Using a YubiKey to unlock LUKS - How to secure or encrypt /boot?

This page summarizes the projects mentioned and recommended in the original post on /r/linuxquestions

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • yubikey-full-disk-encryption

    Use YubiKey to unlock a LUKS partition

  • A few days ago I akquiriere a Yubikey and I'm currently trying to set up 2FA with the Yubikey and a password to unlock the LUKS container. Since I am running Arch I came across the yubikey-full-disk-encryption package and tested it in an Arch VM. So far it worked really well. The only issue I am having is that compared to my old setup I need to have /boot unencrypted because it seems GRUB itself cannot deal with the 2FA setup and ykfde if /boot is encrypted. Previously I had most of /boot inside the LUKS volume with only the /efi part unencrypted (this is used when telling grub where the efi-directory is - see the previous guide for the full details please) and the GRUB_ENABLE_CRYPTODISK=y option set in the GRUB config.

  • yubikey-luks

    Two factor authentication for harddisk encryption

  • Regarding you adding a Yubikey to your Debian setup... I think there is a package called yubikey-luks which is also in the official debian repos. I have not tested it myself but maybe it can be of help to you!

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • systemd 253 Released With Ukify Tool, systemd-cryptenroll Unlocking Via FIDO2 Tokens

    1 project | /r/linux | 18 Feb 2023
  • LUKS boot unlock fido2 issue

    2 projects | /r/archlinux | 11 Jun 2022
  • Is it possible to crack drive encryption without header?

    1 project | /r/linux4noobs | 18 Feb 2022
  • How safe is encryption?

    2 projects | /r/PrivacyGuides | 31 Dec 2021
  • git.rip has been seized by the FBI

    2 projects | /r/DataHoarder | 13 Mar 2021