Skip to content

crypto: Add BitLocker Clear Key detection and passwordless open - #1212

Draft
Marcondiro wants to merge 1 commit into
storaged-project:masterfrom
Marcondiro:master
Draft

Marcondiro wants to merge 1 commit into
storaged-project:masterfrom
Marcondiro:master

Conversation

@Marcondiro

Copy link
Copy Markdown

Hi,

This PR introduces support for Bitlocker Clear Keys: pre-provisioned and suspended BitLocker devices contain this on-disk key in clear, more info on Microsoft's FAQ.

In cryptsetup 2.8+, passing a NULL passphrase allows extracting the VMK using this Clear Key.

  • Extend BDCryptoBITLKInfo with has_clearkey field
  • In bd_crypto_bitlk_info(), probe for clear key presence
  • In bd_crypto_bitlk_open_flags(), allow NULL context to trigger clear key activation
  • Add test cases in tests/crypto_test.py

Assisted-by: Gemini

Thanks!

@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Pre-provisioned and suspended BitLocker devices contain an on-disk
Clear Key protector. In cryptsetup 2.8+, passing a NULL passphrase
allows extracting the VMK using this Clear Key.

- Extend BDCryptoBITLKInfo with has_clearkey field
- In bd_crypto_bitlk_info(), probe for clear key presence
- In bd_crypto_bitlk_open_flags(), allow NULL context  to trigger
clear key activation
- Add test cases in tests/crypto_test.py

Assisted-by: Gemini
Signed-off-by: Marco Cavenati <cavenati.marco@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant