| CRYPTSETUP-CONFIG(8) | Maintenance Commands | CRYPTSETUP-CONFIG(8) |
NAME
cryptsetup-config - set permanent configuration options (store to LUKS header)
SYNOPSIS
cryptsetup config
DESCRIPTION
Set permanent configuration options (store to LUKS header). The config command is supported only for LUKS2.
The permanent options can be --priority to set priority (normal, prefer, ignore) for keyslot (specified by --key-slot) or --label and --subsystem.
OPTIONS
--batch-mode, -q
If the --verify-passphrase option is not specified, this option also switches off the passphrase verification.
--debug or --debug-json
If --debug-json is used, additional LUKS2 JSON data structures are printed.
--disable-locks
WARNING: Do not use this option unless you run cryptsetup in a restricted environment where locking is impossible to perform (where /run directory cannot be used).
--header
For commands that change the LUKS header (e.g., luksAddKey), specify the device or file with the LUKS header directly as the LUKS device.
--help, -?
--key-slot, -S <0-N>
The maximum number of keyslots depends on the LUKS version. LUKS1 can have up to 8 keyslots. LUKS2 can have up to 32 keyslots based on keyslot area size and key size, but a valid keyslot ID can always be between 0 and 31 for LUKS2.
--label , --subsystem
--priority
--usage
--version, -V
REPORTING BUGS
Report bugs at cryptsetup mailing list
Please attach the output of the failed command with --debug option added.
SEE ALSO
Cryptsetup FAQ https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAskedQuestions
CRYPTSETUP
Part of cryptsetup project https://gitlab.com/cryptsetup/cryptsetup/.
| 2026-09-07 | cryptsetup 2.8.8 |