]> git.ipfire.org Git - thirdparty/systemd.git/commit
Introduce 'fixate-volume-key' option to repart/cryptsetup to pin the exact LUKS volum...
authorLennart Poettering <lennart@poettering.net>
Mon, 19 Jan 2026 20:59:47 +0000 (21:59 +0100)
committerGitHub <noreply@github.com>
Mon, 19 Jan 2026 20:59:47 +0000 (21:59 +0100)
commit9316e02c9d72a09c9ff7ac0ec4dc92d94440b60f
tree5e1c429a2764aa16c11cd1f19bd2f59a7181e48e
parent3a0ddbe338f1c8c63e8d4378499517b65a6407a8
parent398acccb2ac97c99a8bef6b542b4516e158266a8
Introduce 'fixate-volume-key' option to repart/cryptsetup to pin the exact LUKS volume key hash (#40343)

Add an option to generate the expected volume key hash for LUKS volumes
by systemd-repart
and put it to crypttab, make systemd-cryptsetup check it upon attaching.
The format of the hash
matches what's currently being measured to TPM2 PCR with
tpm2-measure-pcr=.

Closes #40123