HACKER Q&A
📣 kosolam

Cryptsetup Luks Security


Luks dmcrypt is unlocked at boot from initrd image and kernel that are not encrypted which means that they are vulnerable to manipulation for anyone that has physical access to the server, is this correct? How to mitigate?


  👤 kosolam Accepted Answer ✓
Here, this sums it all. I wonder what is the state today, 3 years later?

https://0pointer.net/blog/authenticated-boot-and-disk-encryp...


👤 kosolam
Found: secureboot enabled will boot signed kernels