dyindude / ubuntu-zfs

BSD 2-Clause "Simplified" License
8 stars 4 forks source link

vault-provided LUKS passphrase #46

Open dyindude opened 4 years ago

dyindude commented 4 years ago

gatewaymac is a method we found of basing the LUKS passphrase on the MAC address of the default gateway - which does provide some level of security against theft, but not much else.

A more interesting method would be to store our LUKS passphrase in a service like vault, retrieve it during initramfs and unlock all drives