##openSUSE Tumbleweed now uses systemd-boot as default for NEW installations! Better# FDE integration with #TPM2 / #FIDO2, simpler boot management via BLS. Existing systems stay on GRUB..#Linux https://linuxiac.com/opensuse-tumbleweed-switches-fresh-installs-to-systemd-boot/
openSUSE Tumbleweed Switches Fresh Installs to systemd-boot

openSUSE Tumbleweed has replaced GRUB2-BLS with systemd-boot as the default bootloader for fresh installations.

Linuxiac
Big #security improvement for #openSUSE #FDE; pcr-oracle is being replaced by #systemd-pcrlock, which stores policy in #TPM2 non-volatile RAM and protects against rollback attacks. Time to migrate! 🔐 #Linux https://news.opensuse.org/2026/03/11/dropping-pcr-oracle/
Dropping pcr-oracle in user space Full Disk Encryption

Introduction In user space Full Disk Encryption (FDE), as opposed to the boot loader based FDE, developers for openSUSE supported signed policy and NVIndex p...

openSUSE News
I just configured my #Fedora laptop to use the #TPM2 chip to unencrypt my #LUKS partitions instead of having to enter the passphrase on every boot. And I'm wondering, why didn't I do that sooner? 

Acabo de configurar mi instalación e #Fedora para que descifre mis particiones #LUKS usando el chip #TPM2 en vez de que tenga que meter la frase de paso en cada inicio, y me estoy preguntando, ¿por qué nabos no lo hice antes?  

#Linux

#openSUSE is dropping pcr-oracle in Full Disk Encryption #FDE. systemd-pcrlock now handles #TPM2 policy, fixing rollback attacks and simplifying maintenance. Migration is just two commands! 🔒🐧 Find out more. #Linux https://news.opensuse.org/2026/03/11/dropping-pcr-oracle/
Dropping pcr-oracle in user space Full Disk Encryption

Introduction In user space Full Disk Encryption (FDE), as opposed to the boot loader based FDE, developers for openSUSE supported signed policy and NVIndex p...

openSUSE News

Talking about #TPM2 again at a new venue #scale23x

https://www.socallinuxexpo.org/scale/23x/presentations/enhancing-tpm-security-linux-kernel

I don't think they record but I promise to do a blog post really soon about how to use the exported null name to verify the #TPM in your booted OS is secure.

Enhancing TPM security in the Linux Kernel | SCALE

The Southern California Linux Expo (SCALE) is North America’s largest community-run open source conference.

@lug_nuernberg Great Meme 🫶 #TPM2 was a child once - for a better understanding, may I add this great animation to your thread? I think it's worth viewing ❤️

https://youtu.be/mLoIcdIu_Kk?si=YULJHV9WXf56U_OZ
#trustedcomputing #tcpa

TCPA - Trusted Computing Platform Alliance

YouTube
RT @[email protected]
GRUB 2.14 launches in Jan 2026, fixing the Year 2038 bug and adding Argon2, TPM 2.0, and EROFS support for the ultimate Linux boot security. https://securityonline.info/defeating-the-epochalypse-grub-2-14-arrives-to-save-linux-from-year-2038/ #GRUB214 #Linux #Bootloader #Y2038 #CyberSecurity2026 #OpenSource #TPM2 #Argon2 #TechNews #GNU
Defeating the Epochalypse: GRUB 2.14 Arrives to Save Linux from Year 2038

GRUB 2.14 launches in Jan 2026, fixing the Year 2038 bug and adding Argon2, TPM 2.0, and EROFS support for the ultimate Linux boot security.

Daily CyberSecurity