Re: Not Much Linux Stuff of Late

Marc Haber <[email protected]> Sun, 02 Aug 2026 15:29:51 +0200
Newsgroups comp.os.linux.misc
Organization private site, see http://www.zugschlus.de/ for details
Message-ID <[email protected]>
Lawrence D´Oliveiro <[email protected]> wrote:
>On Sun, 02 Aug 2026 08:41:02 +0200, Marc Haber wrote:
>
>> Lawrence D´Oliveiro <[email protected]> wrote:
>>>
>>> I notice some systems now require the root password if you try to
>>> use the “single” boot option. If that doesn’t work, there’s always
>>> something like “init=/bin/bash” ...
>>
>> Unless you have secure boot on.
>
>Does the Linux kernel really enforce anything like that?

I might be mixing things (here: unlocking a LUKS container and secure
boot) up.

As far as I remember (I do not have practical experience with that)
you can use the TPM to unlock the LUKS container that contains the
root filesystem if the system passes some kind of attestation process
and the bootmanager is confident and can convince the TPM that you're
entitled to unlock the filesystem. Parts of that attestation are the
images of the kernel, the initramfs, and also the kernel command line
that is being booted. If one of those doesn't fit, the TPM doesn't
unlock the root filesystem and the boot fails until a person at the
console types in a backup decryption key that was hopefully created
during installation.

The way to the bootmanager is supervised by UEFI secure boot (UEFI
firmware verifies shim against the microsoft signatures that can be
verified by the UEFI firmware, shim knows which signed boot manager to
trust).

That way, init=/bin/bash will only work after manually unlocking the
root filesystem, and then it can be argued that this is a
significantly better protection of the data than a root password might
be.

Disclaimer: All typed from memory from knowledge onbtained by reading
web pages and listening to conferene talks. I might remember wrong.

>What about “systemd.break=” and “rd.systemd.break=”?
>
><https://www.freedesktop.org/software/systemd/man/latest/systemd-debug-generator.html>

Same.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402