Upgrade to cryptsetup 2.0 enabling new LUKSv2 metadata format and its features.
(details will follow. I'll add individual feature descriptions for testing)
Hi Ondrej, could you please describe new features in cryptsetup 2.0? How will customers upgrading from cryptsetup-1.7.4 to cryptsetup 2.0 be affected? Is there any work needed to be done on other components (for example python-blivet/anaconda)? Thank you.
It has to be at least 2.0.3 because that version contains code that is better aware of NBDE additional metadata created by luksmeta package.
https://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/v2.0/v2.0.3-ReleaseNotes
Is that rebase switching the tool to use argon2 by default?
No. In RHEL7 LUKS1 format is (and will be) default and it doesn't use argon2 kdf.
cryptsetup-2.0.3-1.el7.x86_64 is already in the distro.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:3239