Re: [systemd-devel] fstab automount of a mdns samba share

2021-09-28 Thread Colin Guthrie
Julian Sikorski wrote on 28/09/2021 07:37: W dniu 27.09.2021 o 16:38, François Cami pisze: Hi, On Mon, Sep 27, 2021 at 4:05 PM Julian Sikorski wrote: Hi list, I am trying to set up an automount of my samba share. It works when I go by the IP address, i.e. //192.168.0.220/julian /mnt/openm

Re: [systemd-devel] troubleshooting Clevis

2021-09-28 Thread Lennart Poettering
On Di, 28.09.21 12:26, lejeczek (pelj...@yahoo.co.uk) wrote: > Hi guys. > > I have 'clevis' set to get luks pin from 'tang' but unlock does not happen > at/during boot time and I wonder if someone can share thoughts on how to > investigate that? > I cannot see anything obvious fail during boot, mo

Re: [systemd-devel] Prefix for direct logging

2021-09-28 Thread Arjun D R
Hmm, changes to the service side (for prefix) would be a bit difficult at the moment. And moreover the journal is a bit luxurious where we get the timestamp, hostname, process name and it's PID. So I would like to have that luxury in the logs. I have a thought raised from your suggestion. Is it fi

Re: [systemd-devel] Prefix for direct logging

2021-09-28 Thread Lennart Poettering
On Mo, 27.09.21 15:40, Arjun D R (drarju...@gmail.com) wrote: > Hi Folks, > > Currently we are using systemd-journald for service logging. We run > journalctl for a bunch of services and redirect those to the custom log > files for every few seconds. This takes up the CPU for that particular > tim

[systemd-devel] troubleshooting Clevis

2021-09-28 Thread lejeczek
Hi guys. I have 'clevis' set to get luks pin from 'tang' but unlock does not happen at/during boot time and I wonder if someone can share thoughts on how to investigate that? I cannot see anything obvious fail during boot, moreover, manual 'clevis-luks-unlock' works no problems. many thanks,

Re: [systemd-devel] FDE: UEFI/Secureboot solves main part / missing link is /boot encryption

2021-09-28 Thread Lennart Poettering
On Di, 28.09.21 19:44, Leon Fauster (leonfaus...@googlemail.com) wrote: > Hallo Lennart, corresponding to your last post about FDE: > > On an EFI system - would an encrypted "/boot" or /boot on > an encrypted "/" filesystem eliminate the mentioned main > attack vector? The whole chain would be aut

[systemd-devel] FDE: UEFI/Secureboot solves main part / missing link is /boot encryption

2021-09-28 Thread Leon Fauster
Hallo Lennart, corresponding to your last post about FDE: On an EFI system - would an encrypted "/boot" or /boot on an encrypted "/" filesystem eliminate the mentioned main attack vector? The whole chain would be authenticated. firmware->shim->bootloader/grub2->{manual interaction/password}->LU

Re: [systemd-devel] Prefix for direct logging

2021-09-28 Thread Arjun D R
Hi Lennart, That's a good idea but still I would like to have the prefix as it is in the journal . I understand it is impossible to bypass the journal and expect the direct logging to be the same as journal entries. We can achieve it through socket but still we cannot have the luxurious prefix as