Skip to content

Hardening domain

Boot & Physical Security

Physical or boot-time access undoes most software controls. This domain sets a GRUB password, enables Secure Boot, and encrypts disks with LUKS so a stolen drive or single-user boot reveals nothing.

  1. Boot & Physical Security: GRUB, LUKS, Secure Boot

    Harden the Linux boot chain against console access, stolen disks and evil-maid attacks with GRUB passwords, LUKS encryption and Secure Boot.

All posts in this series

Harden the Linux boot chain against console access, stolen disks and evil-maid attacks with GRUB passwords, LUKS encryption and Secure Boot.