CRYPTSETUP-LUKSFORMAT(8) (NAME) cryptsetup-luksFormat - LUKS (SYNOPSIS) cryptsetup luksFormat [<>] <> [< >] (DESCRIPTION) LUKS < > . --key-file . '-' (stdin) . luksFormat (mapped) (mounted) LVM RAID . luksFormat (unmount) . LUKS --type luks1 --type luks2 . LUKS2 . OPAL ( SED OPAL) --hw-opal --hw-opal-only . OPAL LUKS OPAL PSID ( ) . --hw-opal-factory-reset erase . luksFormat LUKS (volume key) . . luksFormat (wipe) . LUKS . cryptsetup (FAQ) . <> : [--hash, --cipher, --verify-passphrase, --key-size, --key-slot, --key-file ( ), --keyfile-offset, --keyfile-size, --use-random, --use-urandom, --uuid, --volume-key-file, --iter-time, --header, --pbkdf-force-iterations, --force-password, --disable-locks, --timeout, --type, --offset, --align-payload ()]. LUKS2 <> : [--integrity, --integrity-no-wipe, --sector-size, --label, --subsystem, --pbkdf, --pbkdf-memory, --pbkdf-parallel, --disable-locks, --disable-keyring, --luks2-metadata-size, --luks2-keyslots-size, --keyslot-cipher, --keyslot-key-size, --integrity-legacy-padding, --hw-opal, --hw-opal-only]. (OPTIONS) --align-payload < > ( --offset ) (payload) . cryptsetup . ( ) ( ) . LUKS (detached) . --header . (DEPRECATED) ( LUKS2) . --offset . --batch-mode, -q . ! --verify-passphrase . --cipher, -c <_> . cryptsetup --help . (IV) . ESSIV "plain64" . XTS -s . XTS . --debug --debug-json . # . --debug-json JSON LUKS2 . --disable-blkid blkid . --disable-keyring (kernel keyring) dm-crypt . LUKS2 . --disable-locks () . LUKS2 . : cryptsetup ( /run ). --force-password LUKS . cryptsetup . pwquality.conf(5) passwdqc.conf(5) . --hash, -h <_> LUKS (digest) . PBKDF2 AF . . xxhash . cryptsetup --help . --header < LUKS> () LUKS . LUKS . --header . cryptsetup . --align-payload . --help, -? . --hw-opal LUKS2 dm-crypt SED OPAL . . --hw-opal-only LUKS2 SED OPAL . LUKS2 . SED OPAL . OPAL (--hw-opal-only) () OPAL LUKS ( LUKS) . cryptsetup OPAL OPAL . --integrity < > LUKS2 . : (EXPERIMENTAL) dm-integrity . AEAD << AEAD>> << (Cryptographic API)>> ( CONFIG_CRYPTO_USER_API_AEAD .config) . AUTHENTICATED DISK ENCRYPTION cryptsetup(8) . --integrity-inline . (PI DIF ) . ( "nop" ). (low-level) NVMe LBA nvme(1) id-ns . . ( ) . . . --integrity-key-size . . HMAC . . --integrity-legacy-padding (legacy padding) . . --integrity-no-wipe (wiping) () . . / (I/O) . (kernel page cache) . . --iter-time, -i < > PBKDF . . --key-description (keyring) . --key-file, -d . "-" (stdin) . (newline) . NOTES ON PASSPHRASE PROCESSING cryptsetup(8) . --keyfile-offset . --keyfile-size, -l . --help . . . --keyfile-offset . --key-size, -s . . . /proc/crypto . /proc/crypto . open --type plain luksFormat . LUKS LUKS . cryptsetup --help . --key-slot, -S <0-N> LUKS . LUKS . LUKS1 . LUKS2 LUKS2 . --keyslot-cipher <_> LUKS2 . --keyslot-key-size <> LUKS2 . --label <>, --subsystem <> LUKS2 . . udev . --luks2-keyslots-size LUKS2 ( ) . . <> ( 128k) . --luks2-metadata-size (JSON) LUKS2 . ( JSON ). LUKS2 : . <> ( 128k) . --offset, -o < > . --offset ( payload) ( ). --align-payload . --pbkdf < PBKDF> (PBKDF) LUKS. PBKDF : pbkdf2 ( PBKDF2 RFC2898) argon2i Argon2i argon2id Argon2id ( Argon2 ). LUKS1 PBKDF2 ( ). PBKDF LUKS2 cryptsetup --help . PBKDF (dictionary) (brute-force) . . PBKDF2 ( ) . Argon2i/id ( ) ( ) . ( ) . (--iter-time) --pbkdf-memory . . --pbkdf-parallel (CPU) . PBKDF LUKS2 cryptsetup-luksDump(8) . --pbkdf-force-iterations --pbkdf-memory --pbkdf-parallel . . (out-of-memory) . (embedded) . PBKDF: PBKDF2 ( ). PBKDF2 . Argon2i Argon2id ( CPU) ( ). (KiB) (GiB) . ( ) (MiB) (GiB) . ( ) --pbkdf-memory . ( ). : PBKDF . (brute-force) . . PBKDF . LUKS . cryptsetup ( ) ( ) () . PBKDF RAM RAM . (swap) . (overcommit) . PBKDF cryptsetup . --pbkdf-force-iterations PBKDF ( ). LUKS/LUKS2 . --pbkdf . --pbkdf-memory PBKDF ( Argon2i/id ). PBKDF . PBKDF2 . --pbkdf-parallel PBKDF ( ). . PBKDF2 . --progress-frequency . --progress-json JSON . ( --progress-frequency). JSON ( ): { "device":"/dev/sda", // backing device or file "device_bytes":"8192", // bytes of I/O so far "device_size":"44040192", // total bytes of I/O to go "speed":"126877696", // calculated speed in bytes per second (based on progress so far) "eta_ms":"2520012", // estimated time to finish an operation in milliseconds "time_ms":"5561235" // total time spent in IO operation in milliseconds } JSON: JSON . --sector-size LUKS2. . . . 4096/512e ( ) . . () . --integrity dm-integrity ( ) ( ). . . . --timeout, -t () . . --key-file . (). . --type BASIC ACTIONS cryptsetup(8) . --usage . --use-random, --use-urandom luksFormat ( ) . ( .) . NOTES ON RANDOM NUMBER GENERATORS cryptsetup(8) urandom(4) . --uuid UUID UUID luksFormat UUID . luksUUID UUID . UUID UUID 12345678-1234-1234-1234-123456789abc. --verify-passphrase, -y . (stdin) . --version, -V . --volume-key-file , --master-key-file ( ) . : . . (REPORTING BUGS) cryptsetup . --debug . (SEE ALSO) cryptsetup (FAQ) cryptsetup(8), integritysetup(8) veritysetup(8) (CRYPTSETUP) cryptsetup . cryptsetup 2.8.7 2026-07-21 CRYPTSETUP-LUKSFORMAT(8)