Boot and Security

cache22 uses systemd-boot loading a per-machine-signed Unified Kernel Image (UKI). The signing key is generated at install time on the user’s machine and lives only on the encrypted root. There is no central CI signing key.

This whole section is UEFI-only. Secure Boot, signed UKIs, sd-boot, per-machine SB keys, and TPM2 LUKS auto-unlock all depend on UEFI firmware. cache22 also supports legacy BIOS installs (see Installation → BIOS install), but on BIOS the boot chain is GRUB → kernel + initrd with no cryptographic verification and no LUKS support. None of the tools described in this section apply to BIOS installs.

Pages in this section:

  1. Boot Chain. The full sd-boot + UKI architecture.
  2. cache22-secureboot. Managing the per-machine SB key and firmware DB enrollment.
  3. TPM and LUKS. Auto-unlock with cache22-encryption. Includes the PCR 11 vs PCR 7 dual-keyslot decision.
  4. Threat Model. What is and is not protected.

For the one-time first-boot key enrollment, see First-Boot Secure Boot Setup.


Table of contents