Automatically decrypt your disk using TPM2
https://fedoramagazine.org/automatically-decrypt-your-disk-using-tpm2/
Disk Encryption | Fedora | LUKS | Security | TPM2This Fedora Magazine guide demonstrates how to use a TPM2 chip with clevis and systemd-cryptenroll to automatically unlock LUKS-encrypted partitions at boot.
It explains TPM2 PCRs (Platform Configuration Registers), trust assumptions, prerequisites, and step-by-step commands.
It gives concrete commands and workflow: install clevis packages, regenerate the initramfs with dracut, bind a LUKS device using clevis luks bind, use systemd-cryptenroll, and update /etc/crypttab.
- Automates disk unlocking using a TPM-bound secret to avoid typing a passphrase each boot.
- Uses PCR measurements (e.g.,
1,4,5,7,9) to restrict unlocking to a specific, measured boot state. - Notes the need to rebind after kernel or initramfs updates and provides
clevis luks regenand unbind instructions. - Warns about security trade-offs and firmware/manufacturer trust, citing BitLocker research as a cautionary example.
- Includes troubleshooting tips (delay
plymouthprompts, dracut regeneration) and links to further resources.
Suitable for users who want convenience while accepting the platform-trust tradeoffs and who keep passphrase backups.