this post was submitted on 07 Jul 2025
92 points (100.0% liked)

Linux

8428 readers
249 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of [email protected] and The GIMP

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 1 points 1 week ago (1 children)

That makes sense. Would a signed initramfs be possible though? Since it's usually rebuilt after most system updates?

[โ€“] [email protected] 2 points 1 week ago

Depends on the OS, but you can generally have mkinitcpio handle generating new UKIs after updates and also have it trigger something like sbctl to re-sign images.