- Arch инсталиран
- pacstrap /mnt base linux linux-firmware sudo vim openssh networkmanager iwd
- UEFI vm
- /dev/vda1 ESP (vfat)
- /dev/vda2 crypt luks root
- systemctl enable --now sshd NetworkManager
- јузер damjan
- useradd -m damjan
- usermod -a -G wheel damjan
- /etc/sudoers.d/wheel
- ssh-copy-id …
-
ги скокнавме од инсталација
- sudo pacman -S tree tmux which
- timezone = sudo timedatectl set-timezone Europe/Skopje
- hostname = sudo hostnamectl set-hostname arch-testing
- locale = sudo localectl set-locale en_US.UTF-8
- [testing]
- networkd/resolved/mdns/llmnr
-
Dbus broker
- sudo pacman -S dbus-broker
- sudo systemctl enable dbus-broker.service
- sudo systemctl --user --global enable dbus-broker.service
-
home
- нов диск за home
- homectl
-
secure-boot
- sudo pacman -S sbctl binutils efibootmgr
- sudo sbctl generate-keys
- sudo sbctl bundle -s --kernel-img /boot/vmlinuz-linux --initramfs /boot/initramfs-linux.img --efi-stub /usr/lib/systemd/boot/efi/linuxx64.efi.stub --cmdline /etc/kernel/cmdline -p /boot /boot/EFI/Linux/arch-bundle.efi
- sudo sbctl sign -s /boot/EFI/Linux/arch-bundle.efi
- sudo efibootmgr -v -c -L ArchBundle -l /EFI/Linux/arch-bundle.efi --disk /dev/vda
- reboot - set UEFI/Secure-boot in "Custom mode" or "User mode"
- sudo sbctl enroll-keys
- reboot
-
tpm2 luks unseal - trials and tribulations
- sudo pacman -S tmp2-tss
- measurements
- објаснето
- systemd-cryptenroll --tpm2-device=auto /dev/vda2