morbitzer / linux-luks-tpm-boot
A guide for setting up LUKS boot with a key from TPM in Linux
☆159Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for linux-luks-tpm-boot
- Utility to manage LUKS keys sealed by a TPM 2.0☆50Updated last year
- Framework to join Linux's physical security bricks.☆235Updated 3 months ago
- A guide for setting up LUKS boot with a key from TPM in Linux☆181Updated 6 years ago
- Simple PKCS11 provider for TPM chips☆252Updated 5 months ago
- Provide SSH access to initramfs early user space on Fedora and other systems that use Dracut☆243Updated 3 weeks ago
- Use named netns (net namespace) with systemd services!☆132Updated last year
- ZFS Boot Environment manager for Linux☆190Updated 5 months ago
- Full disk encryption with Yubikey (Yubico key)☆109Updated 5 months ago
- Encrypted boot partition manager with UEFI Secure Boot support☆204Updated 11 months ago
- LUKS support for storing keys in TPM NVRAM☆186Updated 6 years ago
- Scripts to slightly improve the security of the Linux boot process with UEFI Secure Boot and TPM support☆271Updated last year
- Attest the trustworthiness of a device against a human using time-based one-time passwords☆166Updated 4 months ago
- Calculate future (next boot) TPM PCRs after a kernel upgrade☆38Updated last year
- dracut initramfs module to start dropbear sshd during boot to unlock the root filesystem with the (cryptsetup) LUKS passphrase remotely☆286Updated last year
- Provisioning tool for systemd in initramfs (systemd-tool)☆116Updated 4 months ago
- Some hooks to get vlan and bond interfaces to work with initramfs☆41Updated last year
- Tools for using PIV tokens (like Yubikeys) as an SSH agent, for encrypting data at rest, and more☆194Updated 2 weeks ago
- Compatibility between systemd and ZFS roots☆43Updated 3 years ago
- Script to generate an OVMF vars file with default secure boot key enrolled.☆83Updated 2 years ago
- Scripts to bootstrap internal Certificate Authorities (CAs) using Yubikeys☆76Updated 4 years ago
- Decrypt your LUKS partition using a FIDO2 compatible authenticator☆134Updated 8 months ago
- Tang binding daemon☆517Updated last week
- Unmaintained systemd-boot integration with secure boot support; consider https://github.com/Foxboron/sbctl instead.☆33Updated 3 years ago
- PKCS#11 provider with smart card support via GnuPG☆36Updated 5 years ago
- Alternative to sedutil LinuxPBA which uses kexec for faster boot☆25Updated 5 years ago
- PKCS#11 GnuPG SCD☆69Updated 2 weeks ago
- Small and reliable initramfs solution supporting (remote) rescue shell, lvm, dmcrypt luks, software raid, tuxonice, uswsusp and more.☆315Updated last year
- DEPRECATED TPM enabled GRUB2 Bootloader☆193Updated 3 years ago
- Password caching script for multiple luks volumes☆59Updated 2 years ago
- Program that prepares ZFS on a system, and installs Linux☆180Updated 2 years ago