I created initramfs hooks to support tpm, pkcs11, fido2, gpg with luks2
root during boot.   Also created a PPA.

https://sites.google.com/site/jtmoree/utilities/luks-root-smartcard
https://github.com/jtmoree-github-com/luks-root-smartcard.
https://launchpad.net/~jtmoree/+archive/ubuntu/security-tools

https://github.com/jtmoree-github-com/luks-root-
smartcard/blob/main/docs/EXAMPLES.md

```bash
# Enroll TPM2-based unlock against PCR 7
sudo systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=7 "$dev"

# Recommended: set crypttab field 3 to none for token mode
# (edit /etc/crypttab so the line reads: <name> UUID=<uuid> none luks)

# Rebuild initramfs
sudo update-initramfs -u -k "$(uname -r)"
```

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1969375

Title:
  systemd-cryptenroll does not support TPM2 devices

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1969375/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to