ืœื ืืจื˜ ืคื•ื˜ืจื™ื ื’ ื”ืฆื™ืข ืืจื›ื™ื˜ืงื˜ื•ืจืช ืืชื—ื•ืœ ื—ื“ืฉื” ืžืื•ืžืชืช ืฉืœ ืœื™ื ื•ืงืก

Lennart Poettering ืคืจืกื ื”ืฆืขื” ืœืžื•ื“ืจื ื™ื–ืฆื™ื” ืฉืœ ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ืขื‘ื•ืจ ื”ืคืฆื•ืช ืœื™ื ื•ืงืก, ืฉืžื˜ืจืชื” ืœืคืชื•ืจ ื‘ืขื™ื•ืช ืงื™ื™ืžื•ืช ื•ืœืคืฉื˜ ืืช ื”ืืจื’ื•ืŸ ืฉืœ ืืชื—ื•ืœ ืžืื•ืžืช ืžืœื ื”ืžืืฉืจ ืืช ื”ืžื”ื™ืžื ื•ืช ืฉืœ ื”ืœื™ื‘ื” ื•ืกื‘ื™ื‘ืช ื”ืžืขืจื›ืช ื”ื‘ืกื™ืกื™ืช. ื”ืฉื™ื ื•ื™ื™ื ื”ื ื“ืจืฉื™ื ืœื™ื™ืฉื•ื ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ื—ื“ืฉื” ื›ื‘ืจ ื›ืœื•ืœื™ื ื‘ื‘ืกื™ืก ื”ืงื•ื“ ืฉืœ ื”ืžืขืจื›ืช ื•ืžืฉืคื™ืขื™ื ืขืœ ืจื›ื™ื‘ื™ื ื›ื’ื•ืŸ systemd-stub, systemd-measure, systemd-cryptenroll, systemd-cryptsetup, systemd-pcrphase ื•-systemd-creds.

ื”ืฉื™ื ื•ื™ื™ื ื”ืžื•ืฆืขื™ื ืžืกืชื›ืžื™ื ื‘ื™ืฆื™ืจืช ืชืžื•ื ื” ืื•ื ื™ื‘ืจืกืœื™ืช ืื—ืช UKI (ืชืžื•ื ืช ืœื™ื‘ื” ืžืื•ื—ื“ืช), ื”ืžืฉืœื‘ืช ืืช ืชืžื•ื ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก, ืžื˜ืคืœ ืœื˜ืขื™ื ืช ื”ืœื™ื‘ื” ืž-UEFI (UEFI boot stub) ื•ืกื‘ื™ื‘ืช ืžืขืจื›ืช initrd ืฉื ื˜ืขื ืช ืœื–ื™ื›ืจื•ืŸ, ื”ืžืฉืžืฉืช ืขื‘ื•ืจ ืืชื—ื•ืœ ืืชื—ื•ืœ ื‘ืฉืœื‘ ืฉืœืคื ื™ ื”ืจื›ื‘ืช ื”ืฉื•ืจืฉ FS. ื‘ืžืงื•ื ืชืžื•ื ืช ื“ื™ืกืง RAM ืžืงื•ืจื™ืช, ื ื™ืชืŸ ืœืืจื•ื– ืืช ื”ืžืขืจื›ืช ื›ื•ืœื” ื‘-UKI, ืžื” ืฉืžืืคืฉืจ ืœืš ืœื™ืฆื•ืจ ืกื‘ื™ื‘ื•ืช ืžืขืจื›ืช ืžืื•ืžืชื•ืช ื‘ืžืœื•ืืŸ ื”ื ื˜ืขื ื•ืช ื‘-RAM. ืชืžื•ื ืช UKI ืžืขื•ืฆื‘ืช ื›ืงื•ื‘ืฅ ื”ืคืขืœื” ื‘ืคื•ืจืžื˜ PE, ืื•ืชื• ื ื™ืชืŸ ืœื˜ืขื•ืŸ ืœื ืจืง ื‘ืืžืฆืขื•ืช ืžื˜ืขื ื™ ืืชื—ื•ืœ ืžืกื•ืจืชื™ื™ื, ืืœื ื ื™ืชืŸ ืœืงืจื•ื ื™ืฉื™ืจื•ืช ืžืงื•ืฉื—ืช UEFI.

ื”ื™ื›ื•ืœืช ืœื”ืชืงืฉืจ ืž-UEFI ืžืืคืฉืจืช ืœืš ืœื”ืฉืชืžืฉ ื‘ื‘ื“ื™ืงืช ืชืงื™ื ื•ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื”ืžื›ืกื” ืœื ืจืง ืืช ื”ืœื™ื‘ื”, ืืœื ื’ื ืืช ื”ืชื•ื›ืŸ ืฉืœ ื”-initrd. ื‘ืžืงื‘ื™ืœ, ืชืžื™ื›ื” ื‘ื”ืชืงืฉืจื•ืช ืžืžืขืžื™ืกื™ ืืชื—ื•ืœ ืžืกื•ืจืชื™ื™ื ืžืืคืฉืจืช ืœืš ืœืฉืžื•ืจ ืขืœ ืชื›ื•ื ื•ืช ื›ื’ื•ืŸ ืžืกื™ืจื” ืฉืœ ืžืกืคืจ ื’ืจืกืื•ืช ืฉืœ ื”ืœื™ื‘ื” ื•ื”ื—ื–ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืœื’ืจืขื™ืŸ ืขื•ื‘ื“ ืื ืžืชื’ืœื•ืช ื‘ืขื™ื•ืช ืขื ื”ืœื™ื‘ื” ื”ื—ื“ืฉื” ืœืื—ืจ ื”ืชืงื ืช ื”ืขื“ื›ื•ืŸ.

ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ื‘ืจื•ื‘ ื”ื”ืคืฆื•ืช ืฉืœ ืœื™ื ื•ืงืก, ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ืžืฉืชืžืฉ ื‘ืฉืจืฉืจืช "ืงื•ืฉื—ื” โ†’ ืฉื›ื‘ืช shim ื—ืชื•ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ Microsoft โ†’ ื˜ื•ืขืŸ ืืชื—ื•ืœ GRUB ื—ืชื•ื ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ื™ื“ื™ ื”ื”ืคืฆื” โ†’ ืœื™ื‘ืช ืœื™ื ื•ืงืก ื—ืชื•ืžื” ื“ื™ื’ื™ื˜ืœื™ืช โ†’ ืกื‘ื™ื‘ืช initrd ืœืœื ื—ืชื™ืžื” โ†’ ืฉื•ืจืฉ FS." ื”ื™ืขื“ืจ ืื™ืžื•ืช initrd ื‘ื”ืคืฆื•ืช ืžืกื•ืจืชื™ื•ืช ื™ื•ืฆืจ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื”, ืฉื›ืŸ, ื‘ื™ืŸ ื”ื™ืชืจ, ื‘ืกื‘ื™ื‘ื” ื–ื• ืžืื—ื–ืจื™ื ืืช ื”ืžืคืชื—ื•ืช ืœืคืขื ื•ื— ืžืขืจื›ืช ืงื‘ืฆื™ ื”ืฉื•ืจืฉ.

ืื™ืžื•ืช ืฉืœ ืชืžื•ื ืช initrd ืื™ื ื• ื ืชืžืš ืžื›ื™ื•ื•ืŸ ืฉืงื•ื‘ืฅ ื–ื” ื ื•ืฆืจ ื‘ืžืขืจื›ืช ื”ืžืงื•ืžื™ืช ืฉืœ ื”ืžืฉืชืžืฉ ื•ืœื ื ื™ืชืŸ ืœืืฉืจ ืื•ืชื• ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ืขืจื›ืช ื”ื”ืคืฆื”, ืžื” ืฉืžืงืฉื” ืžืื•ื“ ืขืœ ืืจื’ื•ืŸ ื”ืื™ืžื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืฆื‘ SecureBoot (ื›ื“ื™ ืœืืžืช ืืช initrd, ื”ืžืฉืชืžืฉ ืฆืจื™ืš ืœื™ืฆื•ืจ ืžืคืชื—ื•ืช ืžืฉืœื• ื•ืœื˜ืขื•ืŸ ืื•ืชื ืœืงื•ืฉื—ื” ืฉืœ UEFI). ื‘ื ื•ืกืฃ, ืืจื’ื•ืŸ ื”ืืชื—ื•ืœ ื”ื ื•ื›ื—ื™ ืื™ื ื• ืžืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ืžื™ื“ืข ืžืื•ื’ืจื™ TPM PCR (Platform Configuration Register) ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ืฉืœืžื•ืชื ืฉืœ ืจื›ื™ื‘ื™ ืฉื˜ื— ื”ืžืฉืชืžืฉ ืžืœื‘ื“ shim, grub ื•ื”ืงืจื ืœ. ื‘ื™ืŸ ื”ื‘ืขื™ื•ืช ื”ืงื™ื™ืžื•ืช ืžื•ื–ื›ืจื•ืช ื’ื ื”ืžื•ืจื›ื‘ื•ืช ืฉืœ ืขื“ื›ื•ืŸ ื”-bootloader ื•ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœืžืคืชื—ื•ืช ื‘-TPM ืขื‘ื•ืจ ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉื”ืคื›ื• ืœืœื ืจืœื•ื•ื ื˜ื™ื•ืช ืœืื—ืจ ื”ืชืงื ืช ื”ืขื“ื›ื•ืŸ.

ื”ืžื˜ืจื•ืช ื”ืขื™ืงืจื™ื•ืช ืฉืœ ื”ืฆื’ืช ืืจื›ื™ื˜ืงื˜ื•ืจืช ื”ื˜ืขื™ื ื” ื”ื—ื“ืฉื” ื”ืŸ:

  • ืžืชืŸ ืชื”ืœื™ืš ืืชื—ื•ืœ ืžืื•ืžืช ื‘ืžืœื•ืื• ื”ืžืฉืชืจืข ืžืงื•ืฉื—ื” ืœืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ื”ืžืืฉืจ ืืช ืชืงืคื•ืชื ื•ืชืงื™ื ื•ืชื ืฉืœ ื”ืจื›ื™ื‘ื™ื ื”ืžื•ืคืขืœื™ื.
  • ืงื™ืฉื•ืจ ืžืฉืื‘ื™ื ืžื‘ื•ืงืจื™ื ืœืื•ื’ืจื™ TPM PCR, ืžื•ืคืจื“ื™ื ืขืœ ื™ื“ื™ ื”ื‘ืขืœื™ื.
  • ื™ื›ื•ืœืช ืœื—ืฉื‘ ืžืจืืฉ ืขืจื›ื™ PCR ื‘ื”ืชื‘ืกืก ืขืœ ื”ืœื™ื‘ื”, ื”-initrd, ื”ืชืฆื•ืจื” ื•ืžื–ื”ื” ื”ืžืขืจื›ืช ื”ืžืงื•ืžื™ ื‘ืฉื™ืžื•ืฉ ื‘ืžื”ืœืš ื”ืืชื—ื•ืœ.
  • ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช ื”ื—ื–ืจื” ืœืื—ื•ืจ ื”ืงืฉื•ืจื•ืช ืœื—ื–ืจื” ืœื’ืจืกื” ืงื•ื“ืžืช ืคื’ื™ืขื” ืฉืœ ื”ืžืขืจื›ืช.
  • ืคืฉื˜ ื•ื”ื’ื‘ืจ ืืช ืืžื™ื ื•ืช ื”ืขื“ื›ื•ื ื™ื.
  • ืชืžื™ื›ื” ื‘ืขื“ื›ื•ื ื™ ืžืขืจื›ืช ื”ืคืขืœื” ืฉืื™ื ื ืžืฆืจื™ื›ื™ื ื™ื™ืฉื•ื ืžื—ื“ืฉ ืื• ื”ืงืฆืื” ืžืงื•ืžื™ืช ืฉืœ ืžืฉืื‘ื™ื ืžื•ื’ื ื™ TPM.
  • ื”ืžืขืจื›ืช ืžื•ื›ื ื” ืœืื™ืฉื•ืจ ืžืจื—ื•ืง ื›ื“ื™ ืœืืฉืจ ืืช ื ื›ื•ื ื•ืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ื”ื”ื’ื“ืจื•ืช ื”ื˜ืขื•ื ื•ืช.
  • ื”ื™ื›ื•ืœืช ืœืฆืจืฃ ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื ืœืฉืœื‘ื™ ืืชื—ื•ืœ ืžืกื•ื™ืžื™ื, ืœืžืฉืœ, ื—ื™ืœื•ืฅ ืžืคืชื—ื•ืช ื”ืฆืคื ื” ืขื‘ื•ืจ ืžืขืจื›ืช ืงื‘ืฆื™ ื”ืฉื•ืจืฉ ืžื”-TPM.
  • ืžืชืŸ ืชื”ืœื™ืš ืžืื•ื‘ื˜ื—, ืื•ื˜ื•ืžื˜ื™ ื•ืœืœื ืžืฉืชืžืฉ ืœืคืชื™ื—ืช ืžืคืชื—ื•ืช ืœืคืขื ื•ื— ื›ื•ื ืŸ ืžื—ื™ืฆื•ืช ืฉื•ืจืฉ.
  • ืฉื™ืžื•ืฉ ื‘ืฉื‘ื‘ื™ื ื”ืชื•ืžื›ื™ื ื‘ืžืคืจื˜ TPM 2.0, ืขื ื™ื›ื•ืœืช ื—ื–ืจื” ืœืžืขืจื›ื•ืช ืœืœื TPM.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”