Comment 4 for bug 1876989

Revision history for this message
TJ (tj) wrote :

Adding a keyfile to be automatically used is done via the cryptsetup-initramfs package. Keyfile is only exposed to root user. When embedding the keyfile in the initrd.img /boot/ should be encrypted so the keyfile cannot be obtained without unlocking the LUKS container.