heads/initrd/bin
Matt DeVillier 0cae2d7805
kexec-save-default: guard TPM LUKS usage with config option
Add CONFIG_TPM_NO_LUKS_DISK_UNLOCK to allow Librem boards to opt
out of using TPM to store LUKS key, and use it to guard the user
option to add the disk encryption key to the TPM.

Select this option for all Librem boards; all other boards which
select CONFIG_TPM=y will have no change in functionality.

Signed-off-by: Matt DeVillier <matt.devillier@puri.sm>
2020-06-08 11:40:55 -05:00
..
cbfs-init Read and measure an EFI file into initrd during init 2018-04-29 19:58:44 -07:00
config-gui.sh config-gui: mount new /boot after selection 2019-11-18 11:16:53 -06:00
flash-gui.sh Eliminate use of CONFIG_USB_BOOT_DEV 2020-02-19 22:32:08 -06:00
flash.sh Flash.sh cleanup: Fix FLASHROM_OPTIONS -> CONFIG_FLASHROM_OPTIONS to be exported by Makefile 2020-02-19 17:18:01 -05:00
flashrom-kgpe-d16-openbmc.sh Re-add the flashrom script for kgpe-d16-openbmc 2018-05-11 14:23:48 -07:00
generic-init Use global /tmp/config that combines multiple config files 2018-12-06 15:24:28 -08:00
gpg-gui.sh Eliminate use of CONFIG_USB_BOOT_DEV 2020-02-19 22:32:08 -06:00
gpgv Enable gpg with card support (issue #32) 2017-04-05 17:59:49 -04:00
gui-init gui-init: fix checking librem key card-status 2020-02-19 16:31:39 -06:00
kexec-boot Keep Xen cmdline arguments while appending Heads required ones. Fixes #536 2019-03-17 19:37:31 -04:00
kexec-insert-key Allow boot without unseal of TPM LUKS key 2017-09-02 14:13:29 -04:00
kexec-iso-init Use global /tmp/config that combines multiple config files 2018-12-06 15:24:28 -08:00
kexec-parse-bls Parse grub config files for Fedora 29/30 2019-05-02 22:23:59 +01:00
kexec-parse-boot Strip invalid leading/trailing '/' from script params 2017-09-02 14:13:29 -04:00
kexec-save-default kexec-save-default: guard TPM LUKS usage with config option 2020-06-08 11:40:55 -05:00
kexec-save-key Allow TPM LUKS key to be set during default selection 2017-09-02 14:13:29 -04:00
kexec-seal-key also shred LUKS sealed secret when done instead of rm it 2019-02-24 10:29:09 -05:00
kexec-select-boot kecec_select_boot: default to Y when setting new boot option 2019-08-05 11:03:46 -05:00
kexec-sign-config Use global /tmp/config that combines multiple config files 2018-12-06 15:24:28 -08:00
kexec-unseal-key supress errors on console when files don't exist (equivalent of rm -f) 2019-02-24 10:28:57 -05:00
key-init properly deal with trusting keys to supress UX confusion about trusted keys 2019-02-08 12:38:38 -05:00
mount-usb Bugfixes to mount-usb 2019-04-16 12:55:00 -07:00
network-init-recovery network-init-recovery: do DHCP, then ask NTP from DNS server before attempting sync on internet 2020-04-22 15:00:48 -04:00
oem-factory-reset oem-factory-reset: fix GPG key backup filename 2020-02-19 16:47:51 -06:00
poweroff Ensure recovery for failed default boot 2017-09-02 14:13:29 -04:00
qubes-measure-luks qubes init script and improved TPM disk encryption with LUKS headers (issue #123 and #6) 2017-04-01 23:02:00 -04:00
reboot Ensure recovery for failed default boot 2017-09-02 14:13:29 -04:00
seal-libremkey seal-libremkey: add newlines for readability 2019-07-12 11:51:17 -05:00
seal-totp shred TOTP_SECRET also when generation is successful 2019-02-24 11:11:00 -05:00
t430-flash.init Add T430 board support 2020-05-15 18:52:11 +01:00
tpm-reset helper to do a forcible TPM reset (issue #27) 2017-04-12 06:45:15 -04:00
uefi-init Read and measure an EFI file into initrd during init 2018-04-29 19:58:44 -07:00
unseal-hotp unseal-hotp: ensure /boot mounted before checking HOTP secret 2019-11-18 21:52:48 -06:00
unseal-totp supress errors on console when files don't exist (equivalent of rm -f) 2019-02-24 10:28:57 -05:00
usb-init Use global /tmp/config that combines multiple config files 2018-12-06 15:24:28 -08:00
usb-scan Eliminate use of CONFIG_USB_BOOT_DEV 2020-02-19 22:32:08 -06:00
wget-measure.sh wget and measure files into the PCR 2017-03-27 18:03:29 -04:00
x230-flash.init initrd: x230-flash: fix commandline instructions for flashing 2019-05-23 13:10:53 +02:00