[dm-crypt] What are the supported ciphers

Ralf Ramsauer ralf+dm at ramses-pyramidenbau.de
Fri May 1 20:12:14 CEST 2015

Hi David,

you can use

    cat /proc/crypto

this is part of an example output:

    driver       : xts-aes-aesni
    module       : kernel
    priority     : 400
    refcnt       : 4
    selftest     : passed
    type         : ablkcipher
    async        : yes
    blocksize    : 16
    min keysize  : 32
    max keysize  : 64
    ivsize       : 16
    geniv        : <default>

which means that this is the AES cipher driven in the XTS mode of
operation. The keysize may be 32, 48 or 64 Byte. Last you need a
initialisation vector generation algorithm (like ESSIV or Plain) which
generates (at least) 16 Bytes.
I remember this page
http://code.google.com/p/cryptsetup/wiki/DMCrypt#IV_generators which is
not accessible any more. I have in mind, that it contained a list of
possible IVs.

Milan, Arno, is this page available at the new wiki? I couldn't find it.
Besides that, maybe it is a good idea to list all possible combinations
of cipher, mode and IV generator together with a 'recommendation' in the


On 05/01/2015 05:58 PM, David Backer wrote:
> Hello,
> I tried to figure out what ciphers are supported
> but I can't seem to do it. I'm on gentoo. My version is
> 1.6.5. I compiled it with nettle as the crypto backend.
> Thanks, david
> _______________________________________________
> dm-crypt mailing list
> dm-crypt at saout.de
> http://www.saout.de/mailman/listinfo/dm-crypt

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.saout.de/pipermail/dm-crypt/attachments/20150501/f1ebe8aa/attachment.html>

More information about the dm-crypt mailing list