Change default LUKS encryption mode to aes-xts-plain64 (AES128). Force use of gcrypt PBKDF2 instead of internal implementation.