I’ve been trying to set up hibernation on my laptop while also maintaining an encrypted root partition and swap using secure boot and my laptop’s TPM. I’ve documented the steps I’ve followed below, but I still am unable to enable hibernation.

I was under the impression that the only reason you can’t normally have both an encrypted harddrive and hibernation was because swap had to be encrypted as well, but if both the root partition and the swap are encrypted, I’m using UEFI secure boot, and they are automatically decrypted at boot using the TPM, shouldn’t that relieve those security concerns?

After completing the below, entering systemctl hibernate errors saying hibernation is not set up for the system. Am I missing something or is it just not possible? I can confirm not needing to enter passwords for my swap or root FS due to the TPM unlock.

My personal documentation below:

Drop into root shell

sudo su -

Setup LUKS encryption with automatic unlock with TPM

Install necessary components, regenerate initramfs and reboot

dnf install -y clevis clevis-luks clevis-dracut clevis-udisks2 clevis-systemd
dracut -fv --regenerate-all && systemctl reboot

Identify swap and root partition devices, names, and luks UUIDs…

lsblk -f
cryptsetup luksUUID <UUID>

In my case, my home partition is on /dev/nvme0n1p4 and my swap is /dev/nvme0n1p3

# the encrypted home partition
clevis luks bind -d /dev/nvme0n1p4 tpm2 '{"pcr_ids":"1,4,5,7"}'

# the encrypted swap
clevis luks bind -d /dev/nvme0n1p3 tpm2 '{"pcr_ids":"1,4,5,7"}'

Set a timeout before the system asks for a password, to allow time for the TPM to load and enter the password for you systemctl edit systemd-ask-password-plymouth.service

Add the below then ctrl+o ctrl+x to save and exit

[Service]
ExecStartPre=/bin/sleep 10

Create a dracut configuration file to install the systemd-ask-password-plymouth service: vi /etc/dracut.conf.d/systemd-ask-password-plymouth.conf

Add the below, ensure there are spaces inside the quotation marks on either side of the filename

install_items+=" /etc/systemd/system/systemd-ask-password-plymouth.service.d/override.conf "

Regenerate initramfs and reboot

dracut -fv ‐‐regenerate-all && systemctl reboot

Edit crypttab file (/etc/crypttab)to specify decryption of swap file at boot, duplicate the already present line for your root FS crypttab entry and change the UUIDs to reflect the swap file, use cryptsetup luksUUID /dev/nvme0n1p3 and cryptsetup luksUUID /dev/nvme0n1p4 to get the luks UUIDs for your root and swap partitions.

<swap LUKS UUID> UUID=<swap UUID> none x-initrd.attach
<root FS LUKS UUID> UUID=<root FS UUID> none x-initrd.attach

Regenerate initramfs and reboot: dracut -fv --regenerate-all && systemct reboot

Edit fstab to include swap, append the following to /etc/fstab:

UUID=<swap UUID> none swap defaults,x-systemd.device-timeout=0 1 1

Rebind your home and swap partitions. You will have to do this every time you update the kernel.

# encrypted home partition
clevis luks regen -d /dev/nvme0n1... -s 1

# encrypted swap
clevis luks regen -d /dev/nvme0n1... -s 1
  • mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    8 hours ago

    I actually just did this recently with a BTRFS subvolume using a swap file and LUKS encryption.

    The old Fedora magazine article has the overall steps required and someone also made a guide for secure boot on I think the spiceworks framework forum.

    The catch is that secure boot will only allow signed images to be loaded which includes the hibernation swap image, meaning you have to use a customized kernel that allows unsigned hibernation images to load.

    I’ll share both links when I get a chance.

    EDIT:

    Fedora Magazine guide: https://fedoramagazine.org/hibernation-in-fedora-36-workstation/

    This is slightly outdated as Fedora now uses a proper zram.swap definition with systemd, so you can also do a systemctl edit to disable and enable zram0 with post/pre start on the hibernate service directly instead of using swapon/swapoff. I’ll make a second edit with my example I’ll have to dig out of some poorly documented notes lol.

    https://community.frame.work/t/guide-fedora-36-hibernation-with-enabled-secure-boot-and-full-disk-encryption-fde-decrypting-over-tpm2/25474

    This is the full forum post guide for FDE + TPM + secure boot. I’m not entirely sure of the kernel patch specific but it seems that the hibernate swap image is technicallly signed because if the bootloader process, but the kernel lockdown mode rejects it regardless by default because there’s no guarantee that the swap image was configured with FDE and not tampered with, which would be a vulnerability.

    Quick glance at the kernel patch makes it seem like it’s just a flag check to allow hibernate in lockdown mode, so I assume the secure boot signature check is still completed.

    lockdown_hibernate [HIBERNATION] Enable hibernation even if lockdown is enabled. Enable this only if your swap is encrypted and secured properly, as an attacker can modify the kernel offline during hibernation.

    • tapdattl@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      51 minutes ago

      Oh awesome I had seen the Fedora Magazine article but not the framework guide. I’ll give that a shot, thank you!

  • BCsven@lemmy.ca
    link
    fedilink
    arrow-up
    3
    ·
    19 hours ago

    Did you do this ?

    Get the UUID of swap partion then add it to boot parameter(resume=UUID=xxxx)

    System needs that in grub line so it knows where to put the hibernation stuff, and obviously swap has to be equal or larger than RAM amount.

    • tapdattl@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      1 hour ago

      No, I’m using UEFI so from what I read on the ArchWiki that’s only needed for older non-UEFI systems

    • Ooops@feddit.org
      link
      fedilink
      arrow-up
      3
      ·
      9 hours ago

      I asked the same as resume= should still work in general, but strictly speaking it’s not neccesarry anymore. Modern UEFI systems work without it by saving the information where to locate the saved state in an 'HibernateLocation` EFI variable.

  • moonpiedumplings@programming.dev
    link
    fedilink
    English
    arrow-up
    3
    ·
    19 hours ago

    I don’t have/use TPM, but I do have encrypted swap and hibernation on a fully encrypted drive.

    The trick is to put the kernels in the root partition, which is encrypted by LUKS. Then, you can also put a swapfile in that same partition.

    The only unencrypted part of my system is /boot/etfi, which is the EFI partition that holds nothing but the grub binary. Grub configs and kernels are in /boot, which is on the root partition, and encrypted in LUKS.

    Grub automatically scans hard drives, before prompting with a password to decrypt the root and everything on it. Because grub is doing the decryption, rather than the kernels, the kernels and swapfile are decrypted all at once.

    • Ooops@feddit.org
      link
      fedilink
      arrow-up
      2
      ·
      9 hours ago

      OP seems to use the systemd hooks anyway. And with them all disks get decrypted with the first given password (or at least try and only ask for additional passwords if that fails). So it’s not neccessary anymore to have everything on the root partition. Several encrypted with the same password will do. (For example I unlock a classic swap partition and 3 differently sized disks creating one btrfs raid1 for root with one password.)

  • Ooops@feddit.org
    link
    fedilink
    arrow-up
    2
    ·
    23 hours ago

    Wild guess as I’m not using dracut and have only setup encrypted hibernation on an old bios laptop…

    But did you edit the systemd-sleep.conf (usually /etc/systemd/sleep.conf, although there are some other possible locations)? The other old-school and universal way of telling your system that hibernate is enabled without systemd would be a resume= kernel parameter

    • tapdattl@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      1 hour ago

      I did not, looking at my new laptop that file doesn’t even exist, is that something I can just create and add in to folder? On my current computer it exists, so I have a template at the very least.

  • Flyswat@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    11 hours ago

    Why binding specifically to PCRs 1,4,5 and 7? Are they immutable even with updates that modify db and dbx (I think I saw one recently drop on Ubuntu)?

    • tapdattl@lemmy.worldOP
      link
      fedilink
      arrow-up
      2
      ·
      23 hours ago

      You know I’m not 100% sure, I was following another tutorial that I can’t find anymore, but if I remember right 1 was for the UEFI state, 4 was to make sure the bootloader wasn’t changed, 5 was for secure boot, and 7 was for the OS being booted (To make sure someone isn’t booting Kali in a live disk or something), but I could be wrong.

      • dieTasse@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        15 hours ago

        The thing about automated encrypted drive unlock is that you are missing kernel check pcr (8 or 9 I don’t remember) and without that anyone can boot with compromised kernel and unlock your drive. Which makes encryption kind of pointless. The same pcr, however, means that you have to rebind after every kernel update (which is quite often on many distros). The disadvantage is that with current state of the software handling auto unlock on Linux is kinda flaky and rebinding may involve more than one restart. I eventually realized that it’s less trouble to just skip this altogether and enter the password every time and then set autologin.

  • Corngood@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    23 hours ago

    I’ve got multiple machines that do this, but all on nixos.

    After completing the below, entering systemctl hibernate errors saying hibernation is not set up for the system.

    This is weird, so I’d start here. Can you get the exact error and/or whatever it logs to journald?

    I’d ignore all the TPM stuff until you can hibernate it and resume with a password. Maybe the swap is just too small? Maybe something in /etc/systemd/sleep.conf?

    In case it helps, my device setup looks like this:

    NAME               FSTYPE      FSVER    LABEL                             UUID                                   FSAVAIL FSUSE% MOUNTPOINTS
    nvme0n1            crypto_LUKS 2                                          xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    └─encrypted        LVM2_member LVM2 001                                   xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
      ├─encrypted-swap swap        1        swap                              xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx                  [SWAP]
      └─encrypted-root btrfs                root                              xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx      xxxx    xxx /mnt/root
                                                                                                                                    /nix/store
                                                                                                                                    /
    nvme1n1
    ├─nvme1n1p1        vfat        FAT32                                      xxxxxxxxx                                xxxxx    xxx /boot
    [...]
    

    so luks -> lvm -> { swap, btrfs }

    Edit:

    https://wiki.archlinux.org/title/Power_management/Suspend_and_hibernate#Hibernation

    When the system is running on UEFI, systemd-sleep(8) will automatically pick a suitable swap space to hibernate into, and the information of the used swap space is stored in HibernateLocation EFI variable.

    So far I haven’t figured out from the systemd docs what “automatically pick a suitable swap space” actually means, or if that’s accurate.