From fca5f7a16743b7763302c8dfa2f12bea0aa396bc Mon Sep 17 00:00:00 2001 From: Rouven Seifert Date: Sat, 18 Feb 2023 19:33:05 +0100 Subject: [PATCH] use tpm to encrypt drives --- flake.lock | 18 +++++++++--------- hosts/thinkpad/hardware-configuration.nix | 1 + 2 files changed, 10 insertions(+), 9 deletions(-) diff --git a/flake.lock b/flake.lock index c31bc62..a7912d2 100644 --- a/flake.lock +++ b/flake.lock @@ -47,11 +47,11 @@ "xdph": "xdph" }, "locked": { - "lastModified": 1676630258, - "narHash": "sha256-pc3aIr2LgmJFcTQwICpz3d4/u5/xHDI14qY/zEhGM3k=", + "lastModified": 1676682541, + "narHash": "sha256-ltfODM3ZvqygHqbglHoiMO7Qxmdi2Z1tzVtRfXDE//0=", "owner": "hyprwm", "repo": "Hyprland", - "rev": "be2e4d9dd1e58991a4f54078a331cbcbd8265c7f", + "rev": "b944386ca54cf650d660caac31f065c0211168b1", "type": "github" }, "original": { @@ -88,11 +88,11 @@ ] }, "locked": { - "lastModified": 1676406424, - "narHash": "sha256-G+JhFuaeB15MTU8DbJALm/Yf240FCQmrWZ8Y0UzyqRI=", + "lastModified": 1676681260, + "narHash": "sha256-R2FvbPzgvDSVs0jCUA9CMDIgw4F6exF8cR+y3Yea5jQ=", "owner": "hyprwm", "repo": "hyprpaper", - "rev": "1d76f4db0d3b487b9a9562195815e181652aef7c", + "rev": "2bc88dc8c220db674f458432aec0ac0d9ea6a640", "type": "github" }, "original": { @@ -122,11 +122,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1676481215, - "narHash": "sha256-afma/1RU0EePRyrBPcjBdOt+dV8z1bJH9dtpTN/WXmY=", + "lastModified": 1676569297, + "narHash": "sha256-2n4C4H3/U+3YbDrQB6xIw7AaLdFISCCFwOkcETAigqU=", "owner": "nixos", "repo": "nixpkgs", - "rev": "28319deb5ab05458d9cd5c7d99e1a24ec2e8fc4b", + "rev": "ac1f5b72a9e95873d1de0233fddcb56f99884b37", "type": "github" }, "original": { diff --git a/hosts/thinkpad/hardware-configuration.nix b/hosts/thinkpad/hardware-configuration.nix index b7d1e40..023b8be 100644 --- a/hosts/thinkpad/hardware-configuration.nix +++ b/hosts/thinkpad/hardware-configuration.nix @@ -13,6 +13,7 @@ boot.initrd.kernelModules = [ ]; boot.kernelModules = [ "kvm-intel" ]; boot.extraModulePackages = [ ]; + boot.initrd.systemd.enable = true; boot.initrd.luks.devices."luksroot" = { device = "/dev/disk/by-uuid/6b89181c-71e0-4e84-8523-2456d3e28400"; allowDiscards = true;