-
Notifications
You must be signed in to change notification settings - Fork 100
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
UKI: kcrypt unlock-all doesn't unlock TPM-bound partitions #2217
Comments
To reproduce:
Possible solution: Introduce a new stage/hook (e.g. "after-decrypt") to allow people to run code right after decrypting the disks. This stage will also make sure the disk is encrypted again when the stage is done. Also, there is a |
|
kcrypt has the And it works:
Nothing more to do I guess? |
Introduced in version 0.9.0: kairos-io/kcrypt@v0.7.0...v0.9.0 (cut in December 18th: https://github.com/kairos-io/kcrypt/releases/tag/v0.9.0) |
Currently unlocking partitions encrypted with TPM manually by calling
kcrypt unlock-all
doesn't work.Workaround exists, and documented in https://kairos.io/docs/installation/trustedboot/#mount-partitions-after-install
The text was updated successfully, but these errors were encountered: