Encrypted /boot

If you want to encrypt /boot, you have to keep in mind that sys-boot/grub-2.06 has some limitations that are intended to get addressed with version 2.11. You either have to use LUKS1 OR LUKS2 with PBKDF2. I moved away from encrypting /boot with the use of measured boot and the password caching capabilities of systemd. --Duxsco (talk) 01:48, 20 June 2022 (UTC)