[dm-crypt] Cascading encryption how-to?

Claudio Moretti flyingstar16 at gmail.com
Wed Jan 22 00:56:23 CET 2014

It was proposed in a brainstorming session[1] in 2008, but AFAIK it's never
been implemented.

I also found this[2] in which Milan said it's possible by creating LUKS
over a LUKS device, but it's hell in terms of performance and you need to
open every single device by itself (e.g. for aes-serpent-twofish you'd have
to issue 3 separate luksOpen commands).

Since it creates performance issues, it might be best for you to create a
regular LUKS device for - say  your root filesystem and then, if you need
it and your OS supports it, you can try

a) using /etc/crypttab to "luksOpen" a part of that already encrypted
partition (I haven't tried, but it might be possible), or
b) use Truecrypt to unlock encrypted files you keep somewhere.



[2] http://comments.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3020

