Install MAS
The installer erases the whole disk you choose. Back up anything you need first.
1. Check the download
sha256sum masdistro-amd64.hybrid.iso
The result must match this checksum:
3670e65dd716164e2ae17a6419c1c8a88ba6c6da940227270610e95db65a0313
For a stronger check, download SHA256SUMS and SHA256SUMS.asc. Also download the public key. Its fingerprint is AD97 4298 3813 9A91 B6F0 01CD 7CEF 9838 D6C1 74C4. Check that it matches before you trust it. Then run:
gpg --import mas-distro-public-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS --ignore-missing
2. Write the ISO to a USB stick (8 GB or more)
Linux: find your stick with lsblk, then
run this. The wrong device name will erase the wrong disk.
sudo dd if=masdistro-amd64.hybrid.iso of=/dev/sdX bs=4M status=progress oflag=sync
Windows or macOS: use balenaEtcher.
3. Boot and connect
Boot from the USB (usually F12, F10, Esc or Del at power-on). The live desktop opens and you can try MAS without installing. Connect to Wi-Fi or plug in Ethernet, because the install downloads packages.
Live session login: user live, password
live. This is only for the USB session, not your installed
system.
4. Run the installer
Double-click MAS Installer on the desktop. If the graphical one has a problem, use MAS Installer (terminal).
Nothing is written to disk until you confirm on the last screen. You can go back at any step.
| Step | What you choose |
|---|---|
| Disk | The target disk. It refuses the disk you booted from or any disk in use. |
| Dual profile | One system or two. See Two profiles. |
| Passphrase | One per profile. It can be left blank, but then the disk is not protected. |
| Kernel | stable (Debian default, recommended),
backports (newer), or manual (advanced) |
| Graphics driver | Detected for you |
| Secure Boot | The installer checks whether it is on and tells you what that means for NVIDIA |
| Privacy | A list of toggles, all on by default. See Privacy. |
| Sandboxing | Optional firejail per-app sandboxing, off by default |
| Extras | Firefox ESR (on) and fastfetch (off) |
| System setup | Hostname, admin user, passwords |
| Locale and network | Language, timezone, keyboard, Wi-Fi |
| Confirm | Review everything, then start |
The install takes a while. It downloads the base system, the kernel and KDE Plasma.
5. Save your LUKS header backups
When the install finishes, the installer says the LUKS header backups
are in ~/mas-build/luks-headers. That folder is in the live
session and is erased when you reboot. Copy it to a USB drive or another
computer first. See Recovery
for why.
6. First boot
- Remove the USB and reboot.
- Enter your passphrase once, at boot.
- Log in with the admin user you created.
If the install stops
Run the installer again without rebooting the USB. It finds the saved progress and offers to resume, and stages whose settings haven't changed are skipped. The progress is kept in the live session, so if you reboot the USB the install starts from the beginning. See How MAS works.
Updating
sudo apt update && sudo apt full-upgrade