From ad901df99548bce32bc70a8794498a77981794c6 Mon Sep 17 00:00:00 2001 From: Peter Cai Date: Wed, 25 Jan 2023 20:47:35 -0500 Subject: NEWS: Add entry about support for multiple FIDO2 tokens --- NEWS | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/NEWS b/NEWS index 182645fbf4..98b07a2840 100644 --- a/NEWS +++ b/NEWS @@ -312,6 +312,12 @@ CHANGES WITH 253 in spe: * systemd-cryptenroll now supports unlocking via FIDO2 tokens (option --unlock-fido2-device=). + * systemd-cryptsetup now supports pre-flight requests for FIDO2 tokens + (except for tokens with user verification, UV) to identify tokens + before authentication. Multiple FIDO2 tokens can now be enrolled at + the same time, and systemd-cryptsetup will automatically select one + that corresponds to one of the available LUKS key slots. + * systemd-cryptsetup now supports new options tpm2-measure-pcr= and tpm2-measure-bank= in crypttab(5). These allow specifying the PCR bank and number into which the volume key should be measured. -- cgit v1.2.1