Re: Authenticated Boot and Disk Encryption

2021-10-21 Thread Ludovic Courtès
Hi Reza,

Reza Housseini  skribis:

> I came across this blog post
> <https://0pointer.net/blog/authenticated-boot-and-disk-encryption-on-linux.html>
> and was wondering what is the state of authenticated boot and encryption in
> Guix System?

Nothing’s been done wrt. to “authenticated boot” AFAIK (I have
reservations about the concept).

Full disk encryption works but it’s done like in other distros, as
described in the article.  One big failure IMO is the fact that
nothing’s done upon suspend (when closing the laptop lid).  I believe
systemd-homed addresses that properly.

There’s a lot in this article, I’d suggest identifying specific bits to
see whether/how we can implement them in Guix!

Thanks,
Ludo’.



Authenticated Boot and Disk Encryption

2021-10-05 Thread Reza Housseini
Hello Guix!

I came across this blog post
<https://0pointer.net/blog/authenticated-boot-and-disk-encryption-on-linux.html>
and was wondering what is the state of authenticated boot and encryption in
Guix System?
I have this vision where you define such things in your system guile script
and everything gets configured appropriately, or at least the default setup
is as secure as possible.

Thanks for any insights.

Cheers, Reza