<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dual-Boot on Andrea Cervesato</title><link>https://cervesato.it/tags/dual-boot/</link><description>Recent content in Dual-Boot on Andrea Cervesato</description><generator>Hugo</generator><language>en</language><copyright>Andrea Cervesato</copyright><lastBuildDate>Wed, 22 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cervesato.it/tags/dual-boot/index.xml" rel="self" type="application/rss+xml"/><item><title>TPM Auto-Unlock With Dual Boot: Making LUKS Stop Asking For My Password</title><link>https://cervesato.it/posts/tpm-reenroll-dual-boot-luks/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://cervesato.it/posts/tpm-reenroll-dual-boot-luks/</guid><description>&lt;p&gt;When I first set up TPM auto-unlock, my LUKS-encrypted disk seemed to forget I existed after every reboot. Windows gaming session? Password. Plugged in the eGPU? Password. Kernel update? Password. I&amp;rsquo;d re-enroll the TPM, it would work for a day or two, then break again.&lt;/p&gt;
&lt;p&gt;This is the same Framework 13 + &lt;a href="https://cervesato.it/posts/egpu-thunderbolt-nvidia-bar-fix/"&gt;RTX 3070 eGPU&lt;/a&gt; that already needed its own pile of workarounds just to show a picture on a monitor. Of course it also breaks TPM measurements.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;The password is 20 characters. Typing it takes about four seconds. I could have just kept typing it. Instead I spent a weekend setting up Secure Boot with custom keys, writing a systemd service, and packaging the whole thing for AUR. Because of course I did.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p align="center"&gt;&lt;a href="https://xkcd.com/1205/"&gt;&lt;img src="https://imgs.xkcd.com/comics/is_it_worth_the_time.png" alt="xkcd 1205: Is It Worth the Time?" style="max-width: 500px;"&gt;&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>