Comment on What do you use to mount encrypted drives on boot?

akash_rawal@lemmy.world ⁨6⁩ ⁨months⁩ ago

TPM stores the encryption key against secure boot. That way, if attacker disables/alters secure boot then TPM won’t unseal the key. I use clevis to decrypt the drive.

source
Sort:hotnewtop