Hacker News new | past | comments | ask | show | jobs | submit login

To be specific, LUKS supports up to 8 slots. Slots can be used by different decryption mechanisms such as passwords (either typed in, or read from a keyfile), or something like clevis+tang to decrypt the disk on the correct network.

Each of these slots can then decrypt the main key to decrypt the drive data. This is done for a few reasons. This allows you to change "your disk encryption password" - or rather, passwords used for password based slots - without re-encrypting the (arbitrarily large) disk (for an arbitrarily long time). You just change an encrypted master key for a different ciphertext of the same master key.




The limit of 8 slots is only true for the older LUKS1 version




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: