Any insight when, if ever, will Poettering's Authenticated Boot and Disk Encryption -vision be nicely supported on Arch Linux?

This page summarizes the projects mentioned and recommended in the original post on /r/archlinux

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • cryptsetup

  • No need to say sorry. cryptsetup --integrity sets up dm-crypt on top of dm-integrity. But the modern cryptographic advice, in general, is to avoid such layered setups, because they are unnecessarily slow: AEAD is a primitive that provides both authentication and encryption in one layer, and is faster than doing the two parts separately. Unfortunately, this is not yet implemented in a good way for disk encryption.

  • systemd

    The systemd System and Service Manager

  • I'd love to have physical laptop security like Lennart described in his blog some day. I feel like for this setup to be viable for lazy users like me, there needs to be more integrated support (such as this systemd-boot issue) and a new detailed installation guide that establishes a full chain of trust from boot and sets up systemd-homed without having to figure out too much on your own. With automatic signing for system updates, too, of course. Anyone else in a similar situation? I don't wanna come across as demanding, I know it's a community effort OS, but I feel like I wanna learn more about these issues to know how and when to try installing Secure Boot and encryption again.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • sbctl

    :computer: :lock: :key: Secure Boot key manager

  • Things like the sd-boot issue is misunderstood in my eyes. It works for container use cases (like mkosi) and shouldn't be used for personal desktops in my opinion. Obviously biased as the author of sbctl.

  • toolbox-images

    deprecated

  • The main issues I think is that many of these ideas are only really compatible with an immutable OS like Fedora Silverblue and ostree-like systems. It works better where you can cut releases and say "this is the base system" while a rolling release distribution is a moving target where you will be struggling with idiosyncrasies. The mutable part would be /home on a separate partition and any tool usage would be confined into toolbox like containers.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Netdata: query, explore and visualize SystemD Journals!

    2 projects | /r/linux | 5 Oct 2023
  • [Kinoite/Silverblue]Decrypt LUKS volumes with a TPM on Fedora 35+

    2 projects | /r/Fedora | 12 May 2023
  • Systemd Rolling Out "run0" As sudo Alternative

    2 projects | news.ycombinator.com | 30 Apr 2024
  • Run0 – systemd based alternative to sudo announced

    5 projects | news.ycombinator.com | 1 May 2024
  • Crash-only software: More than meets the eye

    1 project | news.ycombinator.com | 30 Apr 2024