[dm-crypt] help

Felix Wagner felix at wagner-felix.com
Thu Feb 25 15:50:20 CET 2016


Hello,

I tried to reencrypt my device today and was way too eager to do it
without reading everything. Heres what I did:

'cryptsetup-reencrypt -v -c aes-xts-plain64 -s
512 /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7
Reencryption will change: volume key, set cipher to aes-xts-plain64.
Enter passphrase for key slot 0:
Key slot 0 unlocked.
LUKS header backup of
device /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7 created.
Data offset for detached LUKS header must be either 0 or higher than
header size (4036 sectors). Creation of LUKS backup headers failed.

So i thought well It didn't work so lets try again:

cryptsetup-reencrypt -v -c
aes-xts-plain64 /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7
Reencryption will change: volume key, set cipher to aes-xts-plain64.
Enter passphrase for key slot 0:
Key slot 0 unlocked.
LUKS header
backup of device /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7
created.
New LUKS header for
device /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7 created.
Activated keyslot 0. 
Marking LUKS
device /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7 unusable.
Activating temporary device using old LUKS header.
Key slot 0 unlocked.
Cannot get info about
device /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7.
Activation of temporary devices failed.

Now it says that the device is not a luks device anymore. I do not have
a header backup (I'm an idiot) what I do have is the luksDump
information and I have not rebooted my system:

LUKS header information
for /dev/disk/by-uuid/2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7

Version:       	1
Cipher name:   	aes
Cipher mode:   	cbc-essiv:sha256
Hash spec:     	sha1
Payload offset:	2056
MK bits:       	256
MK digest:     	1f 82 26 80 f4 41 4f b7 17 ed 45 b0 fc f7 f9 cc
4f ee c8 7a MK salt:       	a6 cb ed 6a 5c db 46 6a 87 a1 cb 5f
62 14 8b ea 50 a0 c9 0e 93 68 56 e3 be 4f 59 a1 7b a9 84 dd 
MK iterations: 	47000
UUID:          	2ea1bb9e-a4a0-48c8-bc67-a694fa6c8cf7

Key Slot 0: ENABLED
	Iterations:         	188266
	Salt:               	a8 b6 30 8c 6a 8c f9 98 3f 1d 1d 1d
1c 22 87 b8 d1 ba 09 e5 63 06 e0 aa 1c fd d0 f9 d7 f7 3c 9c 
	Key material offset:	8
	AF stripes:            	4000
Key Slot 1: DISABLED
Key Slot 2: DISABLED
Key Slot 3: DISABLED
Key Slot 4: DISABLED
Key Slot 5: DISABLED
Key Slot 6: DISABLED
Key Slot 7: DISABLED

Now can I recreate the header so I can move my data before trying to
reencrypt again?

Please Help me and any Help is appreciated!

Sincerely
Felix the Idiot
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 473 bytes
Desc: OpenPGP digital signature
URL: <http://www.saout.de/pipermail/dm-crypt/attachments/20160225/b8b4b1a0/attachment.asc>


More information about the dm-crypt mailing list