4 ms·
Reboot into single user mode, reset root password, and done.
by tokenizerrr 9y ago
Reboot into single user mode, reset root password, and done.
- ilikepi 9y agoThe issue is the new admin has no way to know whether all the processes running before the reboot are configured to come up automatically, and no sense of what external dependencies the server has. Further, the admin is forced to deal with problems reactively at boot time, rather than having the opportunity to gain an understanding of the server setup in advance.
- arca_vorago 9y agoNot if grub is encrypted, better even behind FDE.
- justaj 9y agoHow does booting for remote login in such a setup work though? You'd have to be physically present in order to enter the passphrase.
- arca_vorago 9y agoFor that I do an ssh shim at initram (with portknocking) for key entry preboot
- amdavidson 9y agoI would love to read a tutorial on that if you know of one.
- rthille 9y agohttps://hamy.io/post/0005/remote-unlocking-of-luks-encrypted-root-in-ubuntu-debian/ https://hamy.io/post/0005/remote-unlocking-of-luks-encrypted...