OEM lock for desktop

That second link is quite old.

There’s a systemd component called systemd-cryptenroll that can do this mentioned here: Guide to using LUKS with TPM? - #3 by dngray

There isn’t a lot of benefit, and I’d honestly wait until systemd-measure and ukify are mainstream in your distribution.

We have some discussion about Wayland mentioned here. COSMIC will support Wayland whereas their current setup doesn’t use this by default.

2 Likes