Bug 807494

Summary: LUKS setup inefficiency
Product: Red Hat Enterprise Linux 6 Reporter: Pádraig Brady <pbrady>
Component: doc-Security_GuideAssignee: Martin Prpič <mprpic>
Status: CLOSED CURRENTRELEASE QA Contact: ecs-bugs
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.3CC: eric, jskeoch
Target Milestone: rcKeywords: Documentation
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-02-25 13:39:26 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Pádraig Brady 2012-03-28 00:08:27 UTC
http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Security_Guide/sect-Security_Guide-LUKS_Disk_Encryption-Manually_Encrypting_Directories-Step_by_Step_Instructions.html

Step 5

dd if=/dev/urandom ... is used rather than the equivalent shred,
which is much faster, and also gives a progress report.
Also the following note is less than informative,
and is a bit facetious in telling users to leave the command
running overnight!

I've updated step 5 at the fedora wiki as to how I think it should read:
https://fedoraproject.org/wiki/Implementing_LUKS_Disk_Encryption
(I wouldn't include the mention of scrub or wipe from there)

Note I'm quite sure the PRNG within shred is good enough for this operation:
http://burtleburtle.net/bob/rand/isaacafa.html

Comment 3 Martin Prpič 2012-11-12 12:30:36 UTC
*** Bug 834463 has been marked as a duplicate of this bug. ***