¼¼Êõ²©¿Í

04/07/2017 ×÷Õß ÔÆº£ÓÎÏ·

Linuxϵͳ°²È«Æô¶¯


ÕâÊǹØÓÚLinux°²È«Æô¶¯ºÍÇ©ÃûÄ£¿éÁ½ÆªÏµÁÐÎÄÕµĵÚ1ƪ£º

  1. Linuxϵͳ°²È«Æô¶¯
  2. ¹¹½¨²¢°²×°ÒÑÇ©ÃûÔÆº£ÓÎÏ·Çý¶¯³ÌÐòÄ£¿é?

ʲôÊǰ²È«Æô¶¯£¿

¡°°²È«Æô¶¯¡±ÊÇ2012Äê³öÏÖµÄWindows 8ԤװµçÄÔÀïµÄUEFI¹¦ÄÜ¡£ËùÓÐĿǰµÄUbuntu 64루·Ç32룩°æ±¾ÏÖÔÚÖ§³Ö´Ë¹¦ÄÜ¡£¼ò¶øÑÔÖ®£¬°²È«Æô¶¯¹¤×÷Ô­ÀíÊÇÔڹ̼þÖÐÆôÓÃÐÅÈÎÔ´»úÖÆ¡£ËäÈ»ÆäËüʵÏÖ·½Ê½ÊÇ¿ÉÄܵ쬵«ÔÚʵ¼ùÖÐͨ¹ýx509Ö¤ÊéÀ´ÊµÏÖÐÅÈÎÁ´¡£¸ùÖ¤Êé1ǶÈëÔڹ̼þÖУ¬Ê¹µÃËü¿ÉÒÔÑé֤ǩÃûµÄÒýµ¼¼ÓÔØ³ÌÐò£¬È»ºó£¬Ç©ÃûµÄÒýµ¼¼ÓÔØ³ÌÐò¿ÉÒÔÑéÖ¤ÒÑÇ©ÃûÄں˻òÒÑÇ©ÃûµÄµÚ¶þ¼¶Òýµ¼¼ÓÔØ³ÌÐòµÈ¡£Óйذ²È«Æô¶¯µÄ¸ü¶àÐÅÏ¢¼ûUbuntuά»ù¡£2 ΪÁËʹÓð²È«Æô¶¯£¬ÎÒÃÇÐèҪʹÓÃUEFIÆô¶¯ÏµÍ³£¬¶ø²»ÊǾɵÄBIOS¡£


BIOSÓëUEFIÓÐÊ²Ã´Çø±ð£¿

Á½Õß¶¼¿É³õʼ»¯¼ÆËã»ú£¬ÈÎÎñÊǼÓÔØ²Ù×÷ϵͳ¡£BIOSͨ¹ý¶ÁȡӲÅÌÉϵĵÚÒ»¸öÉÈÇø£¨Ö÷Òýµ¼¼Ç¼£¨MBR£©£©²¢Ö´ÐÐËüÀ´Æô¶¯¡£Ïà±È֮ϣ¬UEFIͨ¹ý´ÓÓ²ÅÌÉϵķÖÇø£¨³ÆÎªEFIϵͳ·ÖÇø£¨ESP£©£©¼ÓÔØEFI³ÌÐòÎļþ£¨Ê¹ÓÃ.efiÎļþÀ©Õ¹Ãû£©À´Æô¶¯¡£3


ÎÒµÄLinuxϵͳÊÇʹÓÃUEFI»¹ÊÇBIOSÆô¶¯µÄ£¿

×î¼òµ¥µÄ·½·¨ÊǼì²éÎļþ¼Ð/sys/firmware/efiÊÇ·ñ´æÔÚ¡£

secureBoot:~$ ls /sys/firmware/efi/
config_table  fw_platform_size  runtime      systab
efivars       fw_vendor         runtime-map  vars

Èç¹ûLinux¼ÆËã»úʹÓô«Í³BIOSÆô¶¯£¬Ôò²»»á³öÏÖ/sys/firmware/efiÎļþ¼Ð¡£

legacy:~$ ls /sys/firmware/efi
ls: cannot access /sys/firmware/efi: No such file or directory

ÎÒµÄLinuxϵͳÊÇ·ñʹÓð²È«Æô¶¯£¿

mokutilÃüÁîÓÃÓÚ¹ÜÀí»úÖ÷ÃÜÔ¿£¨MOK£©¡£ÕâЩÃÜÔ¿ÓÉshim²ãÓÃÓÚÑéÖ¤grub2ºÍÄÚºËÓ³Ïñ£¬Ò²¿ÉÓÃÓÚÑéÖ¤°²È«Æô¶¯ÊÇ·ñÆôÓá£

secureBoot:~$ mokutil --sb-state
SecureBoot enabled

ÎÒÃÇÒ²¿ÉÒÔʹÓÃmokutilÃüÁîÀ´²é¿´µ±Ç°ËùÓÐÒÑ×¢²áµÄÃÜÔ¿¡£

secureBoot:~$ mokutil --list-enrolled

δǩÃûÄ£¿éµÄÌØÕ÷ÊÇʲô£¿

Èç¹ûÎÒÃÇÔÚÆôÓÃÁ˰²È«Æô¶¯µÄ¼ÆËã»úÉϱàÒë²¢°²×°ÁËÎÞÓÐЧǩÃûµÄÔÆº£ÓÎÏ·Çý¶¯³ÌÐòÄ£¿é£¬¼´Ê¹ÎÒÃÇÁ¬ÉÏÁËÔÆº£ÓÎÏ··ÖÎöÒÇ£¬ÔÚÔËÐÐlistChannelsʾÀýµÄʱºòÎÒÃÇÒ²²»»áÕì²âµ½ÈκÎͨµÀ¡£

secureBoot:~$ ./listChannels
Canlib version 5.20
Found 0 channel(s).

ÎÒÃÇ¿ÉÒÔʹÓÃlsusbÃüÁîÑéÖ¤ÔÆº£ÓÎÏ··ÖÎöÒÇʵ¼ÊÉÏÊÇÓÉUSB×ÓϵͳÁ¬½ÓºÍʶ±ðµÄ¡£

secureBoot:~$ lsusb | grep ÔÆº£ÓÎÏ·
Bus 003 Device 008: ID 0bfd:0108 ÔÆº£ÓÎÏ· AB

ÎÒÃÇÏÖÔÚ²éÕÒϵͳÈÕÖ¾ÖеĴíÎ󣬲¢»á·¢ÏÖÀàËÆ´íÎó¡°ËùÐèÃÜÔ¿²»¿ÉÓᱡ£

  apr 19 16:05:38 mypc /usr/sbin/mhydra.sh[22789]: modprobe: ERROR: could not insert ’mhydra’:
Required key not available
  apr 19 16:05:38 mypc systemd-udevd[22776]: Process ’/usr/sbin/mhydra.sh start’ failed
with exit code 1.

Õâ¸æËßÎÒÃÇÐèҪǩÃûÄ£¿éʹÆäÔÚ¼ÆËã»úÉϹ¤×÷¡£ÔÚÏÂÆªÎÄÕÂÖÐÎÒÃǽ«¿´¿´ÈçºÎ¹¹½¨ºÍÇ©ÊðÔÆº£ÓÎÏ·Çý¶¯³ÌÐòÄ£¿é£¬ÒÔ±ãÄܹ»ÔÚÆôÓÃÁ˰²È«Æô¶¯µÄLinux¼ÆËã»úÉÏʹÓÃËüÃÇ¡£


½Å×¢

1? ¸ùÖ¤ÊéÊÇÓÉÊÜÐÅÈεÄÖ¤Êé°ä·¢»ú¹¹£¨CA£©°ä·¢µÄÖ¤Êé

2? Óйذ²È«Æô¶¯µÄ¸ü¶àÄÚÈݼûUbuntuά»ùhttps://wiki.ubuntu.com/SecurityTeam/SecureBoot/

3 BIOSºÍUEFIÖ®±È½Ï¼û³¬¼¶Óû§ÎÄÕ£ºhttps://superuser.com/questions/496026/what-is-the-difference-in-boot-with-bios-and-boot-with-uefi

Author Image

Mikkel Gerdes

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿