This PR only sets the default to "relaxed" - I can change the default to "tofu" if desired. But for that we will also need to update the NEWS file to ensure everyone is aware of this new default. --- This PR adds a new `systemd.credentials-boot=` kernel commandline that allows to control if credentials with a `null` key are accepted. The possible options are: * strict: always insist on tpm encryption * tofu: allow null encryption in firstboot mode and when no tpm is available * relaxed: allow null encryption when sb is off, or no tpm is available * off: allow null encryption always The default is `relaxed` which is exactly the behavior we had before. This replaces the initial idea of using plaintext credentials at firstboot (thanks to Lennart for this nicer and simpler design). --- With that we can drop `- firstboot: optionally accept credentials at firstboot without authentication` from TODO.md
System and Service Manager
Details
Most documentation is available on systemd's web site.
Assorted, older, general information about systemd can be found in the systemd Wiki.
Information about build requirements is provided in the README file.
Consult our NEWS file for information about what's new in the most recent systemd versions.
Please see the Code Map for information about this repository's layout and content.
Please see the Hacking guide for information on how to hack on systemd and test your modifications.
Please see our Contribution Guidelines for more information about filing GitHub Issues and posting GitHub Pull Requests.
When preparing patches for systemd, please follow our Coding Style Guidelines.
If you are looking for support, please contact our mailing list, join our IRC channel #systemd on libera.chat or Matrix channel
Stable branches with backported patches are available in the stable repo.
We have a security bug bounty program sponsored by the Sovereign Tech Fund hosted on YesWeHack
Repositories with distribution packages built from git main are available on OBS, and also repositories with packages built from the latest stable release
