Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Progress report 1
systemd, pick FIDO2:systemd, so “future-proof”.smartcard-key-luksseems unmaintained on GitHub and on GitLab.