Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-16182

Support remote sealing in systemd-cryptenroll/systemd-cryptsetup

    • Icon: Story Story
    • Resolution: Done-Errata
    • Icon: Major Major
    • rhel-9.4
    • rhel-9.3.0
    • systemd
    • None
    • rhel-sst-cs-plumbers
    • ssg_core_services
    • 26
    • 13
    • Dev ack
    • False
    • Hide

      None

      Show
      None
    • None
    • Red Hat Enterprise Linux
    • None
    • None

      Support for remote (when only public key from the target TPM is available) secret sealing and consumption of the remotely sealed data was added to systemd-cryptsetup/systemd-cryptenroll, see https://github.com/systemd/systemd/pull/28519 and its pre-requisites:

      The functionality is needed for RHEL on Confidential VMs on Azure where root volume is pre-encrypted by Azure infrastructure. Currently, RHEL uses a downstream-only solution:

              dtardon@redhat.com David Tardon
              vkuznets@redhat.com Vitaly Kuznetsov
              systemd maint mailing list systemd maint mailing list
              Frantisek Sumsal Frantisek Sumsal
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: