!oNSIfazDqEcwhcOjSL:matrix.org

disko

345 Members
disko - declarative disk partitioning - https://github.com/nix-community/disko87 Servers

Load older messages


SenderMessageTime
29 Apr 2025
@lassulus:lassul.uslassulusDies grub support btrfs for finding the kernel?02:01:53
@realhotgirlshit:envs.net@realhotgirlshit:envs.net I didn’t know that, but I think that’s what I want 02:07:04
@realhotgirlshit:envs.net@realhotgirlshit:envs.net If not, I will not encrypt /boot 02:07:54
@lassulus:lassul.uslassulusIt could be that grub only supports luks1 but we do luks2 nowadays02:15:40
@lassulus:lassul.uslassulusI used the grub unlockaing years ago. But it was pretty slow and frustrating :D02:16:12
@lassulus:lassul.uslassulusMaybe this is better if you boot the machine via efi instead of legacy. But not sure02:16:35
@realhotgirlshit:envs.net@realhotgirlshit:envs.net Yeah, my machine doesn’t support legacy 03:58:56
@realhotgirlshit:envs.net@realhotgirlshit:envs.netI’m looking up tutorials and see if they have anything useful03:59:07
@realhotgirlshit:envs.net@realhotgirlshit:envs.netI want to encrypt boot if possible03:59:16
@lassulus:lassul.uslassulusMaybe here is some context about luks2 support in grub: https://savannah.gnu.org/bugs/?5509304:49:38
@lassulus:lassul.uslassulusI haven't read it yet. So maybe you can check there04:50:21
@realhotgirlshit:envs.net@realhotgirlshit:envs.netOkay, so GRUB LUKS2 support is not great05:03:51
@realhotgirlshit:envs.net@realhotgirlshit:envs.netSo no encrypted /boot05:04:22
@realhotgirlshit:envs.net@realhotgirlshit:envs.netThat’s the only ramification, anything about FDE in general?05:04:58
@lassulus:lassul.uslassulusNo I usually do LUKS fde on all my computers05:07:42
@realhotgirlshit:envs.net@realhotgirlshit:envs.netWith GRUB?05:09:58
@lassulus:lassul.uslassulusThat doesnt matter usually. Since the kernel does the decryption in the initrd05:10:45
@lassulus:lassul.uslassulusI use grub or systemd-boot on different systems05:11:13
@realhotgirlshit:envs.net@realhotgirlshit:envs.netperfect 😁05:11:36
@realhotgirlshit:envs.net@realhotgirlshit:envs.netI’ll remove the cryptodisk stuff05:11:46
@lassulus:lassul.uslassulusYou have to add a /boot partition outside the luks also05:12:12
@realhotgirlshit:envs.net@realhotgirlshit:envs.nethmm :/05:12:31
@realhotgirlshit:envs.net@realhotgirlshit:envs.netI’ll go over the example configs05:13:10
@realhotgirlshit:envs.net@realhotgirlshit:envs.net yes, that is my disko config 05:15:27
@realhotgirlshit:envs.net@realhotgirlshit:envs.net* yes, that is in my disko config :D05:15:54
@lassulus:lassul.uslassulusAh the 1m partition in your config is not the /boot partition. It's an emulation of the MBR for a GPT partition. So you can do legacy boot ir your bios doesn't support efi boot05:17:20
@lassulus:lassul.uslassulus * 05:17:36
@realhotgirlshit:envs.net@realhotgirlshit:envs.netRight, okay yeah I remember that’s how legacy works05:17:58
@realhotgirlshit:envs.net@realhotgirlshit:envs.net Okay, it complains about CRYPTODISK not being enabled and /dev/sda not found 05:42:43
1 May 2025
@rosariopulella:matrix.orgRosuavio changed their display name from Rosario Pulella to Rosuavio.20:07:59

Show newer messages


Back to Room ListRoom Version: 10