Clevis can not decrypt the LUKS device on system boot on Red Hat Enterprise Linux 8

Solution Unverified - Updated -

Issue

  • I configured the Tang server and make a key for decrypting the LUKS device with Clevis in the kickstart file.
  • The expectation was that the system could boot up without LUKS passphrase input, but the input was required.
  • The following error was output in the journal log.
clevis-luks-askpass[xxx]: Error communicating with the server <tang-server-ip>

Environment

Red Hat Enterprise Linux 8

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content