¼¼Êõ²©¿Í

    04/07/2017 ×÷Õß ÔÆº£ÓÎÏ·

    Linuxϵͳ°²È«Æô¶¯


    ÕâÊǹØÓÚLinux°²È«Æô¶¯ºÍÇ©ÃûÄ£¿éÁ½ÆªÏµÁÐÎÄÕµĵÚ1ƪ£º

    1. Linuxϵͳ°²È«Æô¶¯
    2. ¹¹½¨²¢°²×°ÒÑÇ©ÃûÔÆº£ÓÎÏ·Çý¶¯³ÌÐòÄ£¿é?

    ʲôÊǰ²È«Æô¶¯£¿

    ¡°°²È«Æô¶¯¡±ÊÇ2012Äê³öÏÖµÄWindows 8ԤװµçÄÔÀïµÄUEFI¹¦ÄÜ¡£ËùÓÐĿǰµÄUbuntu 64루·Ç32룩°æ±¾ÏÖÔÚÖ§³Ö´Ë¹¦ÄÜ¡£¼ò¶øÑÔÖ®£¬°²È«Æô¶¯¹¤×÷Ô­ÀíÊÇÔڹ̼þÖÐÆôÓÃÐÅÈÎÔ´»úÖÆ¡£ËäÈ»ÆäËüʵÏÖ·½Ê½ÊÇ¿ÉÄܵ쬵«ÔÚʵ¼ùÖÐͨ¹ýx509Ö¤ÊéÀ´ÊµÏÖÐÅÈÎÁ´¡£¸ùÖ¤Êé1ǶÈëÔڹ̼þÖУ¬Ê¹µÃËü¿ÉÒÔÑé֤ǩÃûµÄÒýµ¼¼ÓÔØ³ÌÐò£¬È»ºó£¬Ç©ÃûµÄÒýµ¼¼ÓÔØ³ÌÐò¿ÉÒÔÑéÖ¤ÒÑÇ©ÃûÄں˻òÒÑÇ©ÃûµÄµÚ¶þ¼¶Òýµ¼¼ÓÔØ³ÌÐòµÈ¡£Óйذ²È«Æô¶¯µÄ¸ü¶àÐÅÏ¢¼ûUbuntuά»ù¡£2 ΪÁËʹÓð²È«Æô¶¯£¬ÎÒÃÇÐèҪʹÓÃUEFIÆô¶¯ÏµÍ³£¬¶ø²»ÊǾɵÄBIOS¡£


    BIOSÓëUEFIÓÐÊ²Ã´Çø±ð£¿

    Á½Õß¶¼¿É³õʼ»¯¼ÆËã»ú£¬ÈÎÎñÊǼÓÔØ²Ù×÷ϵͳ¡£BIOSͨ¹ý¶ÁȡӲÅÌÉϵĵÚÒ»¸öÉÈÇø£¨Ö÷Òýµ¼¼Ç¼£¨MBR£©£©²¢Ö´ÐÐËüÀ´Æô¶¯¡£Ïà±È֮ϣ¬UEFIͨ¹ý´ÓÓ²ÅÌÉϵķÖÇø£¨³ÆÎªEFIϵͳ·ÖÇø£¨ESP£©£©¼ÓÔØEFI³ÌÐòÎļþ£¨Ê¹ÓÃ.efiÎļþÀ©Õ¹Ãû£©À´Æô¶¯¡£3


    ÎÒµÄLinuxϵͳÊÇʹÓÃUEFI»¹ÊÇBIOSÆô¶¯µÄ£¿

    ×î¼òµ¥µÄ·½·¨ÊǼì²éÎļþ¼Ð/sys/firmware/efiÊÇ·ñ´æÔÚ¡£

    secureBoot:~$ ls /sys/firmware/efi/
    config_table  fw_platform_size  runtime      systab
    efivars       fw_vendor         runtime-map  vars

    Èç¹ûLinux¼ÆËã»úʹÓô«Í³BIOSÆô¶¯£¬Ôò²»»á³öÏÖ/sys/firmware/efiÎļþ¼Ð¡£

    legacy:~$ ls /sys/firmware/efi
    ls: cannot access /sys/firmware/efi: No such file or directory

    ÎÒµÄLinuxϵͳÊÇ·ñʹÓð²È«Æô¶¯£¿

    mokutilÃüÁîÓÃÓÚ¹ÜÀí»úÖ÷ÃÜÔ¿£¨MOK£©¡£ÕâЩÃÜÔ¿ÓÉshim²ãÓÃÓÚÑéÖ¤grub2ºÍÄÚºËÓ³Ïñ£¬Ò²¿ÉÓÃÓÚÑéÖ¤°²È«Æô¶¯ÊÇ·ñÆôÓá£

    secureBoot:~$ mokutil --sb-state
    SecureBoot enabled

    ÎÒÃÇÒ²¿ÉÒÔʹÓÃmokutilÃüÁîÀ´²é¿´µ±Ç°ËùÓÐÒÑ×¢²áµÄÃÜÔ¿¡£

    secureBoot:~$ mokutil --list-enrolled

    δǩÃûÄ£¿éµÄÌØÕ÷ÊÇʲô£¿

    Èç¹ûÎÒÃÇÔÚÆôÓÃÁ˰²È«Æô¶¯µÄ¼ÆËã»úÉϱàÒë²¢°²×°ÁËÎÞÓÐЧǩÃûµÄÔÆº£ÓÎÏ·Çý¶¯³ÌÐòÄ£¿é£¬¼´Ê¹ÎÒÃÇÁ¬ÉÏÁËÔÆº£ÓÎÏ··ÖÎöÒÇ£¬ÔÚÔËÐÐlistChannelsʾÀýµÄʱºòÎÒÃÇÒ²²»»áÕì²âµ½ÈκÎͨµÀ¡£

    secureBoot:~$ ./listChannels
    Canlib version 5.20
    Found 0 channel(s).

    ÎÒÃÇ¿ÉÒÔʹÓÃlsusbÃüÁîÑéÖ¤ÔÆº£ÓÎÏ··ÖÎöÒÇʵ¼ÊÉÏÊÇÓÉUSB×ÓϵͳÁ¬½ÓºÍʶ±ðµÄ¡£

    secureBoot:~$ lsusb | grep ÔÆº£ÓÎÏ·
    Bus 003 Device 008: ID 0bfd:0108 ÔÆº£ÓÎÏ· AB

    ÎÒÃÇÏÖÔÚ²éÕÒϵͳÈÕÖ¾ÖеĴíÎ󣬲¢»á·¢ÏÖÀàËÆ´íÎó¡°ËùÐèÃÜÔ¿²»¿ÉÓᱡ£

      apr 19 16:05:38 mypc /usr/sbin/mhydra.sh[22789]: modprobe: ERROR: could not insert ’mhydra’:
    Required key not available
      apr 19 16:05:38 mypc systemd-udevd[22776]: Process ’/usr/sbin/mhydra.sh start’ failed
    with exit code 1.

    Õâ¸æËßÎÒÃÇÐèҪǩÃûÄ£¿éʹÆäÔÚ¼ÆËã»úÉϹ¤×÷¡£ÔÚÏÂÆªÎÄÕÂÖÐÎÒÃǽ«¿´¿´ÈçºÎ¹¹½¨ºÍÇ©ÊðÔÆº£ÓÎÏ·Çý¶¯³ÌÐòÄ£¿é£¬ÒÔ±ãÄܹ»ÔÚÆôÓÃÁ˰²È«Æô¶¯µÄLinux¼ÆËã»úÉÏʹÓÃËüÃÇ¡£


    ½Å×¢

    1? ¸ùÖ¤ÊéÊÇÓÉÊÜÐÅÈεÄÖ¤Êé°ä·¢»ú¹¹£¨CA£©°ä·¢µÄÖ¤Êé

    2? Óйذ²È«Æô¶¯µÄ¸ü¶àÄÚÈݼûUbuntuά»ùhttps://wiki.ubuntu.com/SecurityTeam/SecureBoot/

    3 BIOSºÍUEFIÖ®±È½Ï¼û³¬¼¶Óû§ÎÄÕ£ºhttps://superuser.com/questions/496026/what-is-the-difference-in-boot-with-bios-and-boot-with-uefi

    Author Image

    Mikkel Gerdes

    ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿