It's somewhat annoying that this support is not included and that it was
even removed. LUKS2 brings quite a few improvements, for example storing
options persistently (such as `allow-discards`) but also other
operational benefits. It would work better with newly created LUKS
volumes by-default, reducing the amount of unexpected surprises.

Secondly, from security perspective, not only should LUKS2 support be
reincluded (is its support really that complex to warrant disabling over
review?). But ideally the push would be for Argon2 support to be added
as well. This has been done by Arch maintainers
(https://aur.archlinux.org/packages/grub-improved-luks2-git) but it
would be preferred if it was supported by upsteam (especially if
Ubuntu/Canonical would like it). This would finally allow modern KDFs to
be used by everyone, even for volumes unlocked by GRUB.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2043101

Title:
  Mantic+noble inadvertently includes the luks2 module in signed grub-
  efis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/grub2-unsigned/+bug/2043101/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to