Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #89007
| From | Anton Khirnov <anton@khirnov.net> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1112207: Secure Boot unconditionally disables hibernation |
| Date | 2025-08-27 15:10 +0200 |
| Message-ID | <Loo4x-aKZ9-3@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
Source: linux Severity: normal Dear maintainer(s), it seems that when Debian kernel images are booted under UEFI Secure Boot, they unconditionally enable kernel lockdown, which (among other things) unconditionally disables the ability to hibernate (suspend to disk). While I understand the reasoning behind this is that the suspended image could be maliciously modified, this is not a concern for every user - e.g. in my case the system suspends to a LUKS-encrypted swap partition. Therefore I believe there should be a way for people to make use of Secure Boot's boot image integrity guarantees while preserving the ability to hibernate. Cheers, -- Anton Khirnov -- System Information: Debian Release: 13.0 APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500, 'stable-debug'), (500, 'stable'), (400, 'unstable'), (300, 'experimental'), (1, 'experimental-debug') Architecture: amd64 (x86_64) Kernel: Linux 6.16.3+deb14-amd64 (SMP w/12 CPU threads; PREEMPT) Kernel taint flags: TAINT_CPU_OUT_OF_SPEC Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: sysvinit (via /sbin/init)
Back to linux.debian.kernel | Previous | Next | Find similar | Unroll thread
Bug#1112207: Secure Boot unconditionally disables hibernation Anton Khirnov <anton@khirnov.net> - 2025-08-27 15:10 +0200
csiph-web