Hardening domain
Boot & Physical Security
Physical or boot-time access undoes most software controls. This domain sets a GRUB password, enables Secure Boot, and encrypts disks with LUKS so a stolen drive or single-user boot reveals nothing.
- Boot & Physical Security: GRUB, LUKS, Secure Boot
Harden the Linux boot chain against console access, stolen disks and evil-maid attacks with GRUB passwords, LUKS encryption and Secure Boot.