sbpctl
install and configure systemd-boot-password
TLDR
SYNOPSIS
sbpctl install [-i] [-d] [-s] pathsbpctl standalone [-o osrel] [-c cmdline] [-i initrd] [-s] efi outputsbpctl generate
DESCRIPTION
sbpctl controls systemd-boot-password, a systemd-boot fork whose kernel-parameter editor can be locked with a password. install copies the boot manager onto an EFI system partition (ESP). standalone packs a Linux EFI application and one or more initramfs images into a single EFI binary. generate prompts for a password and prints a SHA-512 hash for the password line in `loader.conf`.The boot menu still uses systemd-boot-style entries. The extra option is password: when it is set, pressing e to edit kernel parameters asks for that password.
PARAMETERS
-i, --include (install)
Embed `/etc/sbp/loader.conf` in the EFI binary so the boot manager never reads a file from the ESP-d, --default (install)
Install only as `/EFI/BOOT/BOOT*.EFI`-s, --sign (install and standalone)
Sign the resulting EFI binary with sbsign using `/etc/sbp/db.key` and `/etc/sbp/db.crt`-o, --osrel file (standalone)
Embed an os-release file (usually `/etc/os-release`)-c, --cmdline file (standalone)
Embed a kernel command line (usually `/proc/cmdline`)-i, --initrd file (standalone)
Embed an initramfs. May be given more than once
CONFIGURATION
Loader settings live in $ESP/loader/loader.conf, or in /etc/sbp/loader.conf when install --include is used. Entries live in **$ESP/loader/entries/*.conf**, or in the same file as the loader settings, separated by a blank line.default
Default entry: a `*.conf` file name, or entryINDEX when entries are inlinedtimeout
Menu timeout in seconds. 0 hides the menu unless Esc is held at booteditor
1 enables the kernel-parameter editor on e (the default); 0 disables itpassword
SHA-512 hash from sbpctl generate. Required to open the editorEntry keys include title, version, machine-id, efi, linux, initrd, architecture, and options. linux also adds an initrd argument to the kernel command line.
COMMANDS
install path
Install systemd-boot-password on the ESP at path. By default it is also installed as the fallback loader at `/EFI/BOOT/BOOT*.EFI`standalone efi output
Create a standalone EFI application at output from the Linux EFI binary efi, with optional os-release, cmdline, and initrd sectionsgenerate
Prompt for a password and print its SHA-512 hash for `loader.conf`
CAVEATS
install and standalone need write access to the ESP (typically root). --sign needs sbsigntools and keys in `/etc/sbp`. Restrict `/etc/sbp` to mode 700, and consider `fmask=0077` or `0177` for the ESP in `/etc/fstab`. This is a fork of systemd-boot, not a drop-in for bootctl.
HISTORY
systemd-boot-password is a small fork of systemd-boot by kitsunyan that adds a hashed password for the on-firmware editor. Arch Linux packages it from the AUR as systemd-boot-password.
