Fixing a broken FDE (encrypted /boot) on (K)ubuntu 26.04

Welcome to the Ubuntu Discouse!

That is unsupported by Ubuntu. See this for details and only comment on perceived security implications after having read it to the end.

TL;DR: there is nothing worth hiding in /boot; it’s verifiable integrity (“verity”) you want there, not secrecy.


I am pretty sure it still does support those things, because the actual streamlining hasn’t happened yet. It’s just that the installer will not set up GRUB for that, because of how the (still experimental) TPM-backed FDE option is implemented in the officially supported way. So, if you absolutely must have it that way, despite everything, you can make it work, just not with any help from the installer or this Discourse. But do keep in mind what is to come; the word “stranded” was used by the author of said announcement, IIRC; you connect the dots on who will be stranded where. :wink:

2 Likes