Results 1 to 10 of 169

Thread: Manual Full System Encryption has been updated and simplified

Threaded View

  1. #11
    Join Date
    May 2008
    Location
    United Kingdom
    Beans
    5,263
    Distro
    Ubuntu

    Re: Manual Full System Encryption has been updated and simplified

    Quote Originally Posted by j.folwer View Post
    I apologize, I stand corrected…
    No problem. Thanks to your previous comments, I discovered that VirtualBox allows me to create a NVMe controller, which let me see how it worked. So it was all good — I learned something (always good to do); and I made the script both more robust and more flexible.

    Quote Originally Posted by j.folwer View Post
    … which could enable us to have the boot unencrypted but still signed and checked…
    That's not necessary, because the full-system encryption includes /boot within LVM, which is in turn within LUKS. It all works. The important point is the next one that you make:

    Quote Originally Posted by j.folwer View Post
    I was really hoping not to have to read shim's and grub's source code and hoping to understand how to debug the key validation, and why GRUB_CRYPTED_DISK=y loads cryptomount module only with secureboot disabled. No eta on that tough.
    That's the big one. We need to have proper signing on the EFI System Partition, because that's the only vector for malware on a locked machine. Unfortunately, it is way beyond my level of competence to even comment on how.

    I refer you to the bug's comment #25 by Jonathan Polom, who explains a bit more about the signing flaw. I'd love to raise a bug report for this shortcoming, but I have insufficient knowledge to even begin to frame the report.
    Last edited by Paddy Landau; August 25th, 2018 at 11:04 AM. Reason: SImplify wording
    Always make regular backups of your data (and test them).
    Visit Full Circle Magazine for beginners and seasoned Linux enthusiasts.

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •