• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Arch Linux - stuck at "Loading Initial ramdisk"

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.
That is the GRUB message for sure. The kernel is not loading because it isn't asking me for my encryption password. It can't load the kernel from an encrypted partition. I don't know what you are asking me about mounting. I tried multiple different methods, all mentioned above.
 
That is the GRUB message for sure. The kernel is not loading because it isn't asking me for my encryption password. It can't load the kernel from an encrypted partition. I don't know what you are asking me about mounting. I tried multiple different methods, all mentioned above.

Do you mean by that that you have the kernel on an encrypted partition? Vanilla GRUB can't decrypt partitions by itself IIRC. Maybe that's your problem?

What I was asking was where your EFI partition was mounted on. I wanted to know if you had your kernel inside the encrypted partition or not. It seems you do have it on an encrypted partition?

What you could do if having an unencrypted boot partition bothers you is keep /boot unencrypted on an USB drive. This way you can sleep tight at night knowing your system is properly encrypted, and that there's no way someone could hijack the initrd image to pwn you, but also forget about the headaches that a full disk encryption will surely deliver.

BTW. Didn't you get a Intel 320 mSATA for your laptop? If so, why don't you just enable Intel's own FDE? You just have to set an HDD Password on the BIOS and that's it. This, I think, is supported by your Lenovo.

Intel's FDE could let you have an unecrypted /boot partition, that is actually encrypted using Intel's FDE and your HDD Password, and a LVM that is encrypted with both FDE and LUKS, in case you want to encrypt your encrypted data.
 
I set it up exactly the same way with and without UEFI and it works perfectly. It isn't the encryption settings/configuration. Sorry for the confusion, but /boot is unencrypted, but the root partition is not. I don't know why I said that.

The drive itself is always encrypted, but I would need to prevent access to it. To enable the user password, there is a BIOS menu that has an option I need to enable, but the W530 does not have this option, and I can't enable it. It is just one thing after another with this laptop on Linux not working, and it gets really frustrating. I haven't even begun to talk about Optimus, external monitors, the dock I bought for it, or any other issues I'm currently fighting. Honestly speaking, this is the least of my worries right now.

My goal isn't to prevent any and all tampering given any tools and all the time in the world with the most knowledgeable people. I just want deterrence should someone steal my laptop.
 
Back