feat(stolas): enable TPM2 LUKS keyslot

This commit is contained in:
Tim Schubert 2025-07-26 13:43:39 +02:00
parent 215f4313bd
commit a7e27be92f
No known key found for this signature in database

View file

@ -33,7 +33,10 @@
#passwordFile = "/tmp/secret.key"; # Interactive #passwordFile = "/tmp/secret.key"; # Interactive
settings = { settings = {
allowDiscards = true; allowDiscards = true;
#keyFile = "/tmp/secret.key"; crypttabExtraOpts = [
"tpm2-device=auto"
"tpm2-pin=yes"
];
}; };
#additionalKeyFiles = [ "/tmp/additionalSecret.key" ]; #additionalKeyFiles = [ "/tmp/additionalSecret.key" ];
content = { content = {