Re: systemd-cryptenroll

Date: 2023-04-18 07:40 am (UTC)
From: [personal profile] mjg59
You type in a passphrase, that gets turned into an encrypted key, that gets passed to the TPM to be decrypted with a TPM-bound key, you get the actual key back. You can't perform the second chunk of this without the actual TPM being involved, so while you can perform the first chunk in parallel you're still then rate-limited by the speed of the TPM.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org

Profile

Matthew Garrett

About Matthew

Power management, mobile and firmware developer on Linux. Security developer at nvidia. Ex-biologist. Content here should not be interpreted as the opinion of my employer. Also on Mastodon and Bluesky.

Expand Cut Tags

No cut tags