Add fido2 instructions.
This commit is contained in:
65
fido2.txt
Normal file
65
fido2.txt
Normal file
@@ -0,0 +1,65 @@
|
||||
Enrolling a FIDO2 key for LUKS unlock on straylight (systemd-cryptenroll method)
|
||||
=================================================================================
|
||||
|
||||
Background
|
||||
----------
|
||||
NixOS 26.05 removed support for the old scripted-stage-1 option
|
||||
boot.initrd.luks.fido2Support. The supported method is systemd-cryptsetup:
|
||||
enroll the key directly into the LUKS2 header with systemd-cryptenroll, then
|
||||
tell the initrd to look for a FIDO2 token via crypttab options.
|
||||
|
||||
straylight's encrypted devices:
|
||||
root: /dev/disk/by-uuid/922e2c13-35bc-40de-a829-716b9368e4a7 (luks-922e2c13-...)
|
||||
home: /dev/disk/by-uuid/edfdcdf4-083a-4826-a1f8-9670545e0bc5 (home-crypt)
|
||||
|
||||
Steps
|
||||
-----
|
||||
1. Plug in the FIDO2 key, then enroll it in each LUKS device (you will be
|
||||
prompted for an existing passphrase and the token PIN):
|
||||
|
||||
doas systemd-cryptenroll --fido2-device=auto /dev/disk/by-uuid/922e2c13-35bc-40de-a829-716b9368e4a7
|
||||
doas systemd-cryptenroll --fido2-device=auto /dev/disk/by-uuid/edfdcdf4-083a-4826-a1f8-9670545e0bc5
|
||||
|
||||
Verify with:
|
||||
doas systemd-cryptenroll /dev/disk/by-uuid/922e2c13-35bc-40de-a829-716b9368e4a7
|
||||
(should list a "fido2" slot alongside the "password" slot)
|
||||
|
||||
2. Update hw/straylight/hardware-configuration.nix to use systemd stage 1 and
|
||||
point crypttab at the token (mirrors orion/vade):
|
||||
|
||||
boot.initrd.systemd.enable = true;
|
||||
|
||||
boot.initrd.luks.devices."luks-922e2c13-35bc-40de-a829-716b9368e4a7" = {
|
||||
device = "/dev/disk/by-uuid/922e2c13-35bc-40de-a829-716b9368e4a7";
|
||||
crypttabExtraOpts = [
|
||||
"fido2-device=auto"
|
||||
"token-timeout=10"
|
||||
];
|
||||
};
|
||||
|
||||
boot.initrd.luks.devices."home-crypt" = {
|
||||
device = "/dev/disk/by-uuid/edfdcdf4-083a-4826-a1f8-9670545e0bc5";
|
||||
crypttabExtraOpts = [
|
||||
"fido2-device=auto"
|
||||
"token-timeout=10"
|
||||
];
|
||||
};
|
||||
|
||||
token-timeout=10 makes boot fall back to a passphrase prompt after 10
|
||||
seconds if the key is not plugged in.
|
||||
|
||||
3. Rebuild and reboot to test:
|
||||
rebuild-nixos
|
||||
|
||||
Keep the passphrase slot — do NOT remove it. It is the fallback if the
|
||||
hardware key fails or is lost.
|
||||
|
||||
Notes
|
||||
-----
|
||||
- If migrating from an old scripted-stage-1 enrollment (fido2luks), remove the
|
||||
old key slot afterwards with `doas cryptsetup luksKillSlot <device> <slot>`;
|
||||
straylight never had one enrolled, so this does not apply here.
|
||||
- References:
|
||||
https://www.freedesktop.org/software/systemd/man/systemd-cryptenroll.html
|
||||
https://www.freedesktop.org/software/systemd/man/systemd-cryptsetup.html
|
||||
https://www.freedesktop.org/software/systemd/man/crypttab.html
|
||||
Reference in New Issue
Block a user