mastouille.fr est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Mastouille est une instance Mastodon durable, ouverte, et hébergée en France.

Administré par :

Statistiques du serveur :

632
comptes actifs

#systemrescue

0 message0 participant0 message aujourd’hui

Yesterday was one of the very few times I managed to lock myself out of my #Gentoo system.

This time I didn't understand the severity of a warning after a systemd update.

With an older #SailfishOS SDK I had to set systemd.unified_cgroup_hierarchy=false on the kernel command-line to get the build docker image working. The updated systemd no longer supports this, and refused to launch...

Good that I have a #SystemRescue CD for such situations... IT took less than 15 minutes to fix it.

A répondu dans un fil de discussion

@Gentoo_eV Given that I get a KVM console in time, I will demonstrate my installation guide (gentoo.duxsco.de/) in English using a #Hetzner dedicated server.

  • What? Beyond Secure Boot – Measured Boot on Gentoo Linux?
  • When? Saturday, 2024-10-19 at 18:00 UTC (20:00 CEST)
  • Where? Video call via BigBlueButton: bbb.gentoo-ev.org/

The final setup will feature:

  • #SecureBoot: All EFI binaries and unified kernel images are signed.
  • #MeasuredBoot: #clevis and #tang will be used to check the system for manipulations via #TPM 2.0 PCRs and for remote LUKS unlock (you don't need tty).
  • Fully encrypted: Except for ESPs, all partitions are #LUKS encrypted.
  • #RAID: Except for ESPs, #btrfs and #mdadm based #RAID are used for all partitions.
  • Rescue System: A customised #SystemRescue (system-rescue.org/) supports SSH logins and provides a convenient chroot.sh script.
  • Hardened #Gentoo #Linux for a highly secure, high stability production environment.
  • If enough time is left at the end, #SELinux which provides Mandatory Access Control using type enforcement and role-based access control