for those of you using Full Disk Encryption on your computers, do you store the encryption key on your computer’s Trusted Platform Module? or is it in some other place like an external key or something like a LUKS header?
Timeline
Post
Remote status
Context
1@cell I have a backup LUKS header stored on an external disk in case of corruption, but that is it. The passphrase storage is my brain which unlocks rootfs allowing grub to load kernel and initramfs, initramfs then has a second key embedded in it that doesn't require a passphrases, so it only asks a single time.
Replies
0Fetching replies…