Laptop 13 Pro & Ubuntu hardware-backed full disk encryption (FDE)

Which Linux distro are you using? Ubuntu

Which release version? 26.04.1

Which kernel are you using? 7.0

Which BIOS version are you using? LFP30.03.02

Which Framework Laptop 13 model are you using? Laptop 13 Pro Intel Core 5 325

Has anyone had success enabling the Ubuntu hardware-backed full disk encryption (FDE) using the TPM on the 13 Pro Intel? If so, what combination of settings did you use to get it working?

I really want to use this, but am hitting a brick wall.

1 Like

I haven’t tried, but once someone solved your problem I might copy their solution :grinning_face: I upgraded several times initially from 22.04 so I’m still on an older FDE setup. Would be nice to get the new UKI-based solution working from 26.04.

What does this get you that regular disk encryption doesn’t solve? My worry is that if you use a novel way to store a key, and that way might fail because it is novel, then you’ve increased your risk level.

1 Like
  1. Boot tamper protection
  2. Stronger encryption key
  3. Convenience

I do not think using a TPM and FDE is “novel” by any means. If it were to fail, I utilize proper backups. So losing my actual disk contents is not a risk for me.

1 Like

Regular disk encryption leaves your /boot partition unencrypted so an attacker can modify initramfs. Since initramfs is not measured into TPM, secure boot detection is bypassed.

1 Like

Better solved with UKI Signed Capsules ; there is no grub/uboot/systemd-boot etc manager and you use signed TEE/TPM efi capsules which are kernel and initramfs combined.

Does this mean the encryption key is stored in the TPM and is auto unlocked when the system boots or is another password prompt presented where a password has to be typed in and then the TPM decryption key is used to decrypt the drive for booting?

I have heard of varying levels of disk encryption approaches, some are easy to understand the mechanics of and others are much more involved.

1 Like

I ran into this with my FW16 - it’s a limitation of the OS’s included packages not working with some of the BIOS / TPM settings:

I’m hoping that Ubuntu 26.10 fixes this, but I can’t be sure from the Beta release notes. When I am back at my desk next week and not on the road, I’ll try to pull an ISO of 26.10 Beta and see if it works.

1 Like