Summary: | Missing libraries for FIDO2 and TPM2 in dracut image | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Juan Orti <jorti> |
Component: | dracut | Assignee: | dracut-maint-list |
Status: | CLOSED NEXTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | unspecified | ||
Version: | 35 | CC: | anssi.hannula, Daniel, dhpereh, dracut-maint-list, francois.rigault, gordon.messmer, james, jean, jonathan, marco.ce89, me, peljasz, pvalena, thofmann, vilgot, zbyszek |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2022-08-11 09:48:01 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: |
Description
Juan Orti
2021-06-26 10:51:08 UTC
I suspect there's bits missing for pkcs11 too -- I've created bug 1975827 for that. I think I'll leave it up to the devs to decide whether it's worth merging that one in with this. Still an issue in F35: dracut-055-5.fc35.x86_64 systemd-249.4-2.fc35.x86_64 It's a shame that this "bug" survives for this long. Certainly TPM should be included in vanilla default so users would have a puzzle to solve. regards, L. f35, Can confirm. Sadly fell for it without knowing, locking access to my machine. The configuration suggested fixes the issue. There is truly no reason for such a bug to exist, the fix is simple and prevents unnecessary inconveniences. 'systemd-cryptenroll' is a bliss for an easy implementation of enhanced security and hopefully should be accessible for the average user. Dracut 056 fixes this problem, and "install_optional_items" should no longer be necessary. (However, it does require the tpm2-tools package, which is not currently a dependency.) I've tested unlocking LUKS2 with a TPM2 device using dracut-056-1.fc36.x86_64 and can confirm that the workaround "install_optional_items" is no longer needed. Dracut was updated to 057. I don't think changing any defaults is desired at this point. Feel free to open a new bug or reopen this one in case there're still some issues. |