Re: Not Much Linux Stuff of Late
Marc Haber <[email protected]> Sun, 02 Aug 2026 15:29:51 +0200
| Newsgroups | comp.os.linux.misc |
|---|---|
| Organization | private site, see http://www.zugschlus.de/ for details |
| Message-ID | <[email protected]> |
Lawrence D´Oliveiro <[email protected]> wrote: >On Sun, 02 Aug 2026 08:41:02 +0200, Marc Haber wrote: > >> Lawrence D´Oliveiro <[email protected]> wrote: >>> >>> I notice some systems now require the root password if you try to >>> use the “single” boot option. If that doesn’t work, there’s always >>> something like “init=/bin/bash” ... >> >> Unless you have secure boot on. > >Does the Linux kernel really enforce anything like that? I might be mixing things (here: unlocking a LUKS container and secure boot) up. As far as I remember (I do not have practical experience with that) you can use the TPM to unlock the LUKS container that contains the root filesystem if the system passes some kind of attestation process and the bootmanager is confident and can convince the TPM that you're entitled to unlock the filesystem. Parts of that attestation are the images of the kernel, the initramfs, and also the kernel command line that is being booted. If one of those doesn't fit, the TPM doesn't unlock the root filesystem and the boot fails until a person at the console types in a backup decryption key that was hopefully created during installation. The way to the bootmanager is supervised by UEFI secure boot (UEFI firmware verifies shim against the microsoft signatures that can be verified by the UEFI firmware, shim knows which signed boot manager to trust). That way, init=/bin/bash will only work after manually unlocking the root filesystem, and then it can be argued that this is a significantly better protection of the data than a root password might be. Disclaimer: All typed from memory from knowledge onbtained by reading web pages and listening to conferene talks. I might remember wrong. >What about “systemd.break=” and “rd.systemd.break=”? > ><https://www.freedesktop.org/software/systemd/man/latest/systemd-debug-generator.html> Same. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402