How to decrypt luks encrypted filesystem with FIDO2 on boot

Ubuntu 26.04 LTS guide on how to decrypt luks encrypted filesystem with FIDO2 on boot

To decrypt a LUKS-encrypted drive on boot using a FIDO2 security key, you leverage native systemd-cryptenroll tools. This embeds the FIDO2 token metadata directly into the LUKS header. Your drive must use the LUKS2 format (standard on modern Ubuntu/Debian installs).

Do Not Delete Your Passphrase. This setup adds your FIDO2 key as an additional slot. Always keep your traditional password as a safe recovery fallback.

1. Identify Your Encrypted Partition

Look up the device path of your encrypted drive:

lsblk

Look for the partition labeled crypto_LUKS or type crypt. For this guide, we will assume it is /dev/nvme0n1p3 (replace this with your actual partition path).

2: Enroll the FIDO2 Key Into LUKS

Insert your FIDO2 key and run systemd cryptenrollment utility

sudo systemd-cryptenroll --fido2-device=auto /dev/nvme0n1p3

The system will prompt you for your existing LUKS disk passphrase. Then, it will prompt you for your FIDO2 key's PIN, and finally, your security key will begin flashing. Touch the key to complete the enrollment. If you want to force PIN requirement every single time, you can append --fido2-with-client-pin=true to the command.

3. Tell Initramfs to Look for the Key

Update your crypttab configuration file so the system knows to look for a FIDO2 token instead of a regular password prompt at boot.

sudo nano /etc/crypttab

Find the line corresponding to your encrypted root drive. It usually looks like this:

dm_crypt-0 UUID=12345678-abcd-1234-abcd-1234567890ef none luks

Add fido2-device=auto to the options field as shown below"

dm_crypt-0 UUID=12345678-abcd-1234-abcd-1234567890ef none luks,fido2-device=auto

4. Rebuild Initramfs

sudo update-initramfs -u -k all

If you have dracut, installed instead of initramfs-tools you should use sudo dracut -f and ensure add_dracutmodules+=" fido2 " is added to your dracut configuration.

Sources