agherzan / yubikey-full-disk-encryption

Use YubiKey to unlock a LUKS partition
Apache License 2.0
810 stars 51 forks source link

Possible to have Challenge-Response (posession) AND Password (knowledge) security ? #2

Closed Tormen closed 7 years ago

Tormen commented 7 years ago

Hi,

Is it possible with your ykfde initramfs hook (for archlinux :)), to do as you wrote: 1.) so use the challenge configured in the config file and send it to the key to receive the response 2.) and either before or after (or before AND after) this response to add a PASSWORD, that one has to type in every time (in addition to touching the yk4) ?

I think that would be awesome, becuase even if someone would have both laptop and yk4 they still would need the password like this.

Thanks a lot in advance,

Tormen

agherzan commented 7 years ago

I believe this was included in your last PR. Can you confirm @Tormen ?

Tormen commented 7 years ago

Yes, in deed!