Skip to main content
Version: 2.11

tpm

Requires Restart

Seal the filestore encryption key in the machine's TPM, so it cannot be read off disk.

Properties

NameDescriptionTypeDefaultReloadable
keys_fileFile the TPM-sealed key is stored in.string-No
encryption_passwordPassword protecting the sealed key.string-No
srk_passwordPassword for the TPM storage root key.string-No
pcrPlatform Configuration Register the key is sealed against, so it only unseals on an unchanged boot state.integer-No
cipherCipher used for the filestore once the key is unsealed.string-No