you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 3 years ago

Regarding /boot, it can be encrypted as long as your bootloader can decrypt it, for example GRUB can decrypt LUKS encrypted partitions (albeit somewhat slowly). And the only partition that really has to be unencrypted is UEFI system partition (ESP), where bootloaders are located.

  • source
  • parent