# How secure is TPM unlocking?

**URL:** <https://universal-blue.discourse.group/t/how-secure-is-tpm-unlocking/11105>\
**Category:** General\
**Created:** [November 18, 2025, 9:01am UTC](https://universal-blue.discourse.group/t/how-secure-is-tpm-unlocking/11105 "2025-11-18T09:01:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fred\_Kite](https://yyz2.discourse-cdn.com/free1/user_avatar/universal-blue.discourse.group/fred_kite/32/8588_2.png) [@Fred\_Kite](https://universal-blue.discourse.group/u/Fred_Kite)\
**Post date:** [November 18, 2025, 9:01am UTC](https://universal-blue.discourse.group/t/how-secure-is-tpm-unlocking/11105/1 "2025-11-18T09:01:40Z")

</div>

Hi everyone!

How secure is TPM unlocking in aurora/bluefin? I’ve recently rebased from Kinoite and TPM unlocking is not secure yet: a simple edit in grub command at boot can open a root console. See [this conversation in discussion.fedoraproject.org](https://discussion.fedoraproject.org/t/silverblue-tpm-luks-and-higher-pcrs/160617).

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![inffy](https://yyz2.discourse-cdn.com/free1/user_avatar/universal-blue.discourse.group/inffy/32/7996_2.png) [@inffy](https://universal-blue.discourse.group/u/inffy)\
**Post date:** [November 18, 2025, 12:17pm UTC](https://universal-blue.discourse.group/t/how-secure-is-tpm-unlocking/11105/2 "2025-11-18T12:17:18Z")

</div>

Here is the script we use

> <https://github.com/ublue-os/packages/blob/b9810df1504fdfdf9d78c15779e4399d6cc41ae4/packages/ublue-os-luks/src/luks-enable-tpm2-autounlock>

Haven’t personally used and don’t really know how secure or not it is.

---

<div class="post-metadata">

**Author:** ![nvonwolff](https://yyz2.discourse-cdn.com/free1/user_avatar/universal-blue.discourse.group/nvonwolff/32/4709_2.png) [@nvonwolff](https://universal-blue.discourse.group/u/nvonwolff)\
**Post date:** [November 20, 2025, 1:36am UTC](https://universal-blue.discourse.group/t/how-secure-is-tpm-unlocking/11105/3 "2025-11-20T01:36:27Z")

</div>

Unless you’re self signing your grub files for secure boot, it’s not secure at all. As someone can pull your drive, modify your grub files to bypass user passwords, then reinsert and boot. There are tools out there to do this self-signing but I haven’t seen a way to automate it to happen in ublue on updates as you would need to resign everytime rpm-ostree/bootc does an update.

Your better option is to decrypt with a password and setup your user account in Gnome to auto login. As Long as your luks password is the same as your user password your Gnome keyring will also auto-unlock.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/free1/uploads/univeral_blue/original/2X/e/e39f7d1952979cf23b0f8d634e025fb38da50026.png) [@system](https://universal-blue.discourse.group/u/system)\
**Post date:** [November 23, 2025, 1:36am UTC](https://universal-blue.discourse.group/t/how-secure-is-tpm-unlocking/11105/4 "2025-11-23T01:36:38Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
