bug-grub
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[bug #55093] Add LUKS2 support


From: dllud
Subject: [bug #55093] Add LUKS2 support
Date: Sun, 25 Nov 2018 08:32:51 -0500 (EST)
User-agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:54.0) Gecko/20100101 Firefox/54.0

URL:
  <https://savannah.gnu.org/bugs/?55093>

                 Summary: Add LUKS2 support
                 Project: GNU GRUB
            Submitted by: dllud
            Submitted on: Sun 25 Nov 2018 01:32:49 PM UTC
                Category: Security
                Severity: Major
                Priority: 5 - Normal
              Item Group: Feature Request
                  Status: None
                 Privacy: Public
             Assigned to: None
         Originator Name: 
        Originator Email: 
             Open/Closed: Open
         Discussion Lock: Any
                 Release: 
                 Release: Git master
         Reproducibility: None
         Planned Release: None

    _______________________________________________________

Details:

The LUKS2 format brings several advantages over the original LUKS format. Some
of the most important are (1) data integrity protection and (2) memory-hard
functions for key derivation.

GRUB supports the original LUKS format, allowing the setup of full-disk
encryption (FDE) schemes where GRUB decrypts an encrypted /boot partition.
Adding support for LUKS2 on GRUB would improve the security on these FDE
schemes, specially due to the two new LUKS2 advantages mentioned above.

I found several references online (Arch Wiki, Stackoverflow, etc.) to the lack
of LUKS2 support on GRUB. I decided to open this feature request since I could
find no mention of LUKS2 on both the bug tracker and the mailing lists.




    _______________________________________________________

Reply to this item at:

  <https://savannah.gnu.org/bugs/?55093>

_______________________________________________
  Message sent via Savannah
  https://savannah.gnu.org/




reply via email to

[Prev in Thread] Current Thread [Next in Thread]