CRYPTSETUP-LUKSADDKEY(8) (NAME) cryptsetup-luksAddKey - LUKS (SYNOPSIS) cryptsetup luksAddKey [<>] <> [< >] (DESCRIPTION) (keyslot) . --key-file LUKS2 () . (volume key) ( --volume-key-file --volume-key-keyring) . ( --new-keyfile) LUKS2 . : --unbound (unbound) LUKS2 . . --volume-key-file . . : LUKS2 . LUKS1 PBKDF () . <> : [--key-file, --keyfile-offset, --keyfile-size, --new-keyfile, --new-keyfile-offset, --new-keyfile-size, --key-slot, --new-key-slot, --volume-key-file, --volume-key-keyring, --force-password, --hash, --header, --disable-locks, --iter-time, --pbkdf, --pbkdf-force-iterations, --pbkdf-memory, --pbkdf-parallel, --unbound, --type, --keyslot-cipher, --keyslot-key-size, --key-size, --timeout, --token-id, --token-type, --token-only, --new-token-id, --verify-passphrase, --external-tokens-path]. (OPTIONS) --batch-mode, -q . ! --verify-passphrase . --debug --debug-json . # . --debug-json LUKS2 JSON . --disable-locks . LUKS2 . : cryptsetup ( /run ). --external-tokens-path _ cryptsetup ( ) . ( '/' ). --force-password LUKS . cryptsetup . pwquality.conf(5) passwdqc.conf(5) . --hash, -h <-> PBKDF2 AF . --header < LUKS> () LUKS . LUKS . LUKS ( luksAddKey) LUKS LUKS . --help, -? . --iter-time, -i < > ( ) PBKDF . . --key-file, -d _ . "-" (stdin) . . --key-file . --new-keyfile . NOTES ON PASSPHRASE PROCESSING cryptsetup(8) . --keyfile-offset . --keyfile-size, -l . --help . . . --keyfile-offset . --key-size, -s . . --volume-key-file . --unbound . --key-slot, -S <0-N> --new-key-slot . : LUKS2 ( --token-id --token-type --token-only) --volume-key-file . : --new-key-slot . LUKS . LUKS1 . LUKS2 LUKS2 . --keyslot-cipher <-> LUKS2 . --keyslot-key-size <> LUKS2 . --new-keyfile _ . "-" (stdin) . . . --new-keyfile-offset . --new-keyfile-size . --help . . --new-keyfile-offset . --new-key-slot <0-N> . : --key-slot . LUKS . LUKS1 . LUKS2 LUKS2 . --new-token-id . --pbkdf < PBKDF> (PBKDF) LUKS. PBKDF : pbkdf2 ( PBKDF2 RFC2898) argon2i Argon2i argon2id Argon2id ( Argon2 ). LUKS1 PBKDF2 ( ). PBKDF LUKS2 cryptsetup --help . PBKDF (dictionary) (brute-force) . . PBKDF2 ( ) . Argon2i/id ( ) ( ) . ( ) . (--iter-time) (--pbkdf-memory) . . (--pbkdf-parallel) (CPU) . PBKDF LUKS2 cryptsetup-luksDump(8) . : --pbkdf-force-iterations --pbkdf-memory --pbkdf-parallel . . (out-of-memory) . (embedded) . PBKDF: PBKDF2 ( ). PBKDF2 . Argon2i Argon2id ( CPU) ( ). (KiB) (GiB) ( CPU ). ( ) (MiB) (GiB) . ( ). --pbkdf-force-iterations <> PBKDF (). LUKS/LUKS2 . --pbkdf . --pbkdf-memory <> PBKDF ( Argon2i/id ). PBKDF . PBKDF2 . --pbkdf-parallel <> PBKDF ( ). . PBKDF2 . --timeout, -t < > () . . --key-file . . . --token-id . --token-only LUKS2 . : --new-token-id . --token-type ( ) . --type <-> BASIC ACTIONS cryptsetup(8) . --unbound (unbound) LUKS2 . --usage . --verify-passphrase, -y . (stdin) . --version, -V . --volume-key-file, --master-key-file ( ) . . . : . . --volume-key-keyring < > (keyring). luks . (digest) . < > keyctl . %< >:< > . KEY IDENTIFIERS keyctl(1) . %< >: user ( ) . (EXAMPLES) : . : cryptsetup luksAddKey /dev/device LUKS2 : cryptsetup luksAddKey --token-only /dev/device systemd-tpm2 LUKS2 ( systemd-tpm2 ): cryptsetup luksAddKey --token-type systemd-tpm2 /dev/device key_file: cryptsetup luksAddKey --new-keyfile key_file /dev/device cryptsetup luksAddKey /dev/device key_file volume_key_file LUKS2 ( ): cryptsetup luksAddKey --volume-key-file volume_key_file --new-token-id 5 /dev/device (REPORTING BUGS) cryptsetup . --debug . (SEE ALSO) cryptsetup (FAQ) cryptsetup(8), integritysetup(8) veritysetup(8) (CRYPTSETUP) cryptsetup . cryptsetup 2.7.5 CRYPTSETUP-LUKSADDKEY(8)