elementary / elementary/triage

Decrypt LUKS-encrypted install with security key

Open
#788 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
4
Forks
1
PR merge metrics
No merged PRs in 30d

Description

## Prerequisites
- [x] I have searched open and closed issues for duplicates.

## Feature
**Is your feature request related to a problem? Please describe.**
I use Nitrokeys to better protect myself with a second factor. Currently, as a user, I don't see any way how this can be done in a user-friendly way with elementary OS.
I think that visually integrating a way to use two-factor authentication right from the start of the system can help more people learn and use secure and conscious data handling.

**Describe the solution you'd like**
Since with the new installer the full encryption of my hard disk will become the standard in elementary OS in the future, my dream is that instead of a complicated passphrase I insert the Nitrokey and authenticate myself and log in to the system (and thus decrypt my hard drive) and in a second step even be able to log in to my user account - which would probably be a Greeter Issue.

**Existing work**
Purism has already developed this for its devices and also provided a script that can be adapted to elementary OS.

Read more:
https://docs.puri.sm/Librem_Key/Getting_Started/User_Manual.html#decrypt-luks-encrypted-drives-with-librem-key
and https://puri.sm/posts/pureboot-best-practices/

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.