Skip to content
  • Francis Lam's avatar
    Added the ability to persist a default boot option · 8004b5df
    Francis Lam authored
    Similar to qubes-update, it will save then verify the hashes of
    the kexec files. Once TOTP is verified, a normal boot will verify
    that the file hashes and all the kexec params match and if
    successful, boot directly to OS.
    
    Also added a config option to require hash verification for
    non-recovery boots, failing to recovery not met.
    8004b5df