From mboxrd@z Thu Jan 1 00:00:00 1970 From: "pelzflorian (Florian Pelz)" Subject: Re: Unencrypted boot with encrypted root Date: Fri, 3 Apr 2020 17:32:07 +0200 Message-ID: <20200403153207.sush7eoqdxtw5yys@pelzflorian.localdomain> References: <87ftdmi7pp.fsf@ambrevar.xyz> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Received: from eggs.gnu.org ([2001:470:142:3::10]:56435) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jKOIn-0003D7-Cd for guix-devel@gnu.org; Fri, 03 Apr 2020 11:32:14 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1jKOIm-0003YB-7z for guix-devel@gnu.org; Fri, 03 Apr 2020 11:32:13 -0400 Received: from pelzflorian.de ([5.45.111.108]:33684 helo=mail.pelzflorian.de) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1jKOIl-0003P6-AK for guix-devel@gnu.org; Fri, 03 Apr 2020 11:32:12 -0400 Content-Disposition: inline In-Reply-To: <87ftdmi7pp.fsf@ambrevar.xyz> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane-mx.org@gnu.org Sender: "Guix-devel" To: Pierre Neidhardt Cc: guix-devel@gnu.org On Thu, Apr 02, 2020 at 10:59:30AM +0200, Pierre Neidhardt wrote: > I suppose that one way to do this is to make /boot a separate file Yes please, this is also an issue in https://issues.guix.info/issue/40273#24 I believe an unencrypted GRUB file-system would be a better default. Regards, Florian