Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Decrypt LUKS container using password + TMPv2.0 derived key #3

Open
komachi opened this issue Aug 29, 2021 · 3 comments
Open

Decrypt LUKS container using password + TMPv2.0 derived key #3

komachi opened this issue Aug 29, 2021 · 3 comments

Comments

@komachi
Copy link
Owner

komachi commented Aug 29, 2021

No description provided.

@savchenko
Copy link

I was trying to solve the very same problem, some notes: https://github.com/savchenko/debian/wiki/tpm2-@-libvirt,-Clevis

P.S. You might want to check the https://github.com/savchenko/debian as well. Feel free to fork.

@komachi
Copy link
Owner Author

komachi commented Sep 14, 2021

I'm looking into systemd-cryptenroll, looks promising and makes everything much simpler (run one command and everything else should work out-of-box). Sadly this requires newer systemd that available only in experimental for now.

@komachi
Copy link
Owner Author

komachi commented Sep 14, 2021

This also invoves migration from grub2 to systemd-boot, also systemd-cryptenroll provide a nice way to lock kernel cmdline when used with systemd-boot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants