Twofish LUKS Support in Alternate Installer

Bug #886483 reported by Brian Knoll
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
cryptsetup (Ubuntu)
Expired
Wishlist
Unassigned

Bug Description

In the Ubuntu Alternate installer, the option for using Twofish appears to have been removed around the Maverick or, possibly, Natty time frame. The option to install using LUKS onto Twofish partitions was present in Lucid, but some time around Maverick or Natty it was removed and now this option is no longer available when using the alternate installer to install a LUKS partition.

It would be preferable to have this option back, as Twofish is a very viable cipher which has very high strength, yet is reasonably fast. It is, of course, possible to create Twofish partitions post-install, but having this feature during the install itself is very useful, especially for the root partition. Further, this feature existed in Ubuntu previously.

ProblemType: Bug
DistroRelease: Ubuntu 11.10
Package: cryptsetup 2:1.1.3-4ubuntu2
ProcVersionSignature: Ubuntu 3.0.0-12.20-generic 3.0.4
Uname: Linux 3.0.0-12-generic x86_64
NonfreeKernelModules: openafs
ApportVersion: 1.23-0ubuntu4
Architecture: amd64
Date: Sat Nov 5 05:46:11 2011
InstallationMedia: Ubuntu 10.04.1 LTS "Lucid Lynx" - Release amd64 (20100816.1)
ProcEnviron:
 PATH=(custom, no user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: cryptsetup
UpgradeStatus: Upgraded to oneiric on 2011-11-01 (3 days ago)
crypttab:
 sda2_crypt UUID=2fcde4e4-1711-42fe-8612-bb532b6c4bc6 none luks
 sda3_crypt /dev/sda3 /dev/urandom cipher=twofish-cbc-essiv:sha256,size=256,swap

Revision history for this message
Brian Knoll (brianknoll) wrote :
affects: ubuntu → cryptsetup (Ubuntu)
Revision history for this message
Steve Langasek (vorlon) wrote :

Hi Brian,

When you say that the option has been removed, what do you mean? Do you mean that the alternate installer presented it as an option in a list of available cyphers, or that manually specifying it as an option fails to work?

Changed in cryptsetup (Ubuntu):
importance: Undecided → Wishlist
status: New → Incomplete
Revision history for this message
Brian Knoll (brianknoll) wrote :

Hi Steve,

In Lucid and prior versions of Ubuntu, when using the Alternate installer the user would be presented with three choices when installing to a LUKS partition: AES, Blowfish, Serpent or Twofish. Of course, additional options were also presented, but these four basic ciphers were always available.

Some time around either Maverick or Natty, the option for Twofish was removed, and now it is only possible to install onto AES, Blowfish, or Serpent, but not Twofish. Note that if one installs Lucid using Twofish partitions, then upgrades through the versions all the way up to Oneiric (as I have done on the machine in this report), the Twofish partitions will work fine. There is no problem continuing to use them in the newer versions of Ubuntu once they are installed, it is just that the newer versions of Ubuntu do not offer the option of Twofish any more in the Alternate installer.

Thanks for looking into this. Let me know if there is anything I can do to help.

Brian

Revision history for this message
Brian Knoll (brianknoll) wrote :

I meant to say that in prior versions the user would be presented with _four_ choices, not three. Now they are only presented with three. I apologize for the confusion.

Revision history for this message
Steve Langasek (vorlon) wrote :

Ok, makes sense. Marking this as triaged.

For the record, however, this is a change that was inherited from Debian, so it's probably a better idea for you to discuss with the Debian maintainer (Jonas Meurer <email address hidden>).

Changed in cryptsetup (Ubuntu):
status: Incomplete → Triaged
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

I am using quantal daily image and twofish encryption method is offered.

Changed in cryptsetup (Ubuntu):
status: Triaged → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for cryptsetup (Ubuntu) because there has been no activity for 60 days.]

Changed in cryptsetup (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.