You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As far as I understand, you can use your - for example Nitrokey Pro - to "avoid" typing in the Disk Recovery Key. The Disk Recovery Key is the key used at OS installation for the encrypted root partition (passphrase placed in LUKS keyslot 0). So I can use this key whenever I connect my harddrive to another computer.
For me, it would be logical, if I use my GPG key on my Nitrokey to do some magic to decrypt my harddrive (or decrypt some parts on the TPM which then decrypts my harddrive). It would make sense, if I would need to type in my Nitrokey User PIN to decrypt my harddrive.
Instead I am asked for another password in Heads when I try to set up this. This confuses me.
(Added for newcomers: The Nitrokey User PIN is - obviously - relatively easy to guess, if brute force methods are available. But the USB Security dongles are actually locking the user out of their User role if 3 bad attempts were made, so it is safe, to use the PIN to unlock/decrypt my harddrive.)
The text was updated successfully, but these errors were encountered:
Unlocking the Disk encrypted container with GPG PINs is possible and was documented there, and requires the booted OS to be modified accordingly. Purism is doing so with their OS and documentation is given on their website, pointed from the section in wiki PR above.
Not sure why that PR was closed. Maybe the discussion should continue there so that that PR is modified and merged.
As far as I understand, you can use your - for example Nitrokey Pro - to "avoid" typing in the
Disk Recovery Key
. TheDisk Recovery Key
is the key used at OS installation for the encrypted root partition (passphrase placed in LUKS keyslot 0). So I can use this key whenever I connect my harddrive to another computer.For me, it would be logical, if I use my GPG key on my Nitrokey to do some magic to decrypt my harddrive (or decrypt some parts on the TPM which then decrypts my harddrive). It would make sense, if I would need to type in my
Nitrokey User PIN
to decrypt my harddrive.Instead I am asked for another password in Heads when I try to set up this. This confuses me.
I read https://osresearch.net/Keys/
(Added for newcomers: The
Nitrokey User PIN
is - obviously - relatively easy to guess, if brute force methods are available. But the USB Security dongles are actually locking the user out of their User role if 3 bad attempts were made, so it is safe, to use the PIN to unlock/decrypt my harddrive.)The text was updated successfully, but these errors were encountered: