Im working on a livebuild of a secure image and looking for some pointers.

The intent is to change the initramfs to a custom made one (lets call it initramfs-tiny) that first validates the cryptographic hash of the initramfs, then decrypts the initramfs using a JCOP4 smart card with Smartpgp on it. To do this Ill build a small initramfs that does the work. (not a problem, I can do/script this)

The problem is Im not sure how to interrupt and change the build process in live-build to encrypt the initramfs, generate the needed hashes, then change the grub menu to boot to the new initramfs-tiny. Ok that last part is not hard but telling live-build to change how the initramfs is made is something I have not found in any of the docs or anyone writing about.

Any help would be appreciated.

Attachment: 0xBE355809.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to