0. How to prepare an encrypted filesystem in 5 minutes

Don't forget about adding proper aliases into /etc/modules.conf!
Then type:

		/etc/rc.d/init.d/cryptofs initialize

Interactive script will ask you some questions.

1. How to prepare an encrypted filesystem

First, create a partition, or a file on which you will keep an encrypted
filesystem. If you want to create a file, the simple way to do it is:

	dd if=/dev/zero of=<my_file> bs=1M count=<size in MBs>

And more secure way:

	dd if=/dev/urandom of=<my_file> bs=1M count=<size in MBs>

Don't exaggerate with filesystem size: random numbers generator doesn't
work very fast, and you will have to give system lots of ,,random''
events: like moving your mouse or pressing keys. Generating an 50MB
filesystem can take even up to 15 minutes...

Then, setup a loopback device:

	losetup /dev/loop<X> <my_file> -e <encryption type>

where /dev/loop<X> is one of unused loop devices, and encryption type is
one of the shown below in section 2.
You will be prompted for a password - be careful when typing: you will be
prompted only once, so you can't verify what you typed. Make
sure you remember it: once you set a password, you can't change it.

Now, make a filesystem:

	mke2fs /dev/loop<X>

or
	
	mkswap /dev/loop<X>

or

	mk<any filesystem type> /dev/loop<X>

Try to mount it (or turn the swap on). If it works, try to umount it, turn
loopback off:

	losetup -d /dev/loop<X>

and once again: set up looback device with some encryption, and try to
mount it. If you succeed, this will mean that the password you entered was
the same as for the first time.

Umount, turn loopback off again, and insert description of your
filesystem into /etc/cryptofstab, just as shown in section 2.




2. Configuration

Config file format:

<device> <mountpoint> <fs type> <encryption type> <options> <run fsck?>

where:

<device>, <mountpoint>, <fs type> are the same as in fstab

<encryption type> is one of:
- aes
- blowfish
- des
- dfc
- idea
- mars
- rc5
- rc6
- rijndael
- serpent

<options> are same as for fstab, except:
- noauto option is useless - only rc-scripts use cryptofstab/cryptomtab,
  so normal mount won't know what and where to mount. If you want an
  encrypted fileystem, put it into standard fstab, with
  "noauto,loop,encryption=..." parameters.
- loop= and encryption= should not be used
- for swap devices, two new options are available:
  * new -- run mkswap after losetup. Allows to change key at every mount.
  * randompass -- read encryption key from /dev/urandom. Implies "new"

<run fsck?> may be "yes" or "no"
