cryptsetup 2.7.5
The userspace tool for LUKS and dm-crypt, managing encrypted block devices, key slots, headers, and TPM enrolment. Full disk encryption on Linux runs through it.
Download TAR.XZ Project website ↗Download Mirrors
cryptsetup manages LUKS encrypted volumes. It is what your installer used if you ticked the encryption box, and what you need when managing those volumes afterwards.
The key slot model
Worth understanding because it explains everything else.
Data is encrypted with a master key generated once, which never changes. That master key is stored in the LUKS header, encrypted separately in each of up to eight key slots, each unlocked by a different passphrase or key file.
Two consequences: changing a passphrase is instant, because it rewrites one small slot rather than re-encrypting the volume. And the header is critical, because losing it loses the master key and there is no recovery.
Everyday commands
sudo cryptsetup luksFormat /dev/sdb1 # destroys everything on it
sudo cryptsetup open /dev/sdb1 mydata
sudo mkfs.ext4 /dev/mapper/mydata # the mapped device, not the raw one
sudo mount /dev/mapper/mydata /mnt/data
sudo umount /mnt/data
sudo cryptsetup close mydata
Managing passphrases
sudo cryptsetup luksDump /dev/sdb1 # which slots are in use
sudo cryptsetup luksAddKey /dev/sdb1
sudo cryptsetup luksChangeKey /dev/sdb1
sudo cryptsetup luksKillSlot /dev/sdb1 1
The pattern worth adopting: one passphrase you type daily, and one long recovery passphrase in a password manager or on paper. Forgetting the daily one then costs you nothing.
Back up the header
sudo cryptsetup luksHeaderBackup /dev/sdb1 --header-backup-file luks-header.img
Do this now, not later. It is a small file and it is the difference between a recoverable and an unrecoverable disk.
Store it separately from the drive and treat it as sensitive, since it contains the encrypted master key. Note also that restoring an old header re-enables any passphrase valid when it was taken, including ones you have since revoked.
What it protects
Data at rest: a stolen laptop, a disk returned under warranty, a drive from a decommissioned machine.
Not a running system. Once unlocked, the kernel decrypts transparently and malware or anyone using your session sees plaintext. Our LUKS guide covers the distinction properly.
Performance
cryptsetup benchmark
Negligible on any CPU with AES-NI, which is essentially everything from the last decade. The default aes-xts-plain64 cipher is the right choice and worth leaving alone.
Verify Your Download
Source releases on kernel.org are published with GPG signatures.