Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Secure Encrypted Storage Setup with LUKS2, TPM2, FIDO2, and Btrfs
Secure Encrypted Storage Setup with LUKS2, TPM2, FIDO2, and Btrfs - Secure_Encrypted_Storage_Setup.mdGist


eldavi
in reply to modem_down • • •modem_down
in reply to eldavi • • •eldavi
in reply to modem_down • • •modem_down
in reply to eldavi • • •I read them before writing my OP. I'm still not sure what you're getting at.
I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.
eldavi
in reply to modem_down • • •i don't understand the hostility.
i asked a question about needing yubikey software in a ramdisk image to enable decryption at boot time and most of the sources you provided don't mention it at all.
kkremitzki
in reply to eldavi • • •Bystander observation: you were asked to clarify but essentially refused in a way that took more effort than simply doing so.