> The thing is that you cannot do 2-factor authentication
> generically. You typically have password/passphrase as
> one factor, and that can be done generically and is implemented
> in cryptsetup. However the second factor is usually a token
> or biometrics and there is no way to do these generically.
> They always have to be customized to the concrete solution.
> While there are generic smarcard indterfaces, they are
> still problematic for this use.
ok, thanks for the info.
