Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 503280

Summary: =sys-fs/cryptsetup-1.6.4 version bump
Product: Gentoo Linux Reporter: Manuel Rüger (RETIRED) <mrueg>
Component: [OLD] Core systemAssignee: Gentoo's Team for Core System packages <base-system>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://code.google.com/p/cryptsetup/wiki/Cryptsetup164
Whiteboard:
Package list:
Runtime testing required: ---

Description Manuel Rüger (RETIRED) gentoo-dev 2014-03-03 02:03:47 UTC
Released on 2014-02-27. 


Cryptsetup 1.6.4 Release Notes
Changes since version 1.6.3

    Implement new erase (with alias luksErase) command. 

    The erase cryptsetup command can be used to permanently erase all keyslots and make the LUKS container inaccessible.
    (The only way to unlock such device is to use LUKS header backup created before erase command was used.) 

    You do not need to provide any password for this operation. 

    This operation is irreversible. 

    Add internal "whirlpool_gcryptbug hash" for accessing flawed
    Whirlpool hash in gcrypt (requires gcrypt 1.6.1 or above). 

    The gcrypt version of Whirlpool hash algorithm was flawed in some situations. 

    This means that if you used Whirlpool in LUKS header and upgraded to new gcrypt library your LUKS container become inaccessible. 

    Please refer to cryptsetup FAQ for detail how to fix this situation. 

    Allow to use --disable-gcrypt-pbkdf2 during configuration to force use internal PBKDF2 code. 

    Require gcrypt 1.6.1 for imported implementation of PBKDF2
    (PBKDF2 in gcrypt 1.6.0 is too slow). 

    Add --keep-key to cryptsetup-reencrypt. 

    This allows change of LUKS header hash (and iteration count) without the need to reencrypt the whole data area.
    (Reencryption of LUKS header only without master key change.) 

    By default verify new passphrase in luksChangeKey and luksAddKey commands (if input is from terminal). 

    Fix memory leak in Nettle crypto backend. 

    Support --tries option even for TCRYPT devices in cryptsetup. 

    Support --allow-discards option even for TCRYPT devices.
    (Note that this could destroy hidden volume and it is not suggested by original TrueCrypt security model.) 

    Link against -lrt for clock_gettime to fix undefined reference to clock_gettime error (introduced in 1.6.2). 

    Fix misleading error message when some algorithms are not available. 

    Count system time in PBKDF2 benchmark if kernel returns no self usage info.
    (Workaround to broken getrusage() syscall with some hypervisors.)
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-03-03 09:28:16 UTC
+*cryptsetup-1.6.4 (03 Mar 2014)
+
+  03 Mar 2014; Lars Wendler <polynomial-c@gentoo.org> -cryptsetup-1.1.2.ebuild,
+  -cryptsetup-1.4.1.ebuild, -cryptsetup-1.4.1-r1.ebuild,
+  -cryptsetup-1.4.2.ebuild, -cryptsetup-1.6.0.ebuild, -cryptsetup-1.6.1.ebuild,
+  +cryptsetup-1.6.4.ebuild, -files/1.1.0-libudev.patch,
+  -files/1.1.0_rc3-static-no-selinux.patch, -files/1.4.1-dmcrypt.rc:
+  Version bump (bug #503280). Removed old.
+