← Downloads

cryptsetup 2.7.5

Package v2.7.5 x86_64 TAR.XZ September 3, 2024

The userspace tool for LUKS and dm-crypt, managing encrypted block devices, key slots, headers, and TPM enrolment. Full disk encryption on Linux runs through it.

Download TAR.XZ Project website ↗

Download Mirrors

Mirror Region Download
GitLab Repository Primary Global Download
kernel.org Releases Global Download

cryptsetup manages LUKS encrypted volumes. It is what your installer used if you ticked the encryption box, and what you need when managing those volumes afterwards.

The key slot model

Worth understanding because it explains everything else.

Data is encrypted with a master key generated once, which never changes. That master key is stored in the LUKS header, encrypted separately in each of up to eight key slots, each unlocked by a different passphrase or key file.

Two consequences: changing a passphrase is instant, because it rewrites one small slot rather than re-encrypting the volume. And the header is critical, because losing it loses the master key and there is no recovery.

Everyday commands

sudo cryptsetup luksFormat /dev/sdb1        # destroys everything on it
sudo cryptsetup open /dev/sdb1 mydata
sudo mkfs.ext4 /dev/mapper/mydata           # the mapped device, not the raw one
sudo mount /dev/mapper/mydata /mnt/data

sudo umount /mnt/data
sudo cryptsetup close mydata

Managing passphrases

sudo cryptsetup luksDump /dev/sdb1          # which slots are in use
sudo cryptsetup luksAddKey /dev/sdb1
sudo cryptsetup luksChangeKey /dev/sdb1
sudo cryptsetup luksKillSlot /dev/sdb1 1

The pattern worth adopting: one passphrase you type daily, and one long recovery passphrase in a password manager or on paper. Forgetting the daily one then costs you nothing.

Back up the header

sudo cryptsetup luksHeaderBackup /dev/sdb1 --header-backup-file luks-header.img

Do this now, not later. It is a small file and it is the difference between a recoverable and an unrecoverable disk.

Store it separately from the drive and treat it as sensitive, since it contains the encrypted master key. Note also that restoring an old header re-enables any passphrase valid when it was taken, including ones you have since revoked.

What it protects

Data at rest: a stolen laptop, a disk returned under warranty, a drive from a decommissioned machine.

Not a running system. Once unlocked, the kernel decrypts transparently and malware or anyone using your session sees plaintext. Our LUKS guide covers the distinction properly.

Performance

cryptsetup benchmark

Negligible on any CPU with AES-NI, which is essentially everything from the last decade. The default aes-xts-plain64 cipher is the right choice and worth leaving alone.

Verify Your Download

Source releases on kernel.org are published with GPG signatures.