3 ms·
+1, please share your setup
by tejado 8y ago
+1, please share your setup
- Boulth 8y agoSorry for the late reply but check out https://github.com/electrickite/luks-tpm2 https://github.com/electrickite/luks-tpm2 and scencrypt in AUR.
- techntoke 8y agoThat is freaking cool. Thanks!
- Boulth 8y agoNo problem. If I may suggest something if you have TPM version 2 use sha256 everywhere. And you can expand the PCRs list to cover more stuff. I'm using PCRs 0 to 8 (or 9? Can't check now) so any hardware configuration change is apparent during boot. Another useful package is sbupdate [0] that not only signs kernel for SecureBoot but additionally makes it possible to boot the kernel directly from UEFI firmware bypassing the need for bootloader (be it grub or systemd boot). Once setup it just works! [0]: https://github.com/andreyv/sbupdate https://github.com/andreyv/sbupdate