LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 03-04-2024, 11:10 AM   #1
lin-ux
LQ Newbie
 
Registered: Mar 2024
Posts: 1

Rep: Reputation: 0
Full disk encryption using clevis tpm-tools2 with LUKS question


Hello,

This is my first post in the hope I can get an answer for something I cannot find and answer to anywhere.

I would like to clone a virtual/physical machine which uses full disk encryption and have it boot without requiring any configuration changes. Using the tpm2 tools I need to populate the TPM with the same private/public (SRK)key as the source machine. Is it possible to export the private/public keys used by Clevis and import this this into different TPM allowing the O/S to decrypt the volume?

Example;

1) Setup a VM installed with Redhat 8.4 using full disk encryption and sealed to the TPM (PMK) using clevis (VM1).

2) Create a new VM with new TPM not a cloned virtual machine this might be virtual or physical hardware

3) Using the tpm2 command line tools to migrate the TPM SRK(root storage key) public key from VM1 to VM2 so it automatically mounts and decrypt with the need for passphrase or manual intervention.

4) Successfully boot the machine without the need to use a passphrase or any configuration changes.

Thanks in advance for any help on this.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Uefi and full disk encryption with lvm on luks with luks keyfile lancsuk Slackware 2 04-02-2021 02:43 PM
Disk Encryption with clevis and tang stile23 Linux - Security 3 06-28-2018 04:17 PM
How to have luks encryption with keyfile OR passphrase (efi full disk encryption including boot)? byroncollege Linux - Security 2 03-30-2017 07:45 AM
Mint 18 Full disk encryption VS Veracrypt Full Disk encryption: Help a Noob Decide Please ! APeacefulRig Linux - Security 2 11-11-2016 08:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 06:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration