Tks for the answer. Sorry for seeing it late but it went in the spam
folder :(
I didn't know clevis/tang, but it's really interesting (maybe a bit
overkill in my scenario).
Diego
Il 15/12/2022 18:53, Robert Markula ha scritto:
Am 15.12.22 um 18:15 schrieb Toomas Tamm via linux-fai:
This mess
Just did a quick test. Seems feasible to use clevis w/ tpm2 to securely
bind credentials to a machine. The idea is:
- in case of new install there are no machine-specific files
- secrets gets generated as usual
- once the machine is up & running, use ssh to run a script to
encrypt the needed
Hi all,
after more than a year, a new major FAI release is ready to download.
Following new features are included:
* add support for release specification in package_config via release=
* the partitioning tool now supports partition labels with GPT
* support partition labels and partition