telekom-mms / sectpmctl

sectpmctl - Secure Boot and TPM2 backed LUKS full disk encryption
GNU General Public License v2.0
13 stars 4 forks source link

Don't start installing when a wrong LUKS key has been given #8

Closed robret77 closed 1 year ago

robret77 commented 2 years ago

When a wrong LUKS password has been entered, the installation already modified system files. It is better to first check if the password is good.

CREATE AND ADD TPM INITRAMFS HOOK
## SET UMASK IN /etc/initramfs-tools/initramfs.conf
## EDIT CRYPTTAB
USING sha256 HASH WITH SIZE 32
## CRYPT PARTITION: /dev/vda3
CREATE AND ADD TPM POLICY IN TMPFS DIRECTORY /tmp/tmp.0LW1L1THpU
CREATE SECRET TPM LUKS KEY
KILL EXISTING TPM LUKS KEY FROM KEYSLOT
No key found with this passphrase.
COULD NOT KILL KEYSLOT