MESSAGE
DATE | 2017-01-23 |
FROM | Ruben Safir
|
SUBJECT | Subject: [Hangout-NYLXS] Grub on libreboot
|
Check this out. It seems I can't get to the bios for a reason. If I'm understanding this correctly, grub is the software running the bios?
Installing Parabola or Arch GNU+Linux with full disk encryption (including /boot)
Libreboot on x86 uses the GRUB payload by default, which means that the GRUB configuration file (where your GRUB menu comes from) is stored directly alongside libreboot and it's GRUB payload executable, inside the flash chip. In context, this means that installing distributions and managing them is handled slightly differently compared to traditional BIOS systems.
On most systems, the /boot partition has to be left unencrypted while the others are encrypted. This is so that GRUB, and therefore the kernel, can be loaded and executed since the firmware can't open a LUKS volume. Not so with libreboot! Since GRUB is already included directly as a payload, even /boot can be encrypted. This protects /boot from tampering by someone with physical access to the system.
This guide is *only* for the GRUB payload. If you use the depthcharge payload, ignore this section entirely.
This guide is intended for the Parabola distribution, but it should also work (with some adaptation) for Arch. We recomend using Parabola, which is a version of Arch that removes all proprietary software, both in the default installation and in the package repositories. It usually lags behind Arch by only a day or two, so it is still usable for most people. See Arch to Parabola migration guide.
Note: on some thinkpads, a faulty DVD drive can cause the cryptomount -a step during boot to fail. If this happens to you, try removing the drive.
Back to previous index
https://libreboot.org/docs/gnulinux/encrypted_parabola.html
-- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com
DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com
Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013 _______________________________________________ hangout mailing list hangout-at-nylxs.com http://www.nylxs.com/
|
|