Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AEM password also fed to disk decryption #978

Closed
rustybird opened this issue Apr 28, 2015 · 2 comments
Closed

AEM password also fed to disk decryption #978

rustybird opened this issue Apr 28, 2015 · 2 comments
Labels
C: other help wanted This issue will probably not get done in a timely fashion without help from community contributors. P: major Priority: major. Between "default" and "critical" in severity. T: bug Type: bug report. A problem or defect resulting in unintended behavior in something that exists.

Comments

@rustybird
Copy link

If the AEM secret is protected by a TPM password, then that password, after unsealing the secret, will also be used silently to try and decrypt the disk. This can be verified by entering the disk password into the AEM password prompt.

The TPM password should of course be different from the LUKS password, so this bug will trigger #977: After entering the correct TPM password, you'll have to enter the correct disk password twice (at least if Qubes was installed with the btrfs layout).

(Tested on Qubes 3.0 RC1 with anti-evil-maid 2.0.7 and 2.0.8)

@marmarek marmarek added this to the Release 3.0 milestone May 12, 2015
@marmarek marmarek added T: bug Type: bug report. A problem or defect resulting in unintended behavior in something that exists. C: other P: major Priority: major. Between "default" and "critical" in severity. labels May 12, 2015
@rustybird
Copy link
Author

Happens only with plymouth enabled

@marmarek marmarek modified the milestones: Release 3.1, Release 3.0 Sep 2, 2015
@marmarek marmarek modified the milestones: Far in the future, Release 3.1 Feb 8, 2016
@marmarek marmarek added the help wanted This issue will probably not get done in a timely fashion without help from community contributors. label Feb 8, 2016
@andrewdavidwong
Copy link
Member

This bug report has been open for a very long time with no recent activity, and it is not assigned to any current release milestone. It looks like it was left open by mistake, so I'm closing it now. However, if anyone is still affected by this bug on a currently-supported release, please leave a comment, and we'll be happy to reopen this. Thank you.

@andrewdavidwong andrewdavidwong removed this from the Release TBD milestone Jul 10, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
C: other help wanted This issue will probably not get done in a timely fashion without help from community contributors. P: major Priority: major. Between "default" and "critical" in severity. T: bug Type: bug report. A problem or defect resulting in unintended behavior in something that exists.
Projects
None yet
Development

No branches or pull requests

3 participants