MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
key
Recherche

Ubuntu to add TPM-backed full-disk encryption

jeudi 7 septembre 2023, 18:56 , par LWN.net
The Ubuntu blog has a
detailed article on plans to add full-disk encryption, with the key
stored in the system's trusted platform module (TPM), to the desktop
distribution.

In order to deliver these benefits, the implementation of
TPM-backed FDE relies on two main design principles. First, it
seals the FDE secret key to the full EFI state, including the
kernel command line. Second, access to the decryption key will only
be permitted if and when the device boots software that has been
defined as authorised to access the confidential data. This is
when the initrd code will unseal the key in the secure-boot
protected kernel.efi at boot time.
https://lwn.net/Articles/943869/
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Date Actuelle
ven. 10 mai - 15:43 CEST