I’ve been trying to set up hibernation on my laptop while also maintaining an encrypted root partition and swap using secure boot and my laptop’s TPM. I’ve documented the steps I’ve followed below, but I still am unable to enable hibernation.

I was under the impression that the only reason you can’t normally have both an encrypted harddrive and hibernation was because swap had to be encrypted as well, but if both the root partition and the swap are encrypted, I’m using UEFI secure boot, and they are automatically decrypted at boot using the TPM, shouldn’t that relieve those security concerns?

After completing the below, entering systemctl hibernate errors saying hibernation is not set up for the system. Am I missing something or is it just not possible? I can confirm not needing to enter passwords for my swap or root FS due to the TPM unlock.

My personal documentation below:

Drop into root shell

sudo su -

Setup LUKS encryption with automatic unlock with TPM

Install necessary components, regenerate initramfs and reboot

dnf install -y clevis clevis-luks clevis-dracut clevis-udisks2 clevis-systemd
dracut -fv --regenerate-all && systemctl reboot

Identify swap and root partition devices, names, and luks UUIDs…

lsblk -f
cryptsetup luksUUID <UUID>

In my case, my home partition is on /dev/nvme0n1p4 and my swap is /dev/nvme0n1p3

# the encrypted home partition
clevis luks bind -d /dev/nvme0n1p4 tpm2 '{"pcr_ids":"1,4,5,7"}'

# the encrypted swap
clevis luks bind -d /dev/nvme0n1p3 tpm2 '{"pcr_ids":"1,4,5,7"}'

Set a timeout before the system asks for a password, to allow time for the TPM to load and enter the password for you systemctl edit systemd-ask-password-plymouth.service

Add the below then ctrl+o ctrl+x to save and exit

[Service]
ExecStartPre=/bin/sleep 10

Create a dracut configuration file to install the systemd-ask-password-plymouth service: vi /etc/dracut.conf.d/systemd-ask-password-plymouth.conf

Add the below, ensure there are spaces inside the quotation marks on either side of the filename

install_items+=" /etc/systemd/system/systemd-ask-password-plymouth.service.d/override.conf "

Regenerate initramfs and reboot

dracut -fv ‐‐regenerate-all && systemctl reboot

Edit crypttab file (/etc/crypttab)to specify decryption of swap file at boot, duplicate the already present line for your root FS crypttab entry and change the UUIDs to reflect the swap file, use cryptsetup luksUUID /dev/nvme0n1p3 and cryptsetup luksUUID /dev/nvme0n1p4 to get the luks UUIDs for your root and swap partitions.

<swap LUKS UUID> UUID=<swap UUID> none x-initrd.attach
<root FS LUKS UUID> UUID=<root FS UUID> none x-initrd.attach

Regenerate initramfs and reboot: dracut -fv --regenerate-all && systemct reboot

Edit fstab to include swap, append the following to /etc/fstab:

UUID=<swap UUID> none swap defaults,x-systemd.device-timeout=0 1 1

Rebind your home and swap partitions. You will have to do this every time you update the kernel.

# encrypted home partition
clevis luks regen -d /dev/nvme0n1... -s 1

# encrypted swap
clevis luks regen -d /dev/nvme0n1... -s 1
  • Ooops@feddit.org
    link
    fedilink
    arrow-up
    1
    ·
    2 days ago

    Wild guess as I’m not using dracut and have only setup encrypted hibernation on an old bios laptop…

    But did you edit the systemd-sleep.conf (usually /etc/systemd/sleep.conf, although there are some other possible locations)? The other old-school and universal way of telling your system that hibernate is enabled without systemd would be a resume= kernel parameter

    • tapdattl@lemmy.worldOP
      link
      fedilink
      arrow-up
      0
      ·
      22 hours ago

      I did not, looking at my new laptop that file doesn’t even exist, is that something I can just create and add in to folder? On my current computer it exists, so I have a template at the very least.

      • Ooops@feddit.org
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        20 hours ago

        As of the manpages systemd-sleep looks for:

        The main configuration file is loaded from one of the listed directories in order of priority, only the first file found is used: /etc/systemd/, /run/systemd/, /usr/local/lib/systemd/, /usr/lib/systemd/.

        Also

        The default configuration is set during compilation, so configuration is only needed when it is necessary to deviate from those defaults.

        So yes, you can use any existing file from another computer as your template (root:root 644 would be the default owner/permissions for it).

        PS: I tried on my PC and setting AllowHibernation=no in the config file produced a different “hibernate is disabled by config” error. Only if I remove the resume=<swap location> kernel parameter do I get the “not set up” error you mentioned but I’m not at home and only have my old (encrypted and able to hibernate) bios laptop with me. So I can’t check this for modern UEFI where systemd-sleep should automatically pick a suitable swap space and save the location in an EFI variable without any additional configuration.

        You can however set the resume=UUID=<your swap's UUID> kernel parameter anyway. Even the automatic systemd/uefi setup accepts this as a way to manually select a location. So maybe you try that. If your problem is decryption of the swap at startup you should not get an error when initiating the hibernation as you do now but instead get problems when you try to restart from swap.