latchset / clevis

Automated Encryption Framework
GNU General Public License v3.0
935 stars 105 forks source link

luks bind tpm2 #299

Open ShinobiX9X opened 3 years ago

ShinobiX9X commented 3 years ago

Arch Linux up to date After binding the luks encrypted device. no errors But the tpm module is still empty image

savchenko commented 3 years ago

What's the output of sudo tpm2_pcrread?

sarroutbi commented 3 years ago

@ShinobiX9X : can you please provide the output of tpm2_pcrread as requested?

savchenko commented 3 years ago

@latchset, the issue can probably be closed.

sarroutbi commented 3 years ago

Hello @ShinobiX9X , are you ok if we close the issue?

ShinobiX9X commented 3 years ago

Hello, I am very sorry, only yesterday I saw there are reactions on this post. sudo: tpm2_pcrread: command not found is what I get

sarroutbi commented 3 years ago

tpm2_pcrread is part of the tpm2-tools package, at least in RHEL8.

Install it on your distribution and provide output for further investigation, please.

ShinobiX9X commented 3 years ago

image

sarroutbi commented 3 years ago

Sorry, but I am a little bit confused about the relationship between tpm2_getcap and clevis binding. Are they related? What are you expecting to see? tpm2_getcap should return TPM for it’s capabilities / properties. Anyway, can you please post tpm2_getcap -l output?

ShinobiX9X commented 3 years ago

`