One command from luksformat writes a LUKS header and formats a filesystem on the device you name. There is no confirmation prompt standing between you and an erased disk, so allow fifteen minutes for a prepared test device, plus time to confirm the target is genuinely disposable. The examples use cryptsetup package version 2:2.7.0-1ubuntu4.2 on this machine.
Warning: this is a destructive operation. luksformat writes a LUKS header and then creates a filesystem on the selected device; everything already there can become inaccessible. Replace /dev/DEVICE only after identifying the device by stable facts such as its size, model and serial number. Never experiment with a disk holding the only copy of anything you care about.
Confirm which executable is being called and which package supplied it. These checks are ordinary commands and do not need elevated privileges:
$ command -v luksformat
/usr/sbin/luksformat
$ dpkg-query -W -f='${Package} ${Version}\n' cryptsetup
cryptsetup 2:2.7.0-1ubuntu4.2
The manual describes the command as a wrapper around cryptsetup and mkfs. It creates the LUKS container, opens a temporary device mapping, runs the filesystem formatter, waits for device events, and closes the mapping again. It does not mount the resulting filesystem for you.
Checkpoint: if command -v finds a different copy, stop and inspect that installation before relying on anything shown here. A wrapper from another package or an older release can behave differently in the details.
Use your normal inventory tools to identify the target. Do not infer a device name from the order USB devices were plugged in:
$ lsblk -o NAME,PATH,SIZE,TYPE,FSTYPE,MOUNTPOINTS,MODEL,SERIAL
$ findmnt
Choose a whole unused disk or partition, never a mounted filesystem. If the target appears in findmnt, unmount it using the procedure appropriate to that system before continuing. Stop if it belongs to the running system, holds a swap area, or has a mountpoint you do not recognise.
Warning: do not run the formatting command until the path in your final command matches the device you intend to erase. A typo in /dev/DEVICE is not recoverable through luksformat. If you need a reversible practice environment, use a disposable virtual machine with a separately attached test disk.
The default filesystem is vfat, because the wrapper targets removable devices. That default is easy to miss: LUKS supplies encryption, not the filesystem inside the unlocked mapping. Use -t to select another filesystem whose mkfs helper is installed.
$ sudo luksformat -t ext4 /dev/DEVICE
The command also accepts filesystem-specific options after the device. Those get passed straight to the selected mkfs program, so check that program's manual page before adding any:
$ man mkfs.ext4
$ sudo luksformat -t ext4 /dev/DEVICE -L ARCHIVE
The exact option set depends on the formatter. Keep the device as the first positional argument after -t; everything after it is for mkfs. If you want broad removable-media compatibility, omit -t and accept the documented vfat default, but remember that filesystem choice affects permissions, filenames and platform support.
Elevated privileges are required. Running the installed wrapper as an ordinary user exits before it even prints usage:
$ luksformat --help
This program needs to be started as root
That message comes from the wrapper's own root check, not a successful help request. Use sudo for the actual operation, and do not turn a permission problem into a habit of running unrelated inspection commands as root.
Once the target and filesystem are confirmed, run one of these forms. The command asks cryptsetup for a LUKS passphrase, then asks for it again when opening the temporary mapping:
$ sudo luksformat -t ext4 /dev/DEVICE
Creating encrypted device on /dev/DEVICE...
Please enter passphrase for /dev/DEVICE:
Please enter your passphrase again to verify it
Use a passphrase you can recover through your organisation's approved process; it is not shown while typed. If the two entries differ, the wrapper reports they were not identical and exits, but the initial LUKS operation may already have changed the target. Do not assume a failed run leaves the old contents intact.
When the filesystem formatter finishes, the wrapper closes its temporary mapping. It normally prints the formatter's progress or completion text between the passphrase prompts and the shell prompt. Exact output depends on the selected mkfs helper and its version.
Checkpoint: wait for the shell prompt to return, then inspect the result without mounting it:
$ sudo cryptsetup luksDump /dev/DEVICE
$ lsblk -f /dev/DEVICE
cryptsetup luksDump should recognise a LUKS header. lsblk -f may show the filesystem type on the underlying device, or it may need the unlocked mapping before it can display all filesystem details. A recognised LUKS header is not proof the filesystem was successfully created.
Open the LUKS device with a name that is easy to recognise, then inspect the mapped device:
$ sudo cryptsetup open --type luks /dev/DEVICE archive
Enter passphrase for /dev/DEVICE:
$ lsblk -f /dev/mapper/archive
NAME FSTYPE FSVER LABEL UUID FSAVAIL FSUSE% MOUNTPOINTS
archive ext4 ARCHIVE 00000000-0000-0000-0000-000000000000
The UUID above is deliberately illustrative; use whatever your system prints. A successful cryptsetup open creates /dev/mapper/archive. If the filesystem type is absent or unexpected, stop before mounting and investigate the formatter result.
For a non-destructive filesystem check, ask the filesystem-specific tool what it would do. For ext4, an unmounted check can be read-only:
$ sudo e2fsck -fn /dev/mapper/archive
The -n option tells e2fsck not to make changes. Use the equivalent read-only diagnostic for a different filesystem, since filesystem tools do not share one universal option set.
Create a mountpoint owned according to your local policy, then mount the mapped device. Creating the directory and mounting both need elevated privileges:
$ sudo install -d -m 0750 /mnt/archive
$ sudo mount /dev/mapper/archive /mnt/archive
$ findmnt /mnt/archive
$ sudo sh -c 'printf "%s\n" verified > /mnt/archive/verification.txt'
$ sudo cat /mnt/archive/verification.txt
verified
The file test confirms the mounted filesystem is writable, but it also changes state. Remove only that test file once you are satisfied, or keep it as a deliberate marker:
$ sudo rm /mnt/archive/verification.txt
Do not disconnect the device while it is mounted. Before removal, flush and unmount it, then close the LUKS mapping:
$ sync
$ sudo umount /mnt/archive
$ sudo cryptsetup close archive
$ ls /dev/mapper/archive
ls: cannot access '/dev/mapper/archive': No such file or directory
If another process is using the mountpoint, umount will fail. Find the process and close the application cleanly; do not jump straight to a forced unmount on a device holding writes. Once the mapping is closed, the encrypted data is unreachable through that path until you open it again.
If the wrapper says the device is mounted, stop and resolve the mount rather than retrying. It checks /proc/mounts before starting. If it reports an invalid filesystem, the matching mkfs helper is not executable at the paths it checks, so install or repair the appropriate filesystem tools through your normal package process before trying again.
Recovery: if the passphrase verification fails, or if mkfs fails after LUKS creation, the original device contents may already be gone. The temporary mapping is normally closed by the wrapper, but there is no undo command that restores overwritten data. Restore from a known backup, or destroy and recreate the disposable target once you know what failed. Do not repeatedly rerun the command against a valuable disk hoping one attempt will somehow preserve it.
For a new volume, record the LUKS header backup and recovery procedure required by your organisation. A passphrase without a usable LUKS header is not enough, and a header backup without controlled access can weaken the confidentiality of the volume. Keep recovery material separate from the encrypted device, and test recovery on a disposable copy.
vfat.sudo luksformat completed and cryptsetup luksDump recognises the LUKS header.