Thanks again Theodore. You are absolutely right with "full disc encryption should be the best way for my usecase".
"Should" because the used backup software behind samba is Microsoft's "wbadmin". I'm able to copy gb's of data through samba to an dm-crypt (LUKS/veracrypt/truecrypt) device but I'm not able to do the same using "wbadmin" without errors. The same constellation (devices, softwares, configurations) is working without any encryption or with ext4-encryption. My destination device is an md mirror of SATA and USB devices so I'm able to change the USB device weekly removing from raid an rebuilding it. This works with truecrypt for years but one day ... You know the rest of the story and I'm not able to find out what changed (perhaps an MS update I can't revert). The first step should be to make an bug report of this misbehaviour but I'm not sure where to address. Every party will show to the other. And because I need backups and like the removed devices to be encrypted I tried ext4 built-in encryption. Nice to have, because its an layer less then using dm in between. Now I know ext4 encryption workes as is and as should, also the kernel key infrastructure but in combination its a bit confusing first time. Mit freundlichen Grüßen / Kind regards Ronny Seffner -- Ronny Seffner | Alter Viehweg 1 | 01665 Klipphausen www.seffner.de | ro...@seffner.de | +49 35245 72950 7EA62E22D9CC4F0B74DCBCEA864623A568694DB8