You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There are various ways this can be done, some methods requiring writing to nvram, other methods can bundle "context" within the initramfs.
NVRAM is not unlimited, and including context in the initramfs itself disrupts TPM PCR reads. There are a lot of bad ways to do this, and I personally use a Yubikey on all of my machines, so I don't have a personal reason to add this support.
If anyone wants to add it, or look into it more, I'll be happy to include it, as long as it doesn't work in some way that could potentially hurt user safety.
Does the
ugrd
support TPM to unseal encrypted volumes?If no, can it be implemented?
The text was updated successfully, but these errors were encountered: