linuxboot / linuxboot/heads-wiki
Document how to reseal disk encryption key in the TPM
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 96
- Forks
- 58
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 11
Description
From https://github.com/osresearch/heads/pull/1282:
> I had trouble after reflashing because it wasn't obvious how to reseal the disk encryption key in the TPM. For posterity: You have to navigate `Options -->` → `Boot Options -->` → `Show OS boot menu` → `Qubes,_with_Xen_hypervisor` → `Make default` and then Heads will prompt `Do you want to reseal a disk key to the TPM [y/N]:`.
We should document things that could lead to this. For example, flashing an updated Heads that changes TPM measurements. Perhaps it belongs in the upgrade guide or an FAQ?
**Edit:** Soon as I posted this, I found https://osresearch.net/Updating#re-owning-the-states:
> - Sign /boot content (GPG User PIN required)
> - Select a new boot default through Boot Options (GPG User PIN required to sign the new default)
> - Optionally set a TPM Disk Unlock Key (Disk Recovery Key passphrase and GPG User PIN required)
I don't think this is clear, and it doesn't explicitly mention resealing the disk encryption key.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Updating guide's “re-owning-the-states” section, especially the existing boot-default and TPM Disk Unlock Key instructions. Clarify when updated Heads measurements require resealing and explicitly name the disk-key resealing prompt and navigation. Done means the upgrade guidance clearly explains the recovery steps without relying on the linked pull request.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100