Big #security improvement for #openSUSE #FDE; pcr-oracle is being replaced by #systemd-pcrlock, which stores policy in #TPM2 non-volatile RAM and protects against rollback attacks. Time to migrate! 🔐 #Linux https://news.opensuse.org/2026/03/11/dropping-pcr-oracle/
Dropping pcr-oracle in user space Full Disk Encryption

Introduction In user space Full Disk Encryption (FDE), as opposed to the boot loader based FDE, developers for openSUSE supported signed policy and NVIndex p...

openSUSE News