Monday, November 06, 2023

Re: OpenBSD FDE: Protect with keydisk + passphrase

Il 05/11/2023 12:16, misc@phosphorus.com.br ha scritto:
[...]
> Now I use FDE with a keydisk, but would like to protect the bootable
> system with a keydisk + passphase (something you have + something you
> know).
>
> Any chance doing this directly using bioctl ?

I don't think so: softraid's on-disk volume key can be encrypted with a
keydisk or with a passphrase. Not both of them.
See this recent explanation written by Stefan Sperling:
https://marc.info/?l=openbsd-misc&m=168500028802972&w=2

--
f

No comments:

Post a Comment