systemd-boot-password
systemd-boot-password copied to clipboard
kernel-install plugin?
Is this project dead?
I'm planning to use systemd kernel-install to install a unified kernel image, signed with Secure Boot. Does systemd-boot-password have a kernel-install plugin, that can protect the cmdline within the UKI so an attacker with physical access can't simply boot a rescue disk and modify the systemd-boot password and get into the device?
Or am I misunderstanding something about how the cmdline works in UKI?