Using that you could set up networking and download the key from somewhere (say a remote KMS that would need user approval before continuing). So you would reduce your problem to being prompted on phone to unlock your desktop.
You could even use some sort of hardware key to prove request came from the physical server. (simplest might be a RP2350 with some key burnt in)
Or you could use something like SGX if it's still available anywhere to prove the same.
...unless your distro uses systemd, which removes keyscript support [1] because the systemd guy "really dislikes generic callouts"
Did not hear about booster. Its README claims "Clevis style data binding. The encrypted filesystem can be bound to TPM2 chip or to a network service.". Does it mean that it tries to deliver various bindings independently from clevis pins, even when duplicating their functions?
I do this with a gateway/router on a PC Engines APU2 that has an internal SSD.
Just ensure GRUB includes the requisite USB modules in its core image, or use grub-mkstandalone to include all modules in core.
With LUKSv2 the seven slot limit doesn't apply.
For headless GRUB is configured to the serial port for its terminal in/out so a passphrase can be typed.
If hardware is stolen it will have hardware key attached.
It is similar to having unencrypted ssd.
Also, someone can temporarily remove the yubikey, fetch the decryption key then place it back.
Key is on my keychain. not attached to the box. I don't need to unlock it remotely. I want to be there and plug my key and touch it and yank it.
> Also, someone can temporarily remove the yubikey, fetch the decryption key then place it back.
If implemented correctly. Nobody can. An encrypted LUKS key would be sent to the yubikey and have it decrypted there. Not the other way.
Disclosure: I am a co-author of Mandos.