# <target name> <source device>          <key file>      <options>
root            /dev/mapper/vg-root      none            luks,cipher=aes-cbc-essiv:sha256
home            /dev/mapper/vg-home      none            luks,cipher=aes-cbc-essiv:sha256,keyscript=decrypt_keyctl
var             /dev/mapper/vg-var       none            luks,cipher=aes-cbc-essiv:sha256,keyscript=decrypt_keyctl
cswap           /dev/sda1                none            swap,cipher=aes-cbc-essiv:sha256