{"repo":"agherzan/yubikey-full-disk-encryption","free":true,"listed":false,"github":"https://github.com/agherzan/yubikey-full-disk-encryption","clone":"git clone https://github.com/agherzan/yubikey-full-disk-encryption.git","description":"Use YubiKey to unlock a LUKS partition","language":"Shell","stars":891,"topics":["luks","encryption","yubikey","archlinux","yubico","linux","initramfs","luks-partition","unlock","disk-encryption"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"YubiKey Full Disk Encryption This project leverages a YubiKey HMAC-SHA1 Challenge-Response mode for creating strong LUKS encrypted volume passphrases. It can be used in intramfs stage during boot process as well as on running system. Be aware that this was only tested and intended for: Arch Linux and its derivatives YubiKey (version 4 or later) There is similar project targeting Debian/Ubuntu based systems: yubikey-luks Table of Contents ================= YubiKey Full Disk Encryption Table of Contents Design Automatic mode with stored challenge (1FA) Manual mode with secret challenge (2FA) Install From Arch Linux official repository From Github using 'makepkg' From Github using 'make' Configure Configure HMAC-SHA1 Challenge-Response slot in YubiKey Edit /etc/ykfde.conf file Usage Format new LUKS encrypted volume using ykfde passphrase Enroll ykfde passphrase to existing LUKS encrypted volume Enroll new ykfde passphrase to existing LUKS encrypted volume protected by old ykfde passphrase Unlock LUKS encrypted volume protected by ykfde passphrase Kill ykfde passphrase for existing LUKS encrypted volume Enable ykfde initramfs hook Enable NFC support in ykfde initramfs hook (experimental) Enable ykfde suspend service (experimental) License Design The passphrase for unlocking LUKS encrypted volumes can be created in two ways: Automatic mode with stored challenge (1FA) In Automatic mode you create custom challenge with 0-64 byte length and store it in cleartext in /etc/ykfde.conf an","default_branch":null,"files":null,"tree":[],"storefront":"/r/agherzan","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/agherzan/yubikey-full-disk-encryption/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}