3 ms·
Thanks to Secure Boot (AFAIK), you can't implement hibernation until you implement hibernation file signing. Sleep works fine for ages. Works better on Linux o
by pedro2 6y ago
Thanks to Secure Boot (AFAIK), you can't implement hibernation until you implement hibernation file signing.
Sleep works fine for ages. Works better on Linux on my 2015 laptop than on Windows (hint: if you have a KIRA laptop, suspend stops borking after you update the drivers for the touchpad to a ~2019 version).
- dathinab 6y agoYou can, by having LVM on top of a LUKS or a swap file on a LUKS partition. E.g. for a relative secure setup you can: - use a custom platform key - use EFIStub boot and bundle you kernel initramfs, flash screen image, kernel options, etc. into a single efi bootable blob - sign that blob with your custom platform key (or enroll it's hash if you don't use a custom platform key). - copy your secure boot signed early boot environment into the efi partition. - have everything else in encrypted partitions including /boot (which your are not using) - easiest way to have this is make a EFI partition and a single large encrypted partition and then use LVM (logic volume manager 2) on it to split it into swap, root, /home etc. Added benefit is you can easily resize them. - now you just need to setup a way to decrypt on boot, e.g. by having a boot password, secure key or similar. You will need to provide it even if you boot from hibernation. (or you use the platforms TPM!) Naturally you can also just ignore how hibernation breaks secure boot and set it up anyway. Your computer doesn't know you are braking the secure boot spec. But a company (like Ubuntu) might have committed to not brake the spec.
- dfox 6y agouswsusp can both sign and/or RSA encrypt the image essentially from the beginning of its existence. On the other hand you in fact do not need that and can simply store the hibernation image on otherwise encrypted device (either as LV on encrypted LVM or as a file somewhere).