Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
There’s a project that allows unlocking LUKS with a decryption key retrieved from another machine in your network. I don’t recall the name but someone hopefully will.
The idea is that put the key on, say, a raspberry pi zero w that you hide somewhere in your house so that if someone steals your server they don’t have the key.
Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.
tang
Thanks. TIL about Clevis/Tang.