Change Passphrase Key for LUKS Encryption
Cockpit administrators can use the Storage page in the web console to change the LUKS passphrase key.
What Do You Need?
- The Cockpit web console must be installed and accessible.
For details, see these topics: Install and Enable Cockpit and Log in to the Cockpit Web Console.
- The
cockpit-storaged
package must be installed.Note:
If thecockpit-storaged
package isn't installed, see this section Install and Manage Add-on Applications - An unmounted LUKS1 formatted file system.
Important:
You can re-encrypt encrypted devices while the devices are in use (change encryption key or algorithm) using the LUKS2 format. The LUKS1 format doesn't provide online re-encryption. In this case, devices encrypted with LUKS1 format might require you to unmount the file system to apply encryption property changes. - Administrator privileges.
Steps
Using the Cockpit web console, follow these steps to change the LUKS primary or slot passphrases assigned to a host encrypted partition or logical volume.