Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1260675

Bug#1114764: ITP: fido2luks -- Unlock LUKS volumes at boot time using a FIDO2 token

From Alberto Garcia <berto@igalia.com>
Newsgroups linux.debian.bugs.dist, linux.debian.devel
Subject Bug#1114764: ITP: fido2luks -- Unlock LUKS volumes at boot time using a FIDO2 token
Date 2025-09-09 16:10 +0200
Message-ID <Lt7cJ-e32s-11@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Package: wnpp
Severity: wishlist
Owner: Alberto Garcia <berto@igalia.com>
X-Debbugs-Cc: debian-devel@lists.debian.org

* Package name    : fido2luks
  Version         : 0.0.3
  Upstream Contact: Alberto Garcia <berto@igalia.com>
* URL             : https://github.com/bertogg/fido2luks
* License         : GPL-2+
  Programming Lang: POSIX shell
  Description     : Unlock LUKS volumes at boot time using a FIDO2 token

fido2luks is an extension to initramfs-tools to unlock LUKS-encrypted
disks at boot time using a FIDO2 token.

It is designed for LUKS volumes where a FIDO2 token was enrolled using
systemd-cryptenroll --fido2-device.

 ---

Additional info:

systemd allows unlocking LUKS volumes with a FIDO2 token such as the
Nitrokey, YubiKey, etc.

However for full disk encryption scenarios there is currently no way
in Debian to do it at boot time with initramfs-tools, as many users
have noted. The solution involves switching to dracut, and there are a
few tutorials available on the web.

This package provides a simple shell script that can do the job
without having to switch the initramfs implementation.

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#1114764: ITP: fido2luks -- Unlock LUKS volumes at boot time using a FIDO2 token Alberto Garcia <berto@igalia.com> - 2025-09-09 16:10 +0200

csiph-web