Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 2 months ago

My servers require manual unlock via SSH at boot. It has been great for years.

  • source
  • parent