Nhau mbiri maererano neye pre-bootloader

Ndidzo dudziro dzezvinyorwa zviviri zvakatorwa naJames Bottomley pane rake blog. Iyo yekutanga posvo yakaitwa muna Kukadzi 1 uye inonzi "LCA2013 uye Kugadzirisazve Yakachengeteka Bhuti"

Ini ndanga ndakanyarara kwechinguva, saka inguva yekupa yekudzokorora pane zviri kuitika neLinux Foundation's Yakachengeteka Boot Loader (kunyanya iyo yaitaridzwa kuLCA2013). (Batanidza nemasiraidhi)

Musimboti wedambudziko nderekuti GregKH (kernel mugadziri Greg Kroah-Hartman) akawana mukutanga kwaZvita kuti Pre-BootLoader yakarongwa yaisazoshanda mune yazvino fomu neGummiboot. Izvo zvaive zvichityisa nekuti zvaireva kuti zvaisazadzisa iro Linux Foundation basa rekumisikidza vese bootloaders. Mukutsvagisa, chikonzero chaive chakareruka: Gummiboot yakagadzirirwa kuratidza kuti iwe unogona kugadzira diki uye yakapusa bootloader iyo yaizotora mukana wese masevhisi anowanikwa papuratifomu yeEFI pachinzvimbo chekuve chakakura chinongedzo mutakuri seGRUB. Nehurombo zvinoreva kuti iwe unobhururuka kernels uchishandisa iyo BootServices-> LoadImage () basa, zvinoreva kuti kernel rinofanira kubviswa rinofanira kupfuura nepakachengeteka bhuti cheki papuratifomu yeEFI. Pakutanga iyo Pre-BootLoader, senge Shim (Mathew Garrett's bootloader), yakanyorwa kuti ishandise PE / Coff link kurodha kuti ikunde macheki akachengeteka. Nehurombo, zvinoreva kuti chimwe chinhu chinomhanyiswa nePre-BootLoader chinofanira zvakare kushandisa chinongedzo kurodha pasi kurova zvakachengeteka bhutsu cheki pane chero chinhu chairi kuda kurodha uye saka Gummiboot, inova nemaune kwete chinongedzo chinobata, haizoshanda pasi pechirongwa ichi.

Saka ini ndaifanira kugadzirisa uye kunyora zvakare: Dambudziko raenda kubva "maitiro ekugadzira chinongedzo chakasainwa neMicrosoft icho chinoteerera marongero avo" kuenda "maitiro ekugonesa vana vese veboot loader kushandisa iyo BootServices-> LoadImage () basa re nzira yekuteerera marongero avo. Neraki, pane nzira yekubvisa iyo UEFI chikuva kusaina zvivakwa nekuisa yako wega mapuratifomu ekuchengetedza protocol. Nehurombo, chikuva chekutanga kutaurwa hachisi chaicho chikamu cheiyo UEFI kududzirwa, asi nekutenda chinoitwa neese Windows 8 system yaunogona kuwana. Iyo nyowani yekuvakisa inopindirana iyo protocol uye inowedzera yayo yega chengetedzo cheki Nekudaro, pane dambudziko repiri: Tiri mukati mekuvakwa kwekuchengetedza protocol kufona, isu hatidi kuti ive yedu yeUFI system skrini, zvichiita kuti zvisakwanise kuita bvunzo yemushandisi kupa mvumo kuisirwa kweiyo bhanari. Neraki, pane isiri-yekudyidzana nzira yekuita izvi uye ndiyo SUSE Machine Muridzi Kiyi (MOK) mashandiro. Naizvozvo, iyo Linux Foundation Pre-BootLoader ikozvino yashanduka kushandisa zviyero zveMOK zvakajairika kuchengetedza mvumo yebhinari ine mvumo.

Iko kukwidziridzwa kweizvi zvese ndekwekuti Pre-BootLoader iko zvino inogona kushandiswa naGummiboot (sekungoitwa kwayakaitwa mudemo kuCAA2013). Kubhuita, iwe unofanirwa kuwedzera maviri hashes: imwe yeGummiboot pachayo uye imwe yeiyo kernel iyo iwe yaunoda kubhowa, asi chiri chinhu chakanaka nekuti ikozvino iwe une imwechete yekuchengetedza mutemo inodzora iyo yese bhuti kuteedzana. Iyo Gummiboot pachayo yainge yakarongedzwa kuti ione kuparara nekuda kwekuchengetedza bhutsu uye inoratidza meseji inokuudza iyo hashi yekunyoresa.

Ini ndichaita rakapatsanurwa posvo ndichitsanangura mashandiro matsva ekuvaka, asi ndakafunga kuti zvaive nani kutsanangura zvakaitika mwedzi wapfuura.

Uye iyi yechipiri kutumira yaakaita nezuro uye inonzi "Yakatangisa iyo Linux Foundation Yakachengeteka Boot System"

Sezvakavimbiswa, heino Linux Foundation Yakachengeteka Boot System. Yakatoburitswa kwatiri neMicrosoft muna Kukadzi 6, asi nerwendo, misangano, uye misangano ndakanga ndisina nguva yekusimbisa zvese kusvika nhasi. Iwo mafaera ari:

PreLoader.efi (md5sum 4f7a4f566781869d252a09dc84923a82)
HashIts.efi (md5sum 45639d23aa5f2a394b03a65fc732acf2)
Gadzira zvakare bootable mini-USB mufananidzo; (Iwe unofanirwa kuiisa pane iyo USB uchishandisa dd; iwo mufananidzo une GPT partitions, saka shandisa iyo diski rese). Iyo ine EFI shell uko iyo kernel inofanira kunge iri uye inoshandisa gummiboot kuritakura. Unogona kuiwana pano (md5sum 7971231d133e41dd667a184c255b599f).

Kuti ushandise mini-USB mufananidzo, iwe unofanirwa kuisa maheshes emutoro.efi (mu \ EFI \ BOOT dhairekitori) uye iyo shell.efi (iri mumudzi folda). Iyo zvakare inosanganisira kopi yeKiyiTool.efi, iwe unofanirwa kupinda iyo hashi kuti umhanye.

Chii chakaitika kune KeyTool.efi? Pakutanga yaizove chikamu chedu chakasainwa kit. Nekudaro, panguva yekuyedza Microsoft yakaona kuti nekuda kweguru mune imwe yemapuratifomu eEFI, inogona kushandiswa kubvisa kiyi yepuratifomu zvakarongeka, izvo zvinogona kukanganisa UEFI chengetedzo system. Kusvikira tagona kugadzirisa izvi (isu tine mutengesi wega muchiuno), vakaramba kusaina KeyTool.efi kunyangwe ivo vachigona kuitendera nekuwedzera akasiyana MOK kana vachida kuimhanyisa.

Ndizivisei kuti izvi zvinofamba sei nekuti ndiri kufarira kuunganidza mhinduro pane izvo zvinoshanda nezvisingashande. Kunyanya, ndiri kunetsekana kuti kuchengetedzeka kweprotocol kupfuura kunogona kusashanda pane mamwe mapuratifomu, saka ndinonyanya kuda kuziva kana isingashande kwavari.

Source:

http://blog.hansenpartnership.com/lca2013-and-rearchitecting-secure-boot/

http://blog.hansenpartnership.com/linux-foundation-secure-boot-system-released/

Sarudza kana iri yakanaka kana yakaipa nhau.


Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira iyo data: Miguel Ángel Gatón
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako

  1.   alf akadaro

    Zvakanaka, ini handisi kuona iyo yakareba-mhedzisiro, asi kwandiri chichava chinangwa changu kutora imwe yeizvi http://blog.linuxmint.com/?p=2055

    1.    giskard akadaro

      Ivo anodhura kwazvo, ndinofunga.

    2.    Carlos-XFCE akadaro

      Kune makambani anotengesa macomputer asina pre-akaiswa mashandiro ekushandisa. Vamwe vanokutendera kuti usarudze pakati peUbuntu kana vamwe uye wotumira iyo kumba kwako yakagadzirira. Iwe unogona zvakare kutenga izvo zvikamu uye wozviunganidza iwe pachako uye isa iyo yekushandisa system yaunoda.

      Muguta rako (GDL) mune cheni yezvitoro zvemakomputa zvinotengesa makomputa isina pre-yakaiswa yekushandisa system. Unogona kuisa Linux pavari.

      Iko kune nguva dzose sarudzo. Mune ino kesi, ivo vari kure uye chaizvo "vakavanzwa" kubva kune akajairika mushandisi. Asi kune avo vedu vanoda Linux, pane, iripo.

      1.    Muraraungu_nhunzi akadaro

        Iko hakuna zvakawanda sarudzo kune vashandisi muLatin America sezvo iwo makambani "akakosha" asingawanzosvika pano

        1.    abib91 akadaro

          awwnnn kusuruvara, kusuruvara… that damn UEFI idambudziko chairo

          1.    abib91 akadaro

            Report Error…. chii chaitika? Nei ndakawana logo yeapuro mumashoko angu? Ndiri kushandisa midori, asi kubva kubuntu, kwete kubva kumac: /

          2.    pandev92 akadaro

            Zvakanaka, zvakapusa, iwe unofanirwa kushandura mushandisi mushandisi.

  2.   Damian rivera akadaro

    Aya mapulagi akavakirwa pakutsvaga tambo (zvinyorwa tambo) mune ino kesi vanotsvaga yako system mumushandisi mumiriri uye midori mushandisi mumiririri ane chinyorwa tambo iyo zvakare ine MacOS X, ini handirangariri kana intel kana Mac OSX kana iwo maviri, asi tanga watsvaga tambo iyi woirondedzera sekunge yanga iri Mac. Imwe nguva yapfuura ndakarongedza yakafanana script mu php uye imwe JavaScript uye izvi zvinogadziriswa kubva muchinyorwa, ndichiona kuti hazvitore chero chinhu mushure meMac OS X uye kutumira iwo mhedzisiro kune midori kusiyanisa, nekuti ndicho chinhu chete chinosiyanisa mushandisi mushandisi anoshandiswa nemidori neiyo inoshandiswa neMac, kana isu tinogona kuichinja futi.

    Tarisa uone ino saiti ine midori

    http://whatsmyuseragent.com/

    Uye mushandisi mushandisi haana chekuita neLinux

    Reply with quote

  3.   alf akadaro

    "Carlos-Xfce
    Muguta rako (GDL) mune ketani yezvitoro zvemakomputa zvinotengesa makomputa isina pre-yakaiswa mashandiro. Unogona kuisa Linux pavari. "

    Panguva yandakatarisa ndikasawana, mutengesi chete ainditengesera netbook pasina OS, asi izvo chete, hapana PC kana laptop, chete netbook.

    Unogona here kutaura zita reketani?

    1.    alf akadaro

      Kana kutumira zita reketani kukagona kuturikirwa zvisizvo, uye kuchionekwa kunge spam, zvingave zvakanaka kumirira maneja kuti ape maonero avo pazviri.