diff --git a/mkosi.uki-profiles/90-factory-reset.conf b/mkosi.uki-profiles/90-factory-reset.conf index 7b314e76..73c46a2d 100644 --- a/mkosi.uki-profiles/90-factory-reset.conf +++ b/mkosi.uki-profiles/90-factory-reset.conf @@ -3,12 +3,12 @@ [UKIProfile] Profile= ID=factory-reset - TITLE=Reset System to Factory Defaults [CAUTION!] + TITLE=Reset System to Factory Defaults + TPM2 Clear [CAUTION!] Cmdline= - systemd.factory_reset=1 - rw + rd.systemd.unit=factory-reset.target + ro audit=0 - systemd.image_policy=esp=unprotected:xbootldr=unprotected+unused+absent:usr=signed:root=encrypted:swap=encrypted+unused+absent:home=unprotected:=ignore + systemd.image_policy=- -SignExpectedPcr=yes +SignExpectedPcr=no diff --git a/mkosi.uki-profiles/91-factory-reset-with-tpm-clear.conf b/mkosi.uki-profiles/91-factory-reset-with-tpm-clear.conf deleted file mode 100644 index e74c0fd0..00000000 --- a/mkosi.uki-profiles/91-factory-reset-with-tpm-clear.conf +++ /dev/null @@ -1,14 +0,0 @@ -# SPDX-License-Identifier: LGPL-2.1-or-later - -[UKIProfile] -Profile= - ID=factory-reset-tpm2-clear - TITLE=Reset System to Factory Defaults + TPM2 Clear [CAUTION!] - -Cmdline= - rd.systemd.unit=factory-reset.target - ro - audit=0 - systemd.image_policy=- - -SignExpectedPcr=no diff --git a/mkosi.uki-profiles/95-emergency.conf b/mkosi.uki-profiles/95-emergency.conf deleted file mode 100644 index cc736fc8..00000000 --- a/mkosi.uki-profiles/95-emergency.conf +++ /dev/null @@ -1,14 +0,0 @@ -# SPDX-License-Identifier: LGPL-2.1-or-later - -[UKIProfile] -Profile= - ID=emergency - TITLE=Boot into Emergency Mode - -Cmdline= - systemd.unit=emergency.target - rw - audit=0 - systemd.image_policy=esp=unprotected:xbootldr=unprotected+unused+absent:usr=signed:root=encrypted:swap=encrypted+unused+absent:home=unprotected:=ignore - -SignExpectedPcr=yes