• @[email protected]
    link
    fedilink
    English
    18 days ago

    That makes sense. Would a signed initramfs be possible though? Since it’s usually rebuilt after most system updates?

    • @[email protected]
      link
      fedilink
      English
      28 days ago

      Depends on the OS, but you can generally have mkinitcpio handle generating new UKIs after updates and also have it trigger something like sbctl to re-sign images.