Skip to content

crypt.go: add function to verify key for specific keyslot - #574

Merged
frederic-hoerni merged 2 commits into
canonical:masterfrom
valentindavid:valentindavid/verify-key-on-keyslot
Sep 25, 2026
Merged

frederic-hoerni merged 2 commits into
canonical:masterfrom
valentindavid:valentindavid/verify-key-on-keyslot

Conversation

@valentindavid

Copy link
Copy Markdown
Member

In order to be able to prevent removing keyslots for which we have the only key for the containers, we need to be able to check specific keyslots.

We typically only know the key that got registered in keyring during boot. And they come from sealed key that we usually cannot unseal again later. If we remove any of those keyslots because an unexpected keyslot was used for activation, then we lose ability to act on the container, until we reboot and a different keyslot gets used.

Unexpected keyslot might used if we for example lose power or hard reset in the middle of reprovision.

In order to be able to prevent removing keyslots for which we have the
only key for the containers, we need to be able to check specific
keyslots.

We typically only know the key that got registered in keyring during
boot. And they come from sealed key that we usually cannot unseal
again later. If we remove any of those keyslots because an unexpected
keyslot was used for activation, then we lose ability to act on the
container, until we reboot and a different keyslot gets used.

Unexpected keyslot might used if we for example lose power or hard
reset in the middle of reprovision.
Comment thread crypt_test.go Outdated
Comment thread internal/luks2/cryptsetup.go Outdated
Comment thread crypt.go Outdated

@pedronis pedronis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@frederic-hoerni
frederic-hoerni merged commit 4924adc into canonical:master Sep 25, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants