I’ve added my Librem Key as a way to unlock my LUKS-encrypted hard drive during boot. It works great. I’m looking through the smartcard-key-luks.sh script to see what it would take to update the hard drive decryption process if I needed to update the GPG key on my Librem Key.
Assuming I’m reading things correctly, it LOOKS like I should be able to just manually remove the LUKS key manually and then re-run smartcard-key-luks with the new key. Does that sound right to everyone? If so, I may give it a try this afternoon, as I’ve got a current backup of everything if I have to do a wipe/reinstall.