Use luksSuspend/luksResume in hibernation scripts
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cryptsetup (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
The latest trunk version of cryptsetup introduces support for luksSuspend/
http://
Excerpt from manpage:
-------
luksSuspend <name>
suspends active device (all IO operations are frozen) and wipes encryption key from kernel. Kernel version 2.6.19 or later is required.
After that operation you have to use \fIluksResume\fR to reinstate encryption key (and resume device) or \fIluksClose\fR to remove mapped device.
WARNING: never try to suspend device where is the cryptsetup binary itself.
luksResume <name>
Resumes suspended device and reinstates encryption key. You will need provide passphrase identical to luksOpen command (using prompting or key file).
-------
This feature provides a way to implement secure hibernation without having to use an encrypted swap partition. It should be used in ubuntu's hibernation scripts as soon as a new stable version of cryptsetup is released.
affects: | ubuntu → cryptsetup (Ubuntu) |
Changed in cryptsetup (Ubuntu): | |
status: | New → Confirmed |
tags: | added: spam-comment |
- As soon as - is now: I just noticed that Lucid comes with a recent enough version of cryptsetup!