Gentoo Archives: gentoo-security

From: Florian Philipp <lists@××××××××××××××××××.net>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Encryption Ciphers
Date: Fri, 29 Feb 2008 17:10:31
Message-Id: 1204304962.6725.5.camel@NOTE_GENTOO64.PHHEIMNETZ
In Reply to: Re: [gentoo-security] Encryption Ciphers by Mansour Moufid
1 On Thu, 2008-02-28 at 15:19 -0500, Mansour Moufid wrote:
2 > On Thu, Feb 28, 2008 at 1:29 PM, Florian Philipp
3 > <lists@f_philipp.fastmail.net> wrote:
4 > > One last question for everyone who has read this rather long mail (thank
5 > > you, btw): What exactly is benbi in aes-lrw-benbi:sha256 and what should
6 > > I choose for XTS? The kernel description states plain but essiv and
7 > > benbi work as well.
8 > >
9 >
10 > benbi is an IV generation algorithm. If you look at the dm-crypt
11 > sources [1], benbi stands for "big-endian 'narrow block'-count" (not
12 > sure where they got the `i' from...). There's also one called bewbi,
13 > which I thought was entertaining.
14 >
15 > Sincerely,
16 > Mansour Moufid
17 >
18 > [1] http://www.cs.fsu.edu/~baker/devices/lxr/http/source/linux/drivers/md/dm-crypt.c#L110
19
20 Thanks!
21
22 So, am I right to believe that essiv is the best choice and benbi just
23 some kind of special requirement for lrw or should I stick with what's
24 recommended (although without reasons given for xts), e.g. cbc-essiv,
25 lrw-benbi, xts-plain?

Attachments

File name MIME type
signature.asc application/pgp-signature