[Bug 2102048] [NEW] [FFE] TPMFDE passphrase / pin support

Dan Bungert 2102048 at bugs.launchpad.net
Tue Mar 11 18:45:54 UTC 2025


Public bug reported:

I would like to request a feature freeze exception for the feature
"TPMFDE passphrase / pin support" in Subiquity.

[ Rationale ]

Support requiring "additional key material" for TPMFDE - TPM +
passphrase for example.

[ Proposed changes ]

The guided storage API is extended to accept an optional pin field, and
pin or passphrase may be supplied when making the TPMFDE guided choice.
If so, this information is saved for the "setup-storage-encryption" step
and supplied to snapd at that time.

[ Regression Potential ]

The relevant changes post-FF are entirely on the TPMFDE code path, so
the non-TPMFDE regression potential is expected to be very low. I
believe existing TPMFDE test plans will address the rest.

** Affects: subiquity (Ubuntu)
     Importance: Undecided
     Assignee: Dan Bungert (dbungert)
         Status: Triaged

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to subiquity in Ubuntu.
https://bugs.launchpad.net/bugs/2102048

Title:
  [FFE] TPMFDE passphrase / pin support

Status in subiquity package in Ubuntu:
  Triaged

Bug description:
  I would like to request a feature freeze exception for the feature
  "TPMFDE passphrase / pin support" in Subiquity.

  [ Rationale ]

  Support requiring "additional key material" for TPMFDE - TPM +
  passphrase for example.

  [ Proposed changes ]

  The guided storage API is extended to accept an optional pin field,
  and pin or passphrase may be supplied when making the TPMFDE guided
  choice.  If so, this information is saved for the "setup-storage-
  encryption" step and supplied to snapd at that time.

  [ Regression Potential ]

  The relevant changes post-FF are entirely on the TPMFDE code path, so
  the non-TPMFDE regression potential is expected to be very low. I
  believe existing TPMFDE test plans will address the rest.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/subiquity/+bug/2102048/+subscriptions




More information about the foundations-bugs mailing list