All about Disk Encryption

Automatically decrypt your disk using TPM2

https://fedoramagazine.org/automatically-decrypt-your-disk-using-tpm2/

Disk Encryption | Fedora | LUKS | Security | TPM2

This Fedora Magazine guide demonstrates how to use a TPM2 chip with clevis and systemd-cryptenroll to automatically unlock LUKS-encrypted partitions at boot.

It explains TPM2 PCRs (Platform Configuration Registers), trust assumptions, prerequisites, and step-by-step commands.

It gives concrete commands and workflow: install clevis packages, regenerate the initramfs with dracut, bind a LUKS device using clevis luks bind, use systemd-cryptenroll, and update /etc/crypttab.

  • Automates disk unlocking using a TPM-bound secret to avoid typing a passphrase each boot.
  • Uses PCR measurements (e.g., 1,4,5,7,9) to restrict unlocking to a specific, measured boot state.
  • Notes the need to rebind after kernel or initramfs updates and provides clevis luks regen and unbind instructions.
  • Warns about security trade-offs and firmware/manufacturer trust, citing BitLocker research as a cautionary example.
  • Includes troubleshooting tips (delay plymouth prompts, dracut regeneration) and links to further resources.

Suitable for users who want convenience while accepting the platform-trust tradeoffs and who keep passphrase backups.