3 ms·
Also possible without a TPM: you just put openssh into the initrd, so you can log in and type the password to unlock the root. (It's technically not full-disk
by rnhmjoj 1y ago
Also possible without a TPM: you just put openssh into the initrd, so you can log in and type the password to unlock the root.
(It's technically not full-disk encryption because the kernel and initrd are in plaintext, but everything else is)
- pfexec 1y agoWhat do you authenticate against? Your shadow file is in the unencrypted area leaving it susceptible to offline attack. With the TPM you can fully disable password auth over SSH.
- rnhmjoj 1y agoCorrect, someone with physical access could run a MitM attack and steal your passphrase. I just find this extremely unlikely, so I honestly don't care.
- auguzanellato 1y agoMy Raspberry Pi some time ago had a setup where only public key auth was enabled for LUKS unlock, so I only had to have an authorized_keys file unencrypted.