Replies: 3 comments 5 replies
|
Planned. But this is very hard... Since currently the Ubuntu's grub doesn't provide Argon2ID plugin. |
|
I agree that filesystem encryption would be a great addition to the new
installer. I understand that the lack of Argon2id support in Ubuntu’s GRUB
makes this technically difficult, but hopefully there will be a practical
solution that can provide secure LUKS2-based system encryption without
requiring GRUB to directly handle Argon2id.
It would be especially useful if the installer could eventually provide an
optional “Encrypt system” option during installation.
…On Mon, 24 Aug 2026 at 16:54, Anduin Xue ***@***.***> wrote:
Ubuntu seems separated the initrd and kernel out of btrfs volume.
—
Reply to this email directly, view it on GitHub
<#417?email_source=notifications&email_token=B4VDWAAQPGWPYQKV2GYB4435LQNH5A5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBRGMZTSMRWUZZGKYLTN5XKU43VMJZWG4TJMJSWJJLFOZSW45FMMZXW65DFOJPWG3DJMNVQ#discussioncomment-18133926>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/B4VDWAG3NA3KU4QYWB3DSCL5LQNH5AVCNFSNUABIKJSXA33TNF2G64TZHM3DQMZWGA2TANJVHNCGS43DOVZXG2LPNY5TCMBWG4YTGMZRUF3AE>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/B4VDWABLAE4MHA5TM3X5VZL5LQNH5A5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBRGMZTSMRWUZZGKYLTN5XKU43VMJZWG4TJMJSWJJLFOZSW45FKMZXW65DFOJPWS33T>
and Android
<https://github.com/notifications/mobile/android/B4VDWAHHTIX2FHHTNSU5H2L5LQNH5A5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBRGMZTSMRWUZZGKYLTN5XKU43VMJZWG4TJMJSWJJLFOZSW45FOMZXW65DFOJPWC3TEOJXWSZA>.
Download it today!
You are receiving this because you are subscribed to this thread.Message
ID: ***@***.***
com>
|
|
We have been evaluating several ways to combine Btrfs snapshots, full-disk encryption, Secure Boot, and atomic kernel rollback in AnduinOS. The core problem is simple:
The main options we discussed are: Branch A — LUKS2 data + detached LUKS1 header for GRUBKeep the real root as modern LUKS2+Btrfs, but place a small detached LUKS1 compatibility header on the ESP. Ubuntu’s signed GRUB can use that old-format header to unlock the same encrypted data area. Pros
Cons
Branch C — Minimal Linux firmware loader + kexecKeep a fixed signed Ubuntu kernel/initramfs on the ESP. It boots only to ask for the disk password, unlock LUKS2 with normal Linux Pros
Cons
Branch B — Machine-local MOK, custom GRUBGenerate a per-machine signing key, enroll it through MokManager, then use a custom self-contained GRUB that directly understands the required LUKS2/Btrfs stack and only boots trusted root-owned artifacts. Pros
Cons
Branch M — Microsoft-signed AnduinOS shimThis is probably the long-term “real distribution” solution. We obtain an EV code-signing certificate to enter Microsoft’s UEFI signing process, build an AnduinOS shim containing our own Boot CA, pass shim-review, and have Microsoft sign that shim. After that, the AnduinOS trust chain can validate our own GRUB/kernel/UKI artifacts. Conceptually: Pros
Cons
Why Ubuntu does not have this problemUbuntu mostly sidesteps it. Its classic encrypted installation looks roughly like: GRUB reads the plaintext kernel and initramfs from That is simple and mature, but Ubuntu does not promise that rolling back a Btrfs root snapshot also atomically rolls back the matching kernel, initramfs, DKMS state and boot configuration. AnduinOS wants a stronger invariant:
That requirement is what turns At the moment, Branch A is the most heavily proven mechanism, Branch C is the cleanest certificate-free LUKS2 design, and Branch M is probably the long-term distribution-grade end state. |
Uh oh!
There was an error while loading. Please reload this page.
We hope that the new‑version installer can add support for system filesystem encryption. Thank you very much!
All reactions