[PATCH v1 0/3] KEYS: trusted: Introduce support for NXP CAAM-based trusted keys
    Richard Weinberger 
    richard at nod.at
       
    Thu Apr  1 11:05:34 UTC 2021
    
    
  
Ahmad,
----- Ursprüngliche Mail -----
> Von: "Ahmad Fatoum" <a.fatoum at pengutronix.de>
>> I don't want you to force to use cryptsetup.
> 
> I'd love to use cryptsetup with LUKS and trusted keys eventually. I'll take
But using LUKS would mean that cryptsetup has access to the plain disc encryption key material?
This would be a no-go for many systems out there, key material must not accessible to userspace.
I know, distrusting userspace root is not easy, but doable. :)
Thanks,
//richard
    
    
More information about the Linux-security-module-archive
mailing list