techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.7K
active users

#systemrescue

1 post1 participant0 posts today

Yesterday was one of the very few times I managed to lock myself out of my #Gentoo system.

This time I didn't understand the severity of a warning after a systemd update.

With an older #SailfishOS SDK I had to set systemd.unified_cgroup_hierarchy=false on the kernel command-line to get the build docker image working. The updated systemd no longer supports this, and refused to launch...

Good that I have a #SystemRescue CD for such situations... IT took less than 15 minutes to fix it.

Replied in thread

@Gentoo_eV Given that I get a KVM console in time, I will demonstrate my installation guide (gentoo.duxsco.de/) in English using a #Hetzner dedicated server.

  • What? Beyond Secure Boot – Measured Boot on Gentoo Linux?
  • When? Saturday, 2024-10-19 at 18:00 UTC (20:00 CEST)
  • Where? Video call via BigBlueButton: bbb.gentoo-ev.org/

The final setup will feature:

  • #SecureBoot: All EFI binaries and unified kernel images are signed.
  • #MeasuredBoot: #clevis and #tang will be used to check the system for manipulations via #TPM 2.0 PCRs and for remote LUKS unlock (you don't need tty).
  • Fully encrypted: Except for ESPs, all partitions are #LUKS encrypted.
  • #RAID: Except for ESPs, #btrfs and #mdadm based #RAID are used for all partitions.
  • Rescue System: A customised #SystemRescue (system-rescue.org/) supports SSH logins and provides a convenient chroot.sh script.
  • Hardened #Gentoo #Linux for a highly secure, high stability production environment.
  • If enough time is left at the end, #SELinux which provides Mandatory Access Control using type enforcement and role-based access control

#DIY gift recipe for #nerds: Hacker Multi-Boot Drive!

1) Get a USB enclosure: USB 4.0 is best, but anything that says 20Gbps is fine; amzn.to/3TPz9bG

2) Get an M.2 NVMe: PCIe 4.0 is best, but 3.0 works too;
amzn.to/3XOIp10

3) Install #Ventoy ventoy.net/en/doc_start.html

4) Load up with ISOs: #memtest #clonezilla #hiren #systemRescue and #gparted for getting old computers working. #ubuntu #mint or some other #linux. #kali for h4x0ring.

5) Decorate!

$50 total