Skip to content

Use clevis-luks-askpass systemd units in dracut#192

Closed
ArturGaspar wants to merge 1 commit intolatchset:masterfrom
ArturGaspar:dracut_systemd_service
Closed

Use clevis-luks-askpass systemd units in dracut#192
ArturGaspar wants to merge 1 commit intolatchset:masterfrom
ArturGaspar:dracut_systemd_service

Conversation

@ArturGaspar
Copy link
Copy Markdown

With Before=systemd-ask-password-console.service systemd-ask-password-plymouth.service it also fixes #150, so that the user only gets prompted for a password if the clevis unlocker fails.

I am using this with the tpm2 pin and it works correctly both in case of success or failure. If there is interest in merging this I can also test if it works with the tang pin and others.

@sergio-correia
Copy link
Copy Markdown
Collaborator

Thanks for this. And apologies for not getting to it earlier. We merged something similar in cbb64c4 (dracut: favour systemd units over dracut hooks).

I filed this other issue with plymouth regarding the passphrase not being dismissed when a LUKS device is unlocked non-interactively, in our case, with clevis: https://gitlab.freedesktop.org/plymouth/plymouth/-/issues/126 (plymouth splash is not dismissed when LUKS device is unlocked non-interactively) and it would help #150 once resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Slow unlock and passphrase request remains during boot

2 participants