Re: [systemd-devel] Why is my reboot.target disabled?

2023-07-05 Thread Andrei Borzenkov
On 05.07.2023 11:57, Ferenc Wágner wrote: Andrei Borzenkov writes: On 04.07.2023 14:58, Ferenc Wágner wrote: Please help me understand this phenomenon (systemd 252): $ systemctl status ctrl-alt-del.target ○ reboot.target - System Reboot Loaded: loaded

Re: [systemd-devel] bind-mount of /run/systemd for chrooted bind9/named

2023-07-05 Thread Petr Menšík
I would not recommend using own chroot to anyone, who has enabled SELinux or similar security technology. We still offer subpackage bind-chroot, which has prepared named-chroot.service for doing just that. But SELinux provides better enforcement, while not complicating deployment and usage of

[systemd-devel] LLMNR should be disabled on new deployments

2023-07-05 Thread Petr Menšík
Hello everyone, I would like to request disabling LLMNR protocol in new releases by default. The protocol itself is deprecated even by Microsoft, who disabled it in Windows 10. I think Multicast DNS is supperior and MS thinks it also [1]. Because it is not implemented well in

Re: [systemd-devel] timing issue in mounting systemd filesystems

2023-07-05 Thread Giacinto Cifelli
Hi Lennart, thank you for your help. I found the issue, it is a mismatch between the compiler or libc used for the kernel and the systemd/mount executables. Difference not declared, I managed by accident to find the right cross-compiler. On Wed, Jul 5, 2023 at 10:57 AM Lennart Poettering

Re: [systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Felix Rubio
I understand that, but systemd-measure is only about PCR 11. Is there any way to provide a list of PCRs, so that additionally can be embedded on the UKI? Thank you, Felix On 2023-07-05 14:26, Lennart Poettering wrote: On Mi, 05.07.23 13:11, Felix Rubio (fe...@kngnt.org) wrote: For what is

Re: [systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Lennart Poettering
On Mi, 05.07.23 14:17, Mantas Mikulėnas (graw...@gmail.com) wrote: > On Wed, Jul 5, 2023 at 2:11 PM Felix Rubio wrote: > > > For what is explained on the the systemd-pcrphase.service(8) and > > comparing it to what I see in the log of the systemd services, there are > > three events in relation

Re: [systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Lennart Poettering
On Mi, 05.07.23 13:11, Felix Rubio (fe...@kngnt.org) wrote: > For what is explained on the the systemd-pcrphase.service(8) and comparing > it to what I see in the log of the systemd services, there are three events > in relation to this question: > > systemd-pcrphase-initrd.service > [...] >

Re: [systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Mantas Mikulėnas
On Wed, Jul 5, 2023 at 2:11 PM Felix Rubio wrote: > For what is explained on the the systemd-pcrphase.service(8) and > comparing it to what I see in the log of the systemd services, there are > three events in relation to this question: > > systemd-pcrphase-initrd.service > [...] >

Re: [systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Felix Rubio
For what is explained on the the systemd-pcrphase.service(8) and comparing it to what I see in the log of the systemd services, there are three events in relation to this question: systemd-pcrphase-initrd.service [...] [systemd-ask-password-console.service] [...] systemd-pcrphase-sysinit

Re: [systemd-devel] Why is my reboot.target disabled?

2023-07-05 Thread Ferenc Wágner
Andrei Borzenkov writes: > On 04.07.2023 14:58, Ferenc Wágner wrote: > >> Please help me understand this phenomenon (systemd 252): >> >> $ systemctl status ctrl-alt-del.target >> ○ reboot.target - System Reboot >> Loaded: loaded (/lib/systemd/system/reboot.target; disabled; preset: >>

Re: [systemd-devel] timing issue in mounting systemd filesystems

2023-07-05 Thread Lennart Poettering
On Mi, 05.07.23 07:59, Giacinto Cifelli (gciof...@gmail.com) wrote: > I have then increased the log level to debug in the kernel cmdline to > have more info: > systemd.log_level=debug systemd.log_target=console > > and with these settings it boots normally (although much slower). output to

Re: [systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Lennart Poettering
On Mi, 05.07.23 08:30, Felix Rubio (fe...@kngnt.org) wrote: > Hi everybody, > > In my setup (sd-boot+UKI+LUKS) I am using PCRs 7+11+14 to unlock the LUKS > drive. Should I use only PCRs 7+14 everything works, but when I add 11 I > need to provide the rescue password every single time I boot. > >

[systemd-devel] Enrolling PCR11 does not work as expected

2023-07-05 Thread Felix Rubio
Hi everybody, In my setup (sd-boot+UKI+LUKS) I am using PCRs 7+11+14 to unlock the LUKS drive. Should I use only PCRs 7+14 everything works, but when I add 11 I need to provide the rescue password every single time I boot. I have extracted the values of those PCRs using tpm2_pcrread in two

[systemd-devel] timing issue in mounting systemd filesystems

2023-07-05 Thread Giacinto Cifelli
Dear community, I have an issue booting on a RV machine. The mount targets fail, and (I suppose) as a consequence everything else fails and the system is not running: [FAILED] Failed to mount Huge Pages File System. [FAILED] Failed to mount POSIX Message Queue File System. [FAILED] Failed to