encrypt partition on embedded device with TPM without passhrase

Gylstorff Quirin <[email protected]> Wed, 17 Jul 2024 15:28:57 +0200
Newsgroups dev.linux.lists.cryptsetup
Message-ID <[email protected]>
Dear all,

we have the scenario to encrypt an partition on an embedded device with 
TPM.

Currently we encrypt the partition with a temporary key and afterwards 
we enroll the TPM token.

After the token is enrolled with delete the temporary key.


Is there a way to encrypt the partition directly with TPM token without 
using a temporary key?

Using a token  should work both with cryptsetup luksFormat and 
cryptsetup reencrypt.

Best regards,

-- 
Quirin Gylstorff

Siemens AG
Technology