• 1 Post
  • 105 Comments
Joined 2 years ago
cake
Cake day: July 4th, 2023

help-circle
  • I would do FDE yeah. My current laptop setup is with systemd-boot and a special initramfs that allows me to unlock it with a yubikey, with fallback to password. Fair warning, this exact configuration is not particularly easy to setup.

    There are also modules which enable early network connectivity along with a SSH server, meaning you login and unlock it remotely. I have not tried this.

    Debian does not frequently require rebooting under normal circumstances. Kernel updates are not that frequent, and you can usually put it off for a bit if you don’t want to deal with it.









  • Yeah, you can turn off registration without a token. Then, if you want someone to register you can issue them a registration token, or manually create their account.

    Federation can be turned on, on a case by case basis.

    You can set rooms to invite only and not discoverable. Alternately, you can use an invite-only space that allows users to join rooms from there.

    The first two parts are done in the server config, see the synapse docs. The last is done once the server is setup and running as an admin.