[isar-cip-core][PATCH 1/2] doc/README.factory-reset: Explicitly document full disk encryption is not supported with factory reset tpm clearing enabled.

[email protected]
Newsgroups org.cip-project.lists.cip-dev
Message-ID <[email protected]>
From: Alexander Heinisch <[email protected]>

Signed-off-by: Alexander Heinisch <[email protected]>
---
 doc/README.factory-reset.md | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/doc/README.factory-reset.md b/doc/README.factory-reset.md
index 4b1a1ab..15c4f60 100644
--- a/doc/README.factory-reset.md
+++ b/doc/README.factory-reset.md
@@ -23,6 +23,8 @@ and [systemd](https://github.com/systemd/systemd/blob/114ad16c4dcac136fb7646866f
 use the primary key of TPM. To ensure that the key is not reused the factory-reset deletes the primary key from the TPM
 before formatting the selected hard drives with a new LUKS container.
 
+> Note: By default, the factory reset deletes the TPM primary key. As a result, any A/B rootfs partitions using TPM-sealed encryption will become inaccessible, since their encryption keys can no longer be unsealed. Factory reset with full disk encryption on A/B rootfs partitions is therefore not supported unless TPM key clearing is disabled.
+
 The removal of the TPM keys can be deactivated by setting the variable `INITRAMFS_FACTORY_RESET_CLEAR_TPM` to `0`.
 As the factory-reset is executed before the disks are unlocked in the initramfs, the file system type must be provided with the
 variable `INITRAMFS_FACTORY_RESET_LUKS_FORMAT_TYPE`. The factory-reset of encrypted partition is not supported with the file based
@@ -54,7 +56,7 @@ root@demo:~# find /var -name "to-be-deleted"
 
 ## Use cases
 
-- The primary use case is resetting data partitions (e.g. `/home` and `/var`). This also resets any configuration changes made under `/etc`, since the read-write overlay for /etc is currently backed by /var.
+- The primary use case is resetting (wiping) data partitions (e.g. `/home` and `/var`). This also resets any configuration changes made under `/etc`, since the read-write overlay for /etc is currently backed by /var.
 - If the `/etc` RW overlay is backed by a dedicated partition (separate from `/home` or `/var`), that partition can be formatted independently to restore default configurations (included at build time).
 
 ## Relevance to IEC 62443-4-2
-- 
2.47.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.