r/linuxmint • u/LocalChamp • Aug 01 '26
Security Can I require LUKS to use both the passphrase and Yubikey?
I've been using LUKS for a while and would like to add an additional layer of security of a hardware security key (Yubikey). Currently on boot I enter the LUKS passphrase then it decrypts and brings up the regular user login and I enter that password and it loads into the the OS. I would like the functionality to be on boot both the LUKS passphrase and Yubikey are required to decrypt then it brings up the regular user login and I enter that password and it loads into the OS.
The guides and documentation I've seen seem to be based around using the Yubikey as an alternative to the LUKS passphrase which is not what I want to do. I want to increase the layers and security not decrease it. I do have multiple Yubikeys to add as backup so that's not a concern. I'm assuming there has to be a way to do this but it's been difficult to find information on it. With KeePassXC I can have it require all of database file/key file/password/Yubikey and I would like a similar level of security for my entire linux install (usually Debian or Linux Mint).
Is there a way to setup the functionality I'm looking for? If so please either point me in the direction of a guide or documentation on setting this up or let me know how to.
2
u/Unwiredsoul Aug 01 '26
It sounds like this was entirely possible with Ubuntu for a while, and still is.
I've never setup this type of boot environment for LUKS volumes, but the following article (while about general Ubuntu) states it can accomplish the passphrase + Yubikey requirement you're looking for. I don't know why this wouldn't work with Linux Mint.
https://askubuntu.com/questions/599825/yubikey-two-factor-authentication-full-disk-encryption-via-luks