Talk:Full disk encryption secure boot
> Using luks2 (unsupported by GRUB at the moment):
luks2 is now partially supported by GRUB.
> cryptsetup -v -c aes-xts-plain64 -s 512 --hash sha512 --pbkdf pbkdf2 --iter-time 1000 --use-random luksFormat /dev/nvme0n1p2
The options are too many and confusing, and most of them have been made default in cryptsetup 2.4.0, according to https://wiki.archlinux.org/title/Dm-crypt/Device_encryption#Encryption_options_for_LUKS_mode.