Re: [isar-cip-core][PATCH 0/2] Remove unsupported combinations for factory-reset from Kconfig and document them explicitly

Jan Kiszka <[email protected]>
Newsgroups org.cip-project.lists.cip-dev
Message-ID <[email protected]>
On 10.08.26 08:55, Quirin Gylstorff wrote:
> 
> 
> On 8/7/26 5:44 PM, [email protected] wrote:
>> From: Alexander Heinisch <[email protected]>
>>
>> By default factory reset clears the tpm. Therefore, keys needed to
>> decrypt the immutable A/B rootfs in full disk encryption setups
>> cannot be retrieved anymore. Thus, the boot fails and the device
>> cannot be recovered.
>>
>> This patch series removes such combination from the kconfig and documents
>> the issue explicitly.
> 
> This was never in scope of the factory reset. You could implement it by
> moving the keys into the boot partition. But this move will create
> another can of worms.
> 

We already have an option to skip TPM reset if not desired or
problematic. Why not use that, or build smarter on top of it?

Factory reset has already way too many limitations. I would rather likto
work in more cases than in less.

Jan

-- 
Siemens AG, Foundational Technologies
Linux Expert Center
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.