|
|
|
|
|
by wiktor-k
1019 days ago
|
|
> but those have a downside of the TPM needing to be updated with every new kernel. This depends on the configuration. If you don't bind the key to PCRs at key creation time kernel updates don't affect the workflow and you still will take advantage of other TPM features such as locking the key after several unsuccessful attempts. Take a look at the systemd configuration:
https://www.freedesktop.org/software/systemd/man/systemd-cry... I'm using it on my laptop and it works well. |
|