← CSI Knowledge

eCryptfs

name
eCryptfs
source
Notion CSI Technology Register
csi_tech_id
113
category
Cyber Security
csi_classification
Retired
lifecycle_status
Done
client_approved
No
commercial_use
Allowed
current_version
111 (userspace; distro revisions vary)
risk_flag
Caution
official_url
https://www.ecryptfs.org/
documentation_url
https://docs.kernel.org/filesystems/ecryptfs.html
last_verified
August 4, 2026
migration_status
Imported
tags
csi-technology-register, notion-migration
06-Cybersecurity/eCryptfs.md

eCryptfs

Purpose

Legacy Linux stacked filesystem encryption; retained for authorized access, recovery, and migration of existing eCryptfs data only.

Decision Summary

Retired for new deployments because Ubuntu guidance considers eCryptfs deprecated. Retain only for authorized legacy recovery, access, and migration.

Use Cases

Legacy encrypted-home access; authorized recovery; migration to fscrypt or LUKS/dm-crypt; compatibility testing on copied data.

Field Notes

Preserve encrypted source, wrapped-passphrase material, and metadata. Never work on the only copy. Filename limit is about 143 bytes. Prefer fscrypt or LUKS/dm-crypt for new designs.

Hardware Requirements

Linux with eCryptfs kernel support, compatible ecryptfs-utils and key dependencies, administrator access, and capacity for source backup plus migration copy.

Backup Strategy

Keep an immutable encrypted source copy; separately secure keys and metadata; create and verify a protected plaintext migration copy before retirement.

Recovery Strategy

Use a compatible isolated Linux host/VM, mount read-only where practical, validate samples, export to a separate destination, verify, then migrate.

Secure Boot Notes

Normally compatible with signed distribution kernels and their in-tree eCryptfs module. Validate the exact distro/kernel; do not disable Secure Boot for this.

Version History

Kernel support since 2.6.19. Upstream userspace release line 111; distro revisions vary. Reviewed 2026-08-04 and retired for new deployments.

Technology Register Metadata

  • CSI Classification: Retired
  • CSI Tech ID: 113
  • Category: Cyber Security
  • Client Approved: No
  • Commercial Use: Allowed
  • Current Version: 111 (userspace; distro revisions vary)
  • Deployment: Native
  • Docker Support: No
  • Documentation URL: https://docs.kernel.org/filesystems/ecryptfs.html
  • Evidence Complete: Yes
  • Last Updated: August 4, 2026 2:37 AM
  • Last Verified: August 4, 2026
  • Licence: GPL-2.0-or-later (userspace utilities; kernel component follows Linux kernel licensing)
  • Lifecycle Status: Done
  • OS Support: Linux
  • Official URL: https://www.ecryptfs.org/
  • Offline Support: Full
  • Risk Flag: Caution
  • Ventoy Compatibility: Not Applicable

Migration Record

Imported deterministically from the CSI Technology Register.

Source classifications, approval state, risk state, version information and testing status have been preserved. No additional approval or validation has been inferred during migration.


Cyber Space Infocom
Making Technology Work for You