Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

tapdattl

@tapdattl@lemmy.world
lemmy 0.19.19-9-gc55dd700c
  • Open on lemmy.world

Codeberg

0 Followers
0 Following
2 Posts
Joined July 12, 2023
Open post
tapdattl @tapdattl@lemmy.world
· 21h ago
Hibernation with encrypted root and swap using TPM and secure boot on Fedora 44 I’ve been trying to set up hibernation on my laptop while also maintaining an encrypted root partition and swap using secure boot and my laptop’s TPM. I’ve documented the steps I’ve followed below, but I still am unable to enable hibernation. I was under the impression that the only reason you can’t normally have both an encrypted harddrive and hibernation was because swap had to be encrypted as well, but if both the root partition and the swap are encrypted, I’m using UEFI secure boot, and they are automatically decrypted at boot using the TPM, shouldn’t that relieve those security concerns? After completing the below, entering systemctl hibernate errors saying hibernation is not set up for the system. Am I missing something or is it just not possible? I can confirm not needing to enter passwords for my swap or root FS due to the TPM unlock. Drop into root shell sudo su - Setup LUKS encryption with automatic unlock with TPM Install necessary components, regenerate initramfs and reboot dnf install -y clevis clevis-luks clevis-dracut clevis-udisks2 clevis-systemd dracut -fv --regenerate-all && systemctl reboot Identify swap and root partition devices, names, and luks UUIDs… lsblk -f cryptsetup luksUUID In my case, my home partition is on /dev/nvme0n1p4 and my swap is /dev/nvme0n1p3 # the encrypted home partition clevis luks bind -d /dev/nvme0n1p4 tpm2 '{"pcr_ids":"1,4,5,7"}' # the encrypted swap clevis luks bind -d /dev/nvme0n1p3 tpm2 '{"pcr_ids":"1,4,5,7"}' Set a timeout before the system asks for a password, to allow time for the TPM to load and enter the password for you systemctl edit systemd-ask-password-plymouth.service Add the below then ctrl+o ctrl+x to save and exit [Service] ExecStartPre=/bin/sleep 10 Create a dracut configuration file to install the systemd-ask-password-plymouth service: vi /etc/dracut.conf.d/systemd-ask-password-plymouth.conf Add the below, ensure there are spaces inside the quotation marks on either side of the filename install_items+=" /etc/systemd/system/systemd-ask-password-plymouth.service.d/override.conf " Regenerate initramfs and reboot dracut -fv ‐‐regenerate-all && systemctl reboot Edit crypttab file (/etc/crypttab)to specify decryption of swap file at boot, duplicate the already present line for your root FS crypttab entry and change the UUIDs to reflect the swap file, use cryptsetup luksUUID /dev/nvme0n1p3 and cryptsetup luksUUID /dev/nvme0n1p4 to get the luks UUIDs for your root and swap partitions. UUID= none x-initrd.attach UUID= none x-initrd.attach Regenerate initramfs and reboot: dracut -fv --regenerate-all && systemct reboot Edit fstab to include swap, append the following to /etc/fstab: UUID= none swap defaults,x-systemd.device-timeout=0 1 1 Rebind your home and swap partitions. You will have to do this every time you update the kernel. # encrypted home partition clevis luks regen -d /dev/nvme0n1... -s 1 # encrypted swap clevis luks regen -d /dev/nvme0n1... -s 1
1
10
0
0
Open post
tapdattl @tapdattl@lemmy.world
· 20h ago
Replying to
You know I’m not 100% sure, I was following another tutorial that I can’t find anymore, but if I remember right 1 was for the UEFI state, 4 was to make sure the bootloader wasn’t changed, 5 was for secure boot, and 7 was for the OS being booted (To make sure someone isn’t booting Kali in a live disk or something), but I could be wrong.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:56:41 UTC