adding recovery key
This commit is contained in:
parent
2b18b37145
commit
b4eee91f31
|
@ -15,16 +15,17 @@ in {
|
||||||
kernelModules = ["kvm-intel"];
|
kernelModules = ["kvm-intel"];
|
||||||
loader.systemd-boot.enable = true;
|
loader.systemd-boot.enable = true;
|
||||||
initrd = {
|
initrd = {
|
||||||
|
kernelModules = ["usb_storage"];
|
||||||
availableKernelModules = ["xhci_pci" "thunderbolt" "nvme" "usbhid" "tpm_tis"];
|
availableKernelModules = ["xhci_pci" "thunderbolt" "nvme" "usbhid" "tpm_tis"];
|
||||||
systemd = {
|
systemd.enableTpm2 = true;
|
||||||
enableTpm2 = true;
|
|
||||||
emergencyAccess = true;
|
|
||||||
};
|
|
||||||
luks.devices = {
|
luks.devices = {
|
||||||
luksroot = {
|
luksroot = {
|
||||||
device = "${nvme}-part3";
|
device = "${nvme}-part3";
|
||||||
allowDiscards = true;
|
allowDiscards = true;
|
||||||
crypttabExtraOpts = ["tpm2-device=auto"];
|
#crypttabExtraOpts = ["tpm2-device=auto"]; # WIP
|
||||||
|
keyFileOffset = 9728;
|
||||||
|
keyFileSize = 512;
|
||||||
|
keyFile = "/dev/sda";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
Loading…
Reference in New Issue