this post was submitted on 06 Oct 2026
18 points (100.0% liked)

Linux

67973 readers
613 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 7 years ago
MODERATORS
 

I've been trying to set up hibernation on my laptop while also maintaining an encrypted root partition and swap using secure boot and my laptop's TPM. I've documented the steps I've followed below, but I still am unable to enable hibernation.

I was under the impression that the only reason you can't normally have both an encrypted harddrive and hibernation was because swap had to be encrypted as well, but if both the root partition and the swap are encrypted, I'm using UEFI secure boot, and they are automatically decrypted at boot using the TPM, shouldn't that relieve those security concerns?

After completing the below, entering systemctl hibernate errors saying hibernation is not set up for the system. Am I missing something or is it just not possible? I can confirm not needing to enter passwords for my swap or root FS due to the TPM unlock.

My personal documentation below:

Drop into root shell

sudo su -

Setup LUKS encryption with automatic unlock with TPM

Install necessary components, regenerate initramfs and reboot

dnf install -y clevis clevis-luks clevis-dracut clevis-udisks2 clevis-systemd
dracut -fv --regenerate-all && systemctl reboot

Identify swap and root partition devices, names, and luks UUIDs...

lsblk -f
cryptsetup luksUUID <UUID>

In my case, my home partition is on /dev/nvme0n1p4 and my swap is /dev/nvme0n1p3

# the encrypted home partition
clevis luks bind -d /dev/nvme0n1p4 tpm2 '{"pcr_ids":"1,4,5,7"}'

# the encrypted swap
clevis luks bind -d /dev/nvme0n1p3 tpm2 '{"pcr_ids":"1,4,5,7"}'

Set a timeout before the system asks for a password, to allow time for the TPM to load and enter the password for you systemctl edit systemd-ask-password-plymouth.service

Add the below then ctrl+o ctrl+x to save and exit

[Service]
ExecStartPre=/bin/sleep 10

Create a dracut configuration file to install the systemd-ask-password-plymouth service: vi /etc/dracut.conf.d/systemd-ask-password-plymouth.conf

Add the below, ensure there are spaces inside the quotation marks on either side of the filename

install_items+=" /etc/systemd/system/systemd-ask-password-plymouth.service.d/override.conf "

Regenerate initramfs and reboot

dracut -fv ‐‐regenerate-all && systemctl reboot

Edit crypttab file (/etc/crypttab)to specify decryption of swap file at boot, duplicate the already present line for your root FS crypttab entry and change the UUIDs to reflect the swap file, use cryptsetup luksUUID /dev/nvme0n1p3 and cryptsetup luksUUID /dev/nvme0n1p4 to get the luks UUIDs for your root and swap partitions.

<swap LUKS UUID> UUID=<swap UUID> none x-initrd.attach
<root FS LUKS UUID> UUID=<root FS UUID> none x-initrd.attach

Regenerate initramfs and reboot: dracut -fv --regenerate-all && systemct reboot

Edit fstab to include swap, append the following to /etc/fstab:

UUID=<swap UUID> none swap defaults,x-systemd.device-timeout=0 1 1

Rebind your home and swap partitions. You will have to do this every time you update the kernel.

# encrypted home partition
clevis luks regen -d /dev/nvme0n1... -s 1

# encrypted swap
clevis luks regen -d /dev/nvme0n1... -s 1
you are viewing a single comment's thread
view the rest of the comments
[–] Flyswat@lemmy.dbzer0.com 1 points 12 hours ago* (last edited 15 minutes ago) (1 children)

Why binding specifically to PCRs 1,4,5 and 7? Are they immutable even with updates that modify db and dbx (I think I saw one recently drop on Ubuntu)?

[–] tapdattl@lemmy.world 2 points 11 hours ago (1 children)

You know I'm not 100% sure, I was following another tutorial that I can't find anymore, but if I remember right 1 was for the UEFI state, 4 was to make sure the bootloader wasn't changed, 5 was for secure boot, and 7 was for the OS being booted (To make sure someone isn't booting Kali in a live disk or something), but I could be wrong.

[–] dieTasse@feddit.org 1 points 3 hours ago

The thing about automated encrypted drive unlock is that you are missing kernel check pcr (8 or 9 I don't remember) and without that anyone can boot with compromised kernel and unlock your drive. Which makes encryption kind of pointless. The same pcr, however, means that you have to rebind after every kernel update (which is quite often on many distros). The disadvantage is that with current state of the software handling auto unlock on Linux is kinda flaky and rebinding may involve more than one restart. I eventually realized that it's less trouble to just skip this altogether and enter the password every time and then set autologin.