35eHCQlsxM 5aeu1X76f/rrqe+QOYJ/JpWAGqFZUIO5hO46VCFIP8PByL6OCz4takf5S58DSLyQPLXn vGWg== X-Gm-Message-State: AFeK/H2t4XBh2kvvgDdKI9bsD/arB0KN2ACiAaT5sKBxjUqlnx/jGV+b+eiLiXAH7+AnVA== X-Received: by 10.28.170.206 with SMTP id t197mr6072612wme.61.1489675201217; Thu, 16 Mar 2017 07:40:01 -0700 (PDT) Received: from merlot.mazyland.net (nat-pool-brq-t.redhat.com. [213.175.37.10]) by smtp.googlemail.com with ESMTPSA id i203sm4553466wmf.12.2017.03.16.07.40.00 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 16 Mar 2017 07:40:00 -0700 (PDT) From: Milan Broz To: dm-devel@redhat.com Date: Thu, 16 Mar 2017 15:39:38 +0100 Message-Id: <20170316143944.19843-2-gmazyland@gmail.com> In-Reply-To: <20170316143944.19843-1-gmazyland@gmail.com> References: <20170316143944.19843-1-gmazyland@gmail.com> In-Reply-To: References: X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Thu, 16 Mar 2017 14:40:04 +0000 (UTC) X-Greylist: inspected by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Thu, 16 Mar 2017 14:40:04 +0000 (UTC) for IP:'74.125.82.68' DOMAIN:'mail-wm0-f68.google.com' HELO:'mail-wm0-f68.google.com' FROM:'gmazyland@gmail.com' RCPT:'' X-RedHat-Spam-Score: 1.07 * (BAYES_50, DCC_REPUT_13_19, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, FREEMAIL_FROM, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, RCVD_IN_SORBS_SPAM, SPF_PASS) 74.125.82.68 mail-wm0-f68.google.com 74.125.82.68 mail-wm0-f68.google.com X-Scanned-By: MIMEDefang 2.78 on 10.5.110.26 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.12 X-loop: dm-devel@redhat.com Cc: Milan Broz Subject: [dm-devel] [PATCH 1/7] dm-crypt: Fix documentation of integrity table option. X-BeenThere: dm-devel@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: device-mapper development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: dm-devel-bounces@redhat.com Errors-To: dm-devel-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.11 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Thu, 16 Mar 2017 14:40:29 +0000 (UTC) X-Virus-Scanned: ClamAV using ClamSMTP This patch updates old documentation to really implemented version, previous "hmac" option was merged to the same processing path. Signed-off-by: Milan Broz --- Documentation/device-mapper/dm-crypt.txt | 20 ++++++++------------ 1 file changed, 8 insertions(+), 12 deletions(-) diff --git a/Documentation/device-mapper/dm-crypt.txt b/Documentation/device-mapper/dm-crypt.txt index a2a6627aa659..058f26ddf875 100644 --- a/Documentation/device-mapper/dm-crypt.txt +++ b/Documentation/device-mapper/dm-crypt.txt @@ -94,20 +94,16 @@ submit_from_crypt_cpus same context. integrity:: - Calculates and verifies integrity for the encrypted device (uses - authenticated encryption). This mode requires metadata stored in per-bio - integrity structure of in size. + The device requires additional metadata per-sector stored + in per-bio integrity structure. This metadata must by provided + by underlying dm-integrity target. - This option requires that the underlying device is created by dm-integrity - target and provides exactly of per-sector metadata. + The can be "none" if metadata is used only for persistent IV. - There can by two options for . The first one is used when encryption - mode is Authenticated mode (AEAD mode), then type must be just "aead". - The second option is integrity calculated by keyed hash (HMAC), then - is for example "hmac(sha256)". - - If random IV is used (persistently stored IV in metadata per-sector), - then includes both space for random IV and authentication tag. + For Authenticated Encryption with Additional Data (AEAD) + the is "aead". An AEAD mode additionally calculates and verifies + integrity for the encrypted device. The additional space is then + used for storing authentication tag (and persistent IV if needed). Example scripts ===============