CRYPTTAB(5) crypttab CRYPTTAB(5) (NAME) crypttab - (SYNOPSIS) /etc/crypttab (DESCRIPTION) /etc/crypttab . "#" . . (whitespace) . : volume-name encrypted-device key-file options . : LUKS TrueCrypt BitLocker plain. cryptsetup(8) . LUKS LUKS dm-crypt ( plain) . /etc/crypttab : 1. /dev/mapper/ . 2. "UUID=" UUID . 3. . ":" /etc/fstab ( "LABEL=" ) . "none" "-" ( ) .key /etc/cryptsetup-keys.d/ /run/cryptsetup-keys.d/ ( ) . . swap /dev/urandom . AF_UNIX . . . 4. . . (KEY ACQUISITION) . : 1. ( ) . 2. () . . 3. () AF_UNIX . . 4. PKCS#11 . / AF_UNIX JSON LUKS2 . RSA . PKCS#11 RSA . (EC) . PKCS#11 . . pkcs11-uri= . 5. FIDO2 ( "hmac-secret" ) . / AF_UNIX JSON LUKS2 . (HMAC) FIDO2 . . fido2-device= . 6. TPM2 . ( ) -- (seed) TPM2 -- / AF_UNIX JSON LUKS2 . tpm2-device= . /etc/crypttab /etc/cryptsetup-keys.d/ /run/cryptsetup-keys.d/ ( ) JSON LUKS2 ( ) . systemd-cryptenroll(1) PKCS#11 FIDO2 TPM2 LUKS2 . (SUPPORTED OPTIONS) : cipher= . cryptsetup(8) . (IV) "aes-cbc-essiv:sha256" . . 186. discard discard ( ) . SSD . 207. hash= . cryptsetup(8) . 186. header= () () . LUKS TrueCrypt/VeraCrypt . cryptsetup(8) . ":" /etc/fstab ( "UUID=" ) . LUKS (mount) . 219. keyfile-offset= . cryptsetup(8) . 187. keyfile-size= . cryptsetup(8) . plain . (salt) FIDO2 FIDO2 . 188. keyfile-erase . ( /run/ ) . . /etc/cryptsetup-keys.d/ /run/cryptsetup-keys.d/ . . . 246. key-slot= . . luks . cryptsetup(8) . . 209. keyfile-timeout= ( ) . systemd- cryptsetup-generator(8) . 243. link-volume-key= (keyring) ( keyrings(7)) LUKS2 . "::" . "@" ( "@s" "@u"). . . "%key_type:" . "user" . ( - KEY IDENTIFIERS) keyctl(1) . . 256. luks LUKS . LUKS : cipher=, hash=, size=. 186. bitlk BitLocker . cryptsetup BitLocker . 246. _netdev cryptsetup . systemd.mount(5) _netdev . cryptsetup-pre.target cryptsetup.target, remote-fs-pre.target remote-cryptsetup.target . : (mount point) fstab(5) _netdev . local-fs.target . 235. noauto cryptsetup.target . . noauto . 186. nofail () cryptsetup.target . . . nofail . / header () (unmount) cryptset . 186. offset= (backend) . plain . 220. plain plain . 186. read-only, readonly . 186. same-cpu-crypt (CPU) / (IO) . (unbound) . 4.0 . 242. submit-from-crypt-cpus (thread) . . CFQ . 4.0 . 242. no-read-workqueue dm-crypt . . 5.9 . 248. no-write-workqueue dm-crypt . . 5.9 . 248. skip= . offset= (IV) . offset= IV . offset=n n IV 0 . skip= n IV n . plain . 220. size= . cryptsetup(8) . 186. sector-size= . cryptsetup(8) . 240. swap (swap) mkswap(8) . plain . swap . 186. tcrypt TrueCrypt . TrueCrypt : cipher=, hash=, keyfile-offset=, keyfile-size=, size=. . . TrueCrypt . . tcrypt-keyfile= . "/dev/null" . 206. tcrypt-hidden TrueCrypt . tcrypt . . . cryptsetup(8) . 206. tcrypt-keyfile= TrueCrypt . tcrypt . TrueCrypt tcrypt . 206. tcrypt-system TrueCrypt . tcrypt . 206. tcrypt-veracrypt VeraCrypt . VeraCrypt (fork) TrueCrypt . VeraCrypt TrueCrypt . tcrypt . 232. veracrypt-pim= Personal Iteration Multiplier (PIM) 0..2147468 veracrypt 0..65535 veracrypt . 0 VeraCrypt . tcrypt-veracrypt . VeraCrypt () PIM veracrypt-pim= . Veracrypt Personal Iterations Multiplier[1] . 254. timeout= (timeout) . . s, ms, us, min, h, d. 0 ( ). 186. tmp= /tmp/ mkfs(8) . "ext4", "xfs" "btrfs". "ext4" . plain . tmp . 186. tries= . 3 . 0 . 186. headless= false . true /PIN . (headless) . 249. verify . 186. password-echo=yes|no|masked PIN (echo ) . "masked" . password-echo=masked . . . "masked" ("*") . ("") backspace ("") (echo) . 249. password-cache=yes|no|read-only () PIN . "read-only" . "yes" . "read-only" (keyring) /PIN . "yes" /PIN 2.5 . PKCS#11 . PKCS#11 PIN . 257. pkcs11-uri= "auto" RFC7512 PKCS#11 URI[2] . PKCS#11 . LUKS2 YubiKey . "auto" LUKS2 PKCS#11 JSON LUKS2 . URI JSON LUKS2 . systemd-cryptenroll(1) PKCS#11 "auto" . ( "-" ). URI . . ( ) . ( RSA) ( ECC) LUKS Base64 . systemd-cryptenroll --pkcs11-token-uri=list PKCS#11 URI . PKCS#11 FIDO2 . fido2-device= ( ) FIDO2 . PKCS#11 FIDO2 FIDO2 . 245. fido2-device= "auto" "hidraw" ( /dev/hidraw1) FIDO2 "hmac-secret" ( ). FIDO2 . "auto" FIDO2 . FIDO2 (CID) fido2-cid= ( ) HMAC ( ). LUKS2 CID JSON LUKS2 . systemd-cryptenroll(1) FIDO2 LUKS2 . systemd-cryptenroll --fido2-device=list FIDO2 . : HMAC FIDO2 . Base64 LUKS2 . -- -- . FIDO2 PKCS#11 pkcs11-uri= . FIDO2 . 248. fido2-cid= (CID) Base64 FIDO2 FIDO2 . fido2-device= fido2-device=auto . fido2-device= fido2-cid= LUKS2 CID JSON LUKS2 . systemd-cryptenroll(1) FIDO2 LUKS2 . 248. fido2-rp= Relying Party (rp) FIDO2 FIDO2 . "io.systemd.cryptsetup" JSON LUKS2 . . 248. fido2-pin= PIN ( "clientPin" FIDO2). fido2-cid= . true false v248 : PIN PIN PIN . 257. fido2-up= ( "up" FIDO2) . fido2-cid= . true false v248 : UP UP UP . 257. fido2-uv= ( "uv" FIDO2) . fido2-cid= . true false v248 : UV . 257. tpm2-device= "auto" ( /dev/tpmrm0) TPM2 . TPM2 . tpm2-pcrs= ( ) PCR TPM2 . systemd-cryptenroll(1) TPM2 LUKS2 . "auto" TPM2 . systemd-cryptenroll --tpm2-device=list TPM2 . : TPM2 systemd-cryptenroll LUKS2 TPM2 "" "seed" TPM2 . seed TPM2 -- . JSON LUKS2 . TPM2 ( seed TPM2 ) ( TPM2) JSON LUKS2 . . PCR ( ) PCR PCR . 248. tpm2-pcrs= "+" TPM2 PCR ( <>) TPM2 (bind) . TPM2 JSON LUKS2 ( systemd-cryptenroll ). ( JSON LUKS2 ) : PCR 7. PCR PCR . 248. tpm2-pin= "false" . PCR TPM2 PIN . TPM2 . 251. tpm2-signature= JSON TPM2 PCR systemd-measure(1) . LUKS2 PCR . TPM2 PCR systemd-cryptenroll(1) . LUKS2 TPM2 PCR tpm2-pcr-signature.json /etc/systemd/ /run/systemd/ /usr/lib/systemd/ . 252. tpm2-pcrlock= pcrlock TPM2 systemd-pcrlock(8) . LUKS2 PCR . pcrlock TPM2 systemd-cryptenroll(1) . LUKS2 pcrlock TPM2 pcrlock.json /run/systemd/ /var/lib/systemd/ . 255. tpm2-measure-pcr= PCR TPM2 () . "no" ( ) PCR . "yes" PCR 15 . 0...23 PCR . UUID . TPM . 253. tpm2-measure-bank= PCR TPM2 tpm2-measure-pcr= . (:) . . ( "sha1", "sha256", ...) . 253. tpm2-measure-keyslot-nvpcr= LUKS TPM2 ( nvindex PCR) . NvPCR . false ( ) TPM2 nvindex nvindex . true "cryptsetup" NvPCR . ( "tpm2", "fido2", "pkcs11") UUID . 259. token-timeout= ( FIDO2, PKCS#11, TPM2) . ( systemd.time(7) ). 30s . . -- PIN ( ) . 0 . 250. try-empty-password= . . . 246. x-systemd.device-timeout= systemd . "s", "min", "h", "ms" . 216. x-initrd.attach initrd systemd.mount(5) x-initrd.mount . (mount) x-initrd.mount x-initrd.attach systemd . (unmount) . initrd . 245. fixate-volume-key= . LUKS TPM2 (seal) . fixate-volume-key= . tpm2-measure-pcr= sha256 PCR TPM2 . LUKS systemd-repart(8) . EncryptedVolume= repart.d(5) . 260. systemd-cryptsetup-generator(8) systemd . AF_UNIX (AF_UNIX KEY FILES) ( /etc/crypttab ) AF_UNIX . AF_UNIX (abstract namespace) unix(7) . : NUL RANDOM /cryptsetup/ VOLUME : NUL ( ) ( -) "/cryptsetup/" . "myvol": \0d7067f78d9827418/cryptsetup/myvol AF_UNIX getpeername(2) . PKCS#11 ( ) "/cryptsetup-pkcs11/" . FIDO2 ( "/cryptsetup-fido2-salt/") TPM2 ( "/cryptsetup-tpm2/"). PKCS#11/FIDO2/TPM2 . (EXAMPLES) 1. /etc/crypttab . LUKS swap TrueCrypt. "cipher=xchacha12,aes-adiantum-plain64" "keyfile-timeout=10s" . luks UUID=2505567a-9e27-4efe-a4d5-15ad146c258b swap /dev/sda7 /dev/urandom swap truecrypt /dev/sda2 /etc/container_password tcrypt hidden /mnt/tc_hidden /dev/null tcrypt-hidden,tcrypt-keyfile=/etc/keyfile external /dev/sda3 keyfile:LABEL=keydev keyfile-timeout=10s,cipher=xchacha12\,aes-adiantum-plain64 2. PKCS#11 Yubikey PKCS#11 RSA EC . Yubikey LUKS2 ykmap(1) yubikey-manager systemd-cryptenroll(1) LUKS2 : # SPDX-License-Identifier: MIT-0 # Destroy any old key on the Yubikey (careful!) ykman piv reset # Generate a new private/public key pair on the device, store the public key in # 'pubkey.pem'. ykman piv generate-key -a RSA2048 9d pubkey.pem # Create a self-signed certificate from this public key, and store it on the # device. The "subject" should be an arbitrary user-chosen string to identify # the token with. ykman piv generate-certificate --subject "Knobelei" 9d pubkey.pem # We do not need the public key anymore, let's remove it. Since it is not # security sensitive we just do a regular "rm" here. rm pubkey.pem # Enroll the freshly initialized security token in the LUKS2 volume. Replace # /dev/sdXn by the partition to use (e.g. /dev/sda1). sudo systemd-cryptenroll --pkcs11-token-uri=auto /dev/sdXn # Test: Let's run systemd-cryptsetup to test if this all worked. sudo systemd-cryptsetup attach mytest /dev/sdXn none pkcs11-uri=auto # If that worked, let's now add the same line persistently to /etc/crypttab, # for the future. We do not want to use the (unstable) /dev/sdX name, so let's # figure out a stable link: udevadm info -q symlink -r /dev/sdXn # Now add the line using the by-uuid symlink to /etc/crypttab: sudo bash -c 'echo "mytest /dev/disk/by-uuid/... none pkcs11-uri=auto" >>/etc/crypttab' # Depending on your distribution and encryption setup, you may need to manually # regenerate your initramfs to be able to use a Yubikey / PKCS#11 token to # unlock the partition during early boot. # More information at https://unix.stackexchange.com/a/705809 # On Fedora based systems: sudo dracut --force # On Debian based systems: sudo update-initramfs -u : o RSA2048 Yubikey o 9d Yubikey Yubico PIV certificate slots[3] . 3. FIDO2 FIDO2 FIDO2 "hmac-secret" . FIDO2 LUKS2 systemd- cryptenroll(1) : # SPDX-License-Identifier: MIT-0 # Enroll the security token in the LUKS2 volume. Replace /dev/sdXn by the # partition to use (e.g. /dev/sda1). sudo systemd-cryptenroll --fido2-device=auto /dev/sdXn # Test: Let's run systemd-cryptsetup to test if this worked. sudo systemd-cryptsetup attach mytest /dev/sdXn none fido2-device=auto # If that worked, let's now add the same line persistently to /etc/crypttab, # for the future. We do not want to use the (unstable) /dev/sdX name, so let's # figure out a stable link: udevadm info -q symlink -r /dev/sdXn # Now add the line using the by-uuid symlink to /etc/crypttab: sudo bash -c 'echo "mytest /dev/disk/by-uuid/... none fido2-device=auto" >>/etc/crypttab' # Depending on your distribution and encryption setup, you may need to manually # regenerate your initramfs to be able to use a FIDO2 device to unlock the # partition during early boot. # More information at https://unix.stackexchange.com/a/705809 # On Fedora based systems: sudo dracut --force # On Debian based systems: sudo update-initramfs -u 4. TPM2 TPM2 TPM2 . TPM2 LUKS2 systemd-cryptenroll(1) : # SPDX-License-Identifier: MIT-0 # Enroll the TPM2 security chip in the LUKS2 volume, and bind it to PCR 7 # only. Replace /dev/sdXn by the partition to use (e.g. /dev/sda1). sudo systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=7 /dev/sdXn # Test: Let's run systemd-cryptsetup to test if this worked. sudo systemd-cryptsetup attach mytest /dev/sdXn none tpm2-device=auto # If that worked, let's now add the same line persistently to /etc/crypttab, # for the future. We do not want to use the (unstable) /dev/sdX name, so let's # figure out a stable link: udevadm info -q symlink -r /dev/sdXn # Now add the line using the by-uuid symlink to /etc/crypttab: sudo bash -c 'echo "mytest /dev/disk/by-uuid/... none tpm2-device=auto" >>/etc/crypttab' # And now let's check that automatic unlocking works: sudo systemd-cryptsetup detach mytest sudo systemctl daemon-reload sudo systemctl start cryptsetup.target systemctl is-active systemd-cryptsetup@mytest.service # Once we have the device which will be unlocked automatically, we can use it. # Usually we would create a file system and add it to /etc/fstab: sudo mkfs.ext4 /dev/mapper/mytest # This prints a 'Filesystem UUID', which we can use as a stable name: sudo bash -c 'echo "/dev/disk/by-uuid/... /var/mytest ext4 defaults,x-systemd.mkdir 0 2" >>/etc/fstab' # And now let's check that the mounting works: sudo systemctl daemon-reload sudo systemctl start /var/mytest systemctl status /var/mytest # Depending on your distribution and encryption setup, you may need to manually # regenerate your initramfs to be able to use a TPM2 security chip to unlock # the partition during early boot. # More information at https://unix.stackexchange.com/a/705809 # On Fedora based systems: sudo dracut --force # On Debian based systems: sudo update-initramfs -u (SEE ALSO) systemd(1), systemd-cryptsetup@.service(8), systemd-cryptsetup- generator(8), systemd-cryptenroll(1), systemd-repart(8), repart.d(5), fstab(5), cryptsetup(8), mkswap(8), mke2fs(8) (NOTES) 1. Veracrypt Personal Iterations Multiplier https://www.veracrypt.fr/en/Personal%20Iterations%20Multiplier%20%28PIM%29.html 2. RFC7512 PKCS#11 URI https://tools.ietf.org/html/rfc7512 3. Yubico PIV certificate slots https://developers.yubico.com/PIV/Introduction/Certificate_slots.html systemd 261.2 CRYPTTAB(5)