Hi Alex, I'm using the SmartCard-HSM cards. They work as HSM/keystore with VeraCrypt for plain container volumes and is support by OpenSC. They were the most "open-source oriented cards I could find. I looked at DcsCfgCrypt.c but I don't know anything about UEFI and developing loaders for that environment. For example does EFI provide the usb drivers? I'll mention this open issue to the card manufacturer. thanks, Wes
Hi Mounir, thank you for all your work and explaining this. Unfortunately I cannot pay you a bounty for this feature. There are almost no commercial products which you can simply buy online. I understand that most solutions are tailored for the enterprise, but very small teams might also be in need of such solutions (PBA with smartcards) without entering hefty contracts and minumum of 25 seats etc. Should you have a suggestion for such solution (I need 2 - 4 licences) I'm very interested. I thank...
Hi all, I've just bought some SmartCard-HSM cards. They can be initialized from within windows. Now veracrypt can use the smartcard, store a key and read a key, when using volumes AFTER windows has booted. But when I tried to convert to entire drive or system partition VeraCrypt failed by stating that keyfiles are not supported. Is that true, that smartcards aren't supported when using Veracrypt for boot volume encryption? Before purchasing the cards I read the documentation but this exception is...