systemd-cryptenroll.md 2.2 KB

systemd-cryptenroll

LUKS2๋กœ ์•”ํ˜ธํ™”๋œ ์žฅ์น˜๋ฅผ ์ž ๊ธˆ ํ•ด์ œํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ฐฉ๋ฒ•์„ ๋Œ€ํ™”์‹์œผ๋กœ ๋“ฑ๋กํ•˜๊ฑฐ๋‚˜ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค. ๋ณ„๋„๋กœ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ์•”ํ˜ธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์žฅ์น˜๋ฅผ ์ž ๊ธˆ ํ•ด์ œํ•ฉ๋‹ˆ๋‹ค. ์‹œ์Šคํ…œ ๋ถ€ํŒ… ์‹œ ํŒŒํ‹ฐ์…˜์„ ์ž ๊ธˆ ํ•ด์ œํ•˜๋ ค๋ฉด /etc/crypttab ํŒŒ์ผ์ด๋‚˜ initramfs๋ฅผ ์—…๋ฐ์ดํŠธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋” ๋งŽ์€ ์ •๋ณด: https://www.freedesktop.org/software/systemd/man/systemd-cryptenroll.html.

  • ์ƒˆ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋“ฑ๋ก (cryptsetup luksAddKey์™€ ์œ ์‚ฌ):

systemd-cryptenroll --password {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • ์ƒˆ ๋ณต๊ตฌ ํ‚ค ๋“ฑ๋ก (์ฆ‰, ๋Œ€์ฒด๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๋ฌด์ž‘์œ„ ์ƒ์„ฑ ์•”ํ˜ธ):

systemd-cryptenroll --recovery-key {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ํ† ํฐ ๋ชฉ๋ก ๋‚˜์—ด ๋˜๋Š” ์ƒˆ PKCS#11 ํ† ํฐ ๋“ฑ๋ก:

systemd-cryptenroll --pkcs11-token-uri {{list|auto|pkcs11_ํ† ํฐ_uri}} {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ FIDO2 ์žฅ์น˜ ๋ชฉ๋ก ๋‚˜์—ด ๋˜๋Š” ์ƒˆ FIDO2 ์žฅ์น˜ ๋“ฑ๋ก (auto๋Š” ํ† ํฐ์ด ํ•˜๋‚˜๋งŒ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์„ ๋•Œ ์žฅ์น˜ ์ด๋ฆ„์œผ๋กœ ์‚ฌ์šฉ ๊ฐ€๋Šฅ):

systemd-cryptenroll --fido2-device {{list|auto|๊ฒฝ๋กœ/๋Œ€์ƒ/fido2_hidraw_์žฅ์น˜}} {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • ์‚ฌ์šฉ์ž ์ธ์ฆ(์ƒ์ฒด ์ธ์‹)๊ณผ ํ•จ๊ป˜ ์ƒˆ FIDO2 ์žฅ์น˜ ๋“ฑ๋ก:

systemd-cryptenroll --fido2-device {{auto|๊ฒฝ๋กœ/๋Œ€์ƒ/fido2_hidraw_์žฅ์น˜}} --fido2-with-user-verification yes {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • FIDO2 ์žฅ์น˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ž ๊ธˆ ํ•ด์ œํ•˜๊ณ  ์ƒˆ FIDO2 ์žฅ์น˜ ๋“ฑ๋ก:

systemd-cryptenroll --unlock-fido2-device {{๊ฒฝ๋กœ/๋Œ€์ƒ/fido2_hidraw_์ž ๊ธˆ_ํ•ด์ œ_์žฅ์น˜}} --fido2-device {{๊ฒฝ๋กœ/๋Œ€์ƒ/fido2_hidraw_๋“ฑ๋ก_์žฅ์น˜}} {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • TPM2 ๋ณด์•ˆ ์นฉ ๋“ฑ๋ก (๋ณด์•ˆ ๋ถ€ํŒ… ์ •์ฑ… PCR๋งŒ) ๋ฐ ์ถ”๊ฐ€์ ์ธ ์˜๋ฌธ์ž PIN ํ•„์š”:

systemd-cryptenroll --tpm2-device {{auto|๊ฒฝ๋กœ/๋Œ€์ƒ/tpm2_๋ธ”๋ก_์žฅ์น˜}} --tpm2-with-pin yes {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}

  • ๋ชจ๋“  ๋นˆ ๋น„๋ฐ€๋ฒˆํ˜ธ/๋ชจ๋“  ๋น„๋ฐ€๋ฒˆํ˜ธ/๋ชจ๋“  FIDO2 ์žฅ์น˜/๋ชจ๋“  PKCS#11 ํ† ํฐ/๋ชจ๋“  TPM2 ๋ณด์•ˆ ์นฉ/๋ชจ๋“  ๋ณต๊ตฌ ํ‚ค/๋ชจ๋“  ๋ฐฉ๋ฒ• ์ œ๊ฑฐ:

systemd-cryptenroll --wipe-slot {{empty|password|fido2|pkcs#11|tpm2|recovery|all}} {{๊ฒฝ๋กœ/๋Œ€์ƒ/luks2_๋ธ”๋ก_์žฅ์น˜}}