@SomeBoyo@feddit.de to Selfhosted@lemmy.worldEnglish • 2 years agoWhat do you use to mount encrypted drives on boot?message-square9fedilinkarrow-up135arrow-down10
arrow-up135arrow-down1message-squareWhat do you use to mount encrypted drives on boot?@SomeBoyo@feddit.de to Selfhosted@lemmy.worldEnglish • 2 years agomessage-square9fedilink
minus-square@akash_rawal@lemmy.worldlinkfedilinkEnglish5•2 years agoTPM stores the encryption key against secure boot. That way, if attacker disables/alters secure boot then TPM won’t unseal the key. I use clevis to decrypt the drive.
TPM stores the encryption key against secure boot. That way, if attacker disables/alters secure boot then TPM won’t unseal the key. I use clevis to decrypt the drive.