Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #204294 > unrolled thread

Debian 9 /boot && /boot/efi partition

Started byPieter Lems <lems.pieter97@gmail.com>
First post2019-01-10 20:30 +0100
Last post2019-01-14 14:00 +0100
Articles 6 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  Debian 9 /boot && /boot/efi partition Pieter Lems <lems.pieter97@gmail.com> - 2019-01-10 20:30 +0100
    Re: Debian 9 /boot && /boot/efi partition deloptes <deloptes@gmail.com> - 2019-01-10 22:00 +0100
    Re: Debian 9 /boot && /boot/efi partition Jonathan Dowland <jmtd@debian.org> - 2019-01-10 22:10 +0100
      Re: Debian 9 /boot && /boot/efi partition Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-01-13 14:10 +0100
        Re: Debian 9 /boot && /boot/efi partition Jonathan Dowland <jmtd@debian.org> - 2019-01-14 11:40 +0100
          Re: Debian 9 /boot && /boot/efi partition Steve McIntyre <steve@einval.com> - 2019-01-14 14:00 +0100

#204294 — Debian 9 /boot && /boot/efi partition

FromPieter Lems <lems.pieter97@gmail.com>
Date2019-01-10 20:30 +0100
SubjectDebian 9 /boot && /boot/efi partition
Message-ID<xeObD-36p-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Dear Debian users,
Recently I switched from QubesOS to Debian. The reason for this (just in
case anyone wants to know) is because it was hard to combine the OS with
the work I have to do for my school. While installing Debian I choose to
use the following partition scheme:

nvme0n1                 259:0    0   477G  0 disk
├─nvme0n1p1             259:1    0   512M  0 part  /boot/efi
├─nvme0n1p2             259:2    0   244M  0 part  /boot
└─nvme0n1p3             259:3    0 476.2G  0 part
  └─nvme0n1p3_crypt     254:0    0 476.2G  0 crypt
    ├─laptop--vg-root   254:1    0  23.3G  0 lvm   /
    ├─laptop--vg-var    254:2    0   9.3G  0 lvm   /var
    ├─laptop--vg-swap_1 254:3    0  15.8G  0 lvm   [SWAP]
    ├─laptop--vg-tmp    254:4    0   1.9G  0 lvm   /tmp
    └─laptop--vg-home   254:5    0   426G  0 lvm   /home
As you can see there is a /boot and a /boot/efi partition. I was wondering
the following things:
What is the reason this was automaticly done?
Does this have any negative influence on the security of my /boot partition?
How can I counter this?
And if it's possible to counter this, would it be profitable (in case of
security) to counter it?

Thanks in advance!
Kind regards,
Pieter  Lems

[toc] | [next] | [standalone]


#204298

Fromdeloptes <deloptes@gmail.com>
Date2019-01-10 22:00 +0100
Message-ID<xePAJ-3R9-5@gated-at.bofh.it>
In reply to#204294
Pieter Lems wrote:

> What is the reason this was automaticly done?
> Does this have any negative influence on the security of my /boot
> partition? How can I counter this?
> And if it's possible to counter this, would it be profitable (in case of
> security) to counter it?

Not sure but I think /boot/efi has to be dos/vfat format
[https://wiki.archlinux.org/index.php/EFI_system_partition]

And /boot you can ext4 if you want to add also grub as fallback

regards

[toc] | [prev] | [next] | [standalone]


#204299

FromJonathan Dowland <jmtd@debian.org>
Date2019-01-10 22:10 +0100
Message-ID<xePKq-49Y-1@gated-at.bofh.it>
In reply to#204294
On Thu, Jan 10, 2019 at 07:28:04PM +0000, Pieter Lems wrote:
>As you can see there is a /boot and a /boot/efi partition. I was wondering
>the following things:
>What is the reason this was automaticly done?

The system is set up to boot vie (U)EFI. The EFI boot volume must be
FAT32, so /boot/efi is created as FAT32 separately from /boot, which
is one of the exts (I think ext4). The installer will not do this if
it detects the system boots via the old-style method.

I think EFI also mandates the layout of the filesystem to the extent
that one could not simply use /boot as the EFI partition, formatted
as FAT32, but I'm not entirely sure.

>Does this have any negative influence on the security of my /boot partition?
>How can I counter this?

Both /boot and /boot/efi are unencrypted,  but I don't think that
/boot/efi is any worse than /boot for security by virtue of being
FAT32.


-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#204376

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2019-01-13 14:10 +0100
Message-ID<xfNGz-77s-37@gated-at.bofh.it>
In reply to#204299
Le 10/01/2019 à 22:02, Jonathan Dowland a écrit :
> 
> I think EFI also mandates the layout of the filesystem to the extent
> that one could not simply use /boot as the EFI partition, formatted
> as FAT32, but I'm not entirely sure.

/boot can be the EFI partition in the systemd boot specification.
<https://systemd.io/BOOT_LOADER_SPECIFICATION>

But is may disrupt Debian kernel updates because FAT does not support 
hard links.

[toc] | [prev] | [next] | [standalone]


#204398

FromJonathan Dowland <jmtd@debian.org>
Date2019-01-14 11:40 +0100
Message-ID<xg7OV-2zI-5@gated-at.bofh.it>
In reply to#204376
On Sun, Jan 13, 2019 at 02:00:02PM +0100, Pascal Hambourg wrote:
>/boot can be the EFI partition in the systemd boot specification.
><https://systemd.io/BOOT_LOADER_SPECIFICATION>

Thanks, I had seen in the past but had forgotten about it. Do you know
whether Debian has plans to follow this spec?

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#204404

FromSteve McIntyre <steve@einval.com>
Date2019-01-14 14:00 +0100
Message-ID<xga0p-3S9-23@gated-at.bofh.it>
In reply to#204398
Jonathan Dowland wrote:
>On Sun, Jan 13, 2019 at 02:00:02PM +0100, Pascal Hambourg wrote:
>>/boot can be the EFI partition in the systemd boot specification.
>><https://systemd.io/BOOT_LOADER_SPECIFICATION>
>
>Thanks, I had seen in the past but had forgotten about it. Do you know
>whether Debian has plans to follow this spec?

No plans that I've seen, no. Strikes me very much like
https://xkcd.com/927/ , to be honest.

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
Who needs computer imagery when you've got Brian Blessed?

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web