yubikey-full-disk-encryption
void-packages
yubikey-full-disk-encryption | void-packages | |
---|---|---|
16 | 671 | |
775 | 2,378 | |
- | 1.1% | |
0.0 | 10.0 | |
5 months ago | about 17 hours ago | |
Shell | Shell | |
Apache License 2.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
yubikey-full-disk-encryption
- I have seen in a lot of posts here people say not to use Google Authentication for 2FA. Can someone simply explain why, and what should I use instead?
-
LUKS with Yubikey
Would using this be possible? https://github.com/agherzan/yubikey-full-disk-encryption/tree/master/src
-
Getting LUKS, Btrfs, Hibernation and Swap file working in tandem
> Hibernate is less interesting, and apparently unsupported using secure boot anyway.
That's not the case. I have a similar setup to yours (/ on ext4 with separate swap, on LVM on LUKS, separate /efi) and my box hibernates just fine with secure boot and auto-unlock via TPM.
The difference with your setup is I don't use grub, but have the UEFI load a signed unified kernel image directly. Since this works so well, I never had a reason to mess around with yet another moving piece (grub or other bootloader).
As another commenter said, I haven't attempted to mess around with the MOK. I just replaced all the secure boot keys with my own, and I've also signed MS's Windows key (but not the 3rd party one) for my dual-boot needs.
---
For specifics: This is an up-to-date Arch Linux install, running on an HP EliteBook 840 G8 (11th gen intel). I know Debian may have older components than arch, but this setup has been working for more than a year now.
IIRC, the most significant change was brought by systemd 251 which started supporting auto-unlocking LUKS with the TPM. Before that, on an older computer with the same general setup, hibernation worked well, too. I just needed to input the unlock password (which I was too lazy to do, so I just used my yubikey - see https://github.com/agherzan/yubikey-full-disk-encryption).
-
systemd 253 Released With Ukify Tool, systemd-cryptenroll Unlocking Via FIDO2 Tokens
Does yubikey-full-disk-encryption provide anything systemd 253 doesn't now?
-
Tillitis Security Key – Mullvad spin-off inspired by measured boot and DICE
Do you mean something like this: https://github.com/agherzan/yubikey-full-disk-encryption
-
Encrypt data on server (Linux, LUKS) on Raspberry Pi
Full disk encryption is rarely as portable as simply encrypting the files you need. When I ran a “homemade” NAS, I had everything LUKS encrypted. I used a Yubikey to unlock the encrypted data.
-
Using a YubiKey to unlock LUKS - How to secure or encrypt /boot?
A few days ago I akquiriere a Yubikey and I'm currently trying to set up 2FA with the Yubikey and a password to unlock the LUKS container. Since I am running Arch I came across the yubikey-full-disk-encryption package and tested it in an Arch VM. So far it worked really well. The only issue I am having is that compared to my old setup I need to have /boot unencrypted because it seems GRUB itself cannot deal with the 2FA setup and ykfde if /boot is encrypted. Previously I had most of /boot inside the LUKS volume with only the /efi part unencrypted (this is used when telling grub where the efi-directory is - see the previous guide for the full details please) and the GRUB_ENABLE_CRYPTODISK=y option set in the GRUB config.
-
LUKS boot unlock fido2 issue
I don't know about the hanging, I use yubikey-full-disk-encryption which uses challenge-response (1FA or 2FA) which you can set up how many attempts to use the YubiKey before it falls back to the passphrase.
-
Is it possible to crack drive encryption without header?
Related: https://github.com/agherzan/yubikey-full-disk-encryption
-
How safe is encryption?
https://github.com/cornelinux/yubikey-luks or https://github.com/agherzan/yubikey-full-disk-encryption with yubikey 5 will get you going. It is a bit expensive to get two keys (regular and backup), but these can be also used to secure most of the online accounts.
void-packages
-
Damn Small Linux 2024
I was looking for a lightweight OS to run on old Asus Eee PC 1005 HA, which uses a 32-bit Intel Atom N270 processor. I installed Void Linux (https://voidlinux.org/).
I may give DSL 2024 a try and see how it compares.
- Chimera Linux
-
When are we ditching systemd?
Linux Void
- Une nouvelle mise à jour de Systemd permettra à Linux de bénéficier de l'infâme "écran bleu de la mort" de Windows, mais la fonctionnalité a reçu un accueil très mitigé
-
How do I update one of these premade ESP32 boards?
My computer is running Void Linux and it has only a wired network connection. I can hook up my phone for USB tethering if I need to connect to the WiFi of the ESP32. How do I update the software without downloading some shady programs from filesharing site links on my system? I have the Arduino IDE and the esptool.py script installed.
- Linuxi kasutaja, mis distrot kodus kasutad ja millest see valik?
- I want to be a packager
-
Hyphens, minus, and dashes in Debian man pages
Classic "everyone is using the software wrong, but it's the fault of everyone, and not the software".
Some distros like Void seem to patch this out.[1]
From mandoc/mdocml's mandoc_char(7) [2]
In roff(7) documents, the minus sign is normally written as ‘\-’. In manual pages, some style guides recommend to also use ‘\-’ if an ASCII 0x2d “hyphen-minus” output glyph that can be copied and pasted is desired in output modes supporting it, for example in -T utf8 and -T html. But currently, no practically relevant manual page formatter requires that subtlety, so in manual pages, it is sufficient to write plain ‘-’ to represent hyphen, minus, and hyphen-minus.
Which is the common-sense thing to do.
Meanwhile, GNU projects become increasingly less relevant due to obnoxiousness like this.
In general the amount of wankery of "the correct hyphen" is staggering.
[1]: https://man.openbsd.org/mandoc_char
[2]: https://github.com/void-linux/void-packages/blob/20c66829134...
-
Thoughts on Void Linux?
So I was about to configure a new Archlinux build on my PC and came across Void Linux. I had already read about it a year ago but never researched it in depth. I know that is a Linux distribution made from scratch, with a different package manager and so on. Void Linux users or people who have tried it, what are your thoughts on it? Do you think the PM is easy to use? what about updates and bugs? what desktop or Tilling Window Manager do you use? could you tell me about it?
-
Question about python venv
Good news about dbus-next: https://github.com/void-linux/void-packages/pull/46760
What are some alternatives?
dracut - dracut the event driven initramfs infrastructure
AppImageLauncher - Helper application for Linux distributions serving as a kind of "entry point" for running and integrating AppImages
fido2luks - Decrypt your LUKS partition using a FIDO2 compatible authenticator
ungoogled-chromium - Google Chromium, sans integration with Google
solokey-full-disk-encryption - Use SoloKey to unlock a LUKS encrypted partition
gentoo - Official Gentoo ebuild repository
wireguard-initramfs - Use dropbear over wireguard.
nix - Nix, the purely functional package manager
zfsUnlocker - A modular zfs unlocker hook for mkinitcpio on Archlinux.
sway - i3-compatible Wayland compositor
disk-encryption-hetzner - Encrypt a hetzner server from the "serverbörse" and unlock it remote via ssh
xdeb - XDEB - Convert deb (Debian) packages to xbps (Void Linux)