I created initramfs hooks to support tpm, pkcs11, fido2, gpg with luks2 root during boot. Also created a PPA.
https://sites.google.com/site/jtmoree/utilities/luks-root-smartcard https://github.com/jtmoree-github-com/luks-root-smartcard. https://launchpad.net/~jtmoree/+archive/ubuntu/security-tools https://github.com/jtmoree-github-com/luks-root- smartcard/blob/main/docs/EXAMPLES.md ```bash # Enroll TPM2-based unlock against PCR 7 sudo systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=7 "$dev" # Recommended: set crypttab field 3 to none for token mode # (edit /etc/crypttab so the line reads: <name> UUID=<uuid> none luks) # Rebuild initramfs sudo update-initramfs -u -k "$(uname -r)" ``` -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1980018 Title: Cryptsetup-initramfs cant deal with tpm2-device option To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/cryptsetup/+bug/1980018/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
