SYSTEMD-CRYPTSETUP(8) systemd-cryptsetup SYSTEMD-CRYPTSETUP(8) systemd-cryptsetup systemd-cryptsetup@.service - systemd-cryptsetup [...] attach - - [-] [-crypttab] systemd-cryptsetup [...] detach - systemd-cryptsetup@.service system-systemd\x2dcryptsetup.slice systemd-cryptsetup ( attach) ( detach) . systemd-cryptsetup@.service . VOLUME SOURCE-DEVICE KEY-FILE CRYPTTAB-OPTIONS crypttab(5). systemd-cryptsetup@.service . . systemd-cryptsetup@.service systemd\x2dcryptsetup.slice . . systemd-cryptsetup@.service [1] . /etc/crypttab systemd-cryptsetup@.service systemd-cryptsetup-generator(8). . systemd-cryptsetup@.service : 1. ( /etc/crypttab) . PKCS#11 FIDO2 TPM2 ( pkcs11-uri= fido2-device= tpm2-device=) . 2. /etc/cryptsetup-keys.d/volume.key /run/cryptsetup-keys.d/volume.key . / PKCS#11/FIDO2/TPM2 . 3. try-empty-password . 4. password-cache= "yes" "read-only" . 5. headless. . systemd-cryptsetup ImportCredential=/LoadCredential=/SetCredential= ( systemd.exec(5) ). "systemd-crypsetup@root.service" ( systemd-gpt-auto-generator) : cryptsetup.passphrase LUKS. 256. cryptsetup.tpm2-pin TPM. 256. cryptsetup.fido2-pin FIDO2. 256. cryptsetup.pkcs11-pin PKCS11. 256. cryptsetup.luks2-pin LUKS2 . 256. systemd(1) systemd-cryptsetup-generator(8) crypttab(5) systemd-cryptenroll(1) cryptsetup(8) TPM2 PCR systemd[2] 1. https://systemd.io/PASSWORD_AGENTS/ 2. TPM2 PCR systemd https://systemd.io/TPM2_PCR_MEASUREMENTS 3 . . : . systemd 260.1 SYSTEMD-CRYPTSETUP(8)