On 03/01/2018 10:20 PM, Lukáš Pohanka wrote:
> Milan,
> thank you very much for a useful and informative answer. I'll have a look at this.
> Maybe I have a one more question: which part requires the 4.12+ kernel?
> I'm afraid I'll have to backport the changes if we decide to proceed.

Well, Arno guessed right that it a case in a big corporate ... :-)

I would definitely not suggest to try backport this, it will be very time consuming
and you will need to follow many fixes later (it is new code, it will have problems).
The code itself is in device-mapper subsystem, but there probably other fixes elsewhere
that need to be backported as well (block layer - integrity support, crypto API AEAD etc).

On the other side, I would welcome any feedback of using this kind of encryption
on practical cases or even in industrial systems. Even it means massive backports.


