[CentOS] luks and aes-ni
markus.falb at fasel.at
Sun Jan 13 04:42:39 UTC 2013
Short version: If I had a CPU with the aes-ni  feature would luks use it?
I know that Upstream Vendors Security Guide  says:
The default cipher used for LUKS (refer to cryptsetup --help) is
aes-cbc-essiv:sha256 (ESSIV - Encrypted Salt-Sector Initialization
Vector). Note that the installation program, Anaconda, uses by default
XTS mode (aes-xts-plain64)
I also found a notion in the forums that maybe only aes-cbc is using
aes-ni  and that could mean that after a install aes-ni is not used
Does anyone know about this or has experiences?
Kind Regards, Markus Falb
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 306 bytes
Desc: OpenPGP digital signature
More information about the CentOS