mirror of
https://github.com/linuxboot/heads.git
synced 2024-12-18 20:47:55 +00:00
Make it possible to report headers of which LUKSes to be unlocked via TPM change.
This commit is contained in:
parent
b4b0bc4a7a
commit
ed1c23aaa3
@ -51,6 +51,8 @@ tpm extend -ix 4 -ic generic \
|
||||
|
||||
# Check to continue
|
||||
if [ "$unseal_failed" = "y" ]; then
|
||||
diff "$(dirname $INITRD)/kexec_lukshdr_hash.txt" /tmp/luksDump.txt \
|
||||
&& echo "Headers of LUKSes to be unlocked via TPM do not change."
|
||||
confirm_boot="n"
|
||||
read \
|
||||
-n 1 \
|
||||
|
@ -152,3 +152,6 @@ fi
|
||||
|
||||
shred -n 10 -z -u "$TPM_SEALED" 2> /dev/null \
|
||||
|| warn "Failed to delete the sealed secret - continuing"
|
||||
|
||||
cp /tmp/luksDump.txt "$paramsdir/kexec_lukshdr_hash.txt" \
|
||||
|| warn "Failed to have hashes of LUKS header - continuing"
|
||||
|
Loading…
Reference in New Issue
Block a user