On 08/14/14 16:14, _Avyd wrote:
> Hello!
>
> I have documented my steps on moving /boot to an USB drive as it's much
> easier to keep your pendrive with you always then your laptop.
>
> Hopefully this works for everyone, but try this only if you know what
> you are doing coz it's a risky stuff (I mean loosing /boot is not good).
Hi,
Anti-Evil-Maid does this work for you, except in return it also verifies
that your BIOS and settings (or the PCR objects, to be more accurate)
were unmodified on each boot.
See Qubes user docs for the page about AEM.
Perhaps better to say "remove /boot partition from HD/SSD, leaving the
/boot directory in the root volume instead". If you do an update but
forget to mount the USB drive beforehand, the boot directory will hold
the updated files until you copy them to the USB stick. Or, you may
prefer to have no /boot folder and let an update error occur when you
forget to mount the USB stick before an update.