| 
	     You are here  | 
        blog.bofh.it | ||
| | | | | 
            
              www.berrange.com
             | 
        |
| | | | | ||
| | | | | 
            
              www.tecmint.com
             | 
        |
| | | | | In this guide, we will highlight the various steps taken by the Linux OS from the time it is powered on to the time you log in. | |
| | | | | 
            
              blog.jak-linux.org
             | 
        |
| | | | | Today, I wrote sicherboot, a tool to integrate systemd-boot into a Linux distribution in an entirely new way: With secure boot support. To be precise: The use case here is to only run trusted code which then unmounts an otherwise fully encrypted disk, as in my setup: If you want, sicherboot automatically creates db, KEK, and PK keys, and puts the public keys on your EFI System Partition (ESP) together with the KeyTool tool, so you can enroll the keys in UEFI. You can of course also use other keys, you just need to drop a db.crt and a db.key file into /etc/sicherboot/keys. It would be nice if sicherboot could enroll the keys directly in Linux, but there seems to be a bug in efitools preventing that at the moment. For some background: The Platform Key (PK) signs the Key Exchange Key (KEK) which signs the database key (db). The db key is the one signing binaries. | |
| | | | | 
            
              blog.stijn-dhaese.be
             | 
        |
| | | A couple of days ago I received my Fairphone 4, but unfortunately for the moment, there aren't any alternative operating systems available that provides you root access. Fortunately, the comm... | ||