Random Number GodsRNG · Enemy Territory · Battlefield · D&D
Friday BF64 + Sunday D&D

Check the calendar. ET pubs running the new Frostbite rotation all week.

Accessing a TPM remotely

Permalink Preview Print PC
Breakerzote
Covert Ops
Members
51 posts 3 May 2018 joined
7 Sep 2026 at 13:18 #1

So I messed up and when leaving my home, I brought with myself my desktop SSD to use with my laptop. When doing so, however, I completely forgot I had encrypted the disk with luks, as I was used to it auto unlocking with the TPM. Now I'm struggling to find the password I used to encrypt it back when I installed the OS.

Is there any way I can perhaps use the TPM on the desktop remotely to unlock the SSD that is currently in the laptop and then add a new keyslot? The TPM software I'm using is clevis if that helps.

I'm not going to be able to get the SSD the desktop for a while, but I can reach it using whatever RDP software or SSH.

Also not sure if this is the right place to ask, if it's not I'd appreciate tips.

Breakerzote - NA nights
I take the dead hours.

smertnik1234
Covert Ops
Members
55 posts 2 Jun 2026 joined
7 Sep 2026 at 13:33 #2

can't you wipe/re-initialize it if it's not a SED drive?

smertnik1234 - EU evenings
CET after work.

glc8456
Engineer
Members
37 posts 11 Apr 2020 joined
7 Sep 2026 at 13:37 #3

If it's bound to the desktop’s TPM, remote unlock won’t work — the TPM is tied to that specific motherboard, and the SSD is

glc8456 - Map votes
Frostbite supremacy.

Breakerzote
Covert Ops
Members
51 posts 3 May 2018 joined
7 Sep 2026 at 14:02 #4

Yes, but my data is on there, that's the issue 😕

Breakerzote - NA nights
I take the dead hours.

Breakerzote
Covert Ops
Members
51 posts 3 May 2018 joined
7 Sep 2026 at 14:03 #5

Yeah, I know, I was wondering if there was some way I could play with the header perhaps as technically I have access to the tpm, just not physical one

Breakerzote - NA nights
I take the dead hours.

smertnik1234
Covert Ops
Members
55 posts 2 Jun 2026 joined
7 Sep 2026 at 14:17 #6

ah I see...looks like you're SOL then

smertnik1234 - EU evenings
CET after work.

6texture2pack
Covert Ops
Members
69 posts 7 Dec 2020 joined
7 Sep 2026 at 15:06 #7

Restore from backup

6texture2pack - Map votes
Frostbite supremacy.

fgdxhdgxcvx
Engineer
Members
46 posts 14 Aug 2023 joined
7 Sep 2026 at 16:33 #8

Its not posible.

fgdxhdgxcvx - Old guard
Jaymod days. Still here.

smailasltu
Field Medic
Members
32 posts 22 May 2019 joined
7 Sep 2026 at 16:50 #9

It's possible to run a command to unseal the keys if the TPM PCR values did not change.

But it may have changed after you removed the drive. Worth a try though.

smailasltu - D&D nights
Nat 1s are character development.

Breakerzote
Covert Ops
Members
51 posts 3 May 2018 joined
7 Sep 2026 at 16:59 #10

Hmm, the desktop had 2 NVMe drives, what I did was taking the main one out and placing the secondary one in the main slot, so I'm afraid this might have changed it. If you know how to I'd still try though.

Breakerzote - NA nights
I take the dead hours.

smailasltu
Field Medic
Members
32 posts 22 May 2019 joined
7 Sep 2026 at 17:29 #11

It's not something Ive done before so I can't give precise instructions. It involves tpm2_unseal and some other tpm2 commands.

If you took out the boot drive and booted some other OS on the desktop there's no point in trying, that guarantees the PCR values changed.

Whether this can work or not depends on which PCR values were used in the first place by your distro. Some PCR values check for hardware changes, some for different bootloaders and kernels.

smailasltu - D&D nights
Nat 1s are character development.

Sign in to reply.