ULennart Poettering upapashe isindululo sokuphucula inkqubo yokuqalisa. Linux-Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²ΠΎΠ², Π½Π°ΡΠ΅Π»Π΅Π½Π½ΠΎΠ΅ Π½Π° ΡΠ΅ΡΠ΅Π½ΠΈΠ΅ ΠΈΠΌΠ΅ΡΡΠΈΡ ΡΡ ΠΏΡΠΎΠ±Π»Π΅ΠΌ ΠΈ ΡΠΏΡΠΎΡΠ΅Π½ΠΈΠ΅ ΠΎΡΠ³Π°Π½ΠΈΠ·Π°ΡΠΈΠΈ ΠΏΠΎΠ»Π½ΠΎΡΠ΅Π½Π½ΠΎΠΉ Π²Π΅ΡΠΈΡΠΈΡΠΈΡΠΎΠ²Π°Π½Π½ΠΎΠΉ Π·Π°Π³ΡΡΠ·ΠΊΠΈ, ΠΏΠΎΠ΄ΡΠ²Π΅ΡΠΆΠ΄Π°ΡΡΠ΅ΠΉ Π΄ΠΎΡΡΠΎΠ²Π΅ΡΠ½ΠΎΡΡΡ ΡΠ΄ΡΠ° ΠΈ Π±Π°Π·ΠΎΠ²ΠΎΠ³ΠΎ ΡΠΈΡΡΠ΅ΠΌΠ½ΠΎΠ³ΠΎ ΠΎΠΊΡΡΠΆΠ΅Π½ΠΈΡ. ΠΠ΅ΠΎΠ±Ρ ΠΎΠ΄ΠΈΠΌΡΠ΅ Π΄Π»Ρ ΠΏΡΠΈΠΌΠ΅Π½Π΅Π½ΠΈΡ Π½ΠΎΠ²ΠΎΠΉ Π°ΡΡ ΠΈΡΠ΅ΠΊΡΡΡΡ ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΡ ΡΠΆΠ΅ Π²ΠΊΠ»ΡΡΠ΅Π½Ρ Π² ΠΊΠΎΠ΄ΠΎΠ²ΡΡ Π±Π°Π·Ρ systemd ΠΈ Π·Π°ΡΡΠ°Π³ΠΈΠ²Π°ΡΡ ΡΠ°ΠΊΠΈΠ΅ ΠΊΠΎΠΌΠΏΠΎΠ½Π΅Π½ΡΡ, ΠΊΠ°ΠΊ systemd-stub, systemd-measure, systemd-cryptenroll, systemd-cryptsetup, systemd-pcrphase ΠΈ systemd-creds.
ΠΡΠ΅Π΄Π»ΠΎΠΆΠ΅Π½Π½ΡΠ΅ ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΡ ΡΠ²ΠΎΠ΄ΡΡΡΡ ΠΊ ΡΠΎΠ·Π΄Π°Π½ΠΈΡ Π΅Π΄ΠΈΠ½ΠΎΠ³ΠΎ ΡΠ½ΠΈΠ²Π΅ΡΡΠ°Π»ΡΠ½ΠΎΠ³ΠΎ ΠΎΠ±ΡΠ°Π·Π° UKI (Unified Kernel Image), ΠΎΠ±ΡΠ΅Π΄ΠΈΠ½ΡΡΡΠ΅Π³ΠΎ ΠΎΠ±ΡΠ°Π· ΡΠ΄ΡΠ° Linux, ΠΎΠ±ΡΠ°Π±ΠΎΡΡΠΈΠΊ Π΄Π»Ρ Π·Π°Π³ΡΡΠ·ΠΊΠΈ ΡΠ΄ΡΠ° ΠΈΠ· UEFI (UEFI boot stub) ΠΈ Π·Π°Π³ΡΡΠΆΠ°Π΅ΠΌΠΎΠ΅ Π² ΠΏΠ°ΠΌΡΡΡ ΡΠΈΡΡΠ΅ΠΌΠ½ΠΎΠ΅ ΠΎΠΊΡΡΠΆΠ΅Π½ΠΈΠ΅ initrd, ΠΏΡΠΈΠΌΠ΅Π½ΡΠ΅ΠΌΠΎΠ΅ Π΄Π»Ρ Π½Π°ΡΠ°Π»ΡΠ½ΠΎΠΉ ΠΈΠ½ΠΈΡΠΈΠ°Π»ΠΈΠ·Π°ΡΠΈΠΈ Π½Π° ΡΡΠ°Π΄ΠΈΠΈ Π΄ΠΎ ΠΌΠΎΠ½ΡΠΈΡΠΎΠ²Π°Π½ΠΈΡ ΠΊΠΎΡΠ½Π΅Π²ΠΎΠΉ Π€Π‘. ΠΠΌΠ΅ΡΡΠΎ ΠΎΠ±ΡΠ°Π·Π° RAM-Π΄ΠΈΡΠΊΠ° initrd Π² UKI ΠΌΠΎΠΆΠ΅Ρ Π±ΡΡΡ ΡΠΏΠ°ΠΊΠΎΠ²Π°Π½Π° ΠΈ Π²ΡΡ ΡΠΈΡΡΠ΅ΠΌΠ°, ΡΡΠΎ ΠΏΠΎΠ·Π²ΠΎΠ»ΡΠ΅Ρ ΡΠΎΠ·Π΄Π°Π²Π°ΡΡ ΠΏΠΎΠ»Π½ΠΎΡΡΡΡ Π²Π΅ΡΠΈΡΠΈΡΠΈΡΠΎΠ²Π°Π½Π½ΡΠ΅ ΡΠΈΡΡΠ΅ΠΌΠ½ΡΠ΅ ΠΎΠΊΡΡΠΆΠ΅Π½ΠΈΡ, Π·Π°Π³ΡΡΠΆΠ°Π΅ΠΌΡΠ΅ Π² ΠΎΠΏΠ΅ΡΠ°ΡΠΈΠ²Π½ΡΡ ΠΏΠ°ΠΌΡΡΡ. UKI-ΠΎΠ±ΡΠ°Π· ΠΎΡΠΎΡΠΌΠ»ΡΠ΅ΡΡΡ Π² Π²ΠΈΠ΄Π΅ ΠΈΡΠΏΠΎΠ»Π½ΡΠ΅ΠΌΠΎΠ³ΠΎ ΡΠ°ΠΉΠ»Π° Π² ΡΠΎΡΠΌΠ°ΡΠ΅ PE, ΠΊΠΎΡΠΎΡΡΠΉ ΠΌΠΎΠΆΠ΅Ρ Π±ΡΡΡ Π·Π°Π³ΡΡΠΆΠ΅Π½ Π½Π΅ ΡΠΎΠ»ΡΠΊΠΎ ΠΏΡΠΈ ΠΏΠΎΠΌΠΎΡΠΈ ΡΡΠ°Π΄ΠΈΡΠΈΠΎΠ½Π½ΡΡ Π·Π°Π³ΡΡΠ·ΡΠΈΠΊΠΎΠ², ΠΈ Π½Π°ΠΏΡΡΠΌΡΡ Π²ΡΠ·Π²Π°Π½ ΠΈΠ· ΠΏΡΠΎΡΠΈΠ²ΠΊΠΈ UEFI.
Ukukwazi ukufowuna kwi-UEFI kukuvumela ukuba usebenzise i-digital signature integrity check engabandakanyi kuphela i-kernel, kodwa kunye nemixholo ye-initrd. Kwangaxeshanye, inkxaso yokufowuna ukusuka kwizilayishi zemveli zemveli ikuvumela ukuba ugcine izinto ezinje njengokuhanjiswa kweenguqulelo ezininzi zekernel kunye nokubuyela umva ngokuzenzekelayo kwikernel esebenzayo ukuba iingxaki zichongiwe ngekernel entsha emva kokufaka uhlaziyo.
Π Π½Π°ΡΡΠΎΡΡΠ΅Π΅ Π²ΡΠ΅ΠΌΡ Π² Π±ΠΎΠ»ΡΡΠΈΠ½ΡΡΠ²Π΅ Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²ΠΎΠ² Linux Π² ΠΏΡΠΎΡΠ΅ΡΡΠ΅ ΠΈΠ½ΠΈΡΠΈΠ°Π»ΠΈΠ·Π°ΡΠΈΠΈ ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΠ΅ΡΡΡ ΡΠ΅ΠΏΠΎΡΠΊΠ° Β«ΠΏΡΠΎΡΠΈΠ²ΠΊΠ° β Π·Π°Π²Π΅ΡΠ΅Π½Π½Π°Ρ ΡΠΈΡΡΠΎΠ²ΠΎΠΉ ΠΏΠΎΠ΄ΠΏΠΈΡΡΡ Microsoft shim-ΠΏΡΠΎΡΠ»ΠΎΠΉΠΊΠ° β Π·Π°Π²Π΅ΡΠ΅Π½Π½ΡΠΉ ΡΠΈΡΡΠΎΠ²ΠΎΠΉ ΠΏΠΎΠ΄ΠΏΠΈΡΡΡ Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²Π° Π·Π°Π³ΡΡΠ·ΡΠΈΠΊ GRUB β Π·Π°Π²Π΅ΡΠ΅Π½Π½ΠΎΠ΅ ΡΠΈΡΡΠΎΠ²ΠΎΠΉ ΠΏΠΎΠ΄ΠΏΠΈΡΡΡ Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²Π° ΡΠ΄ΡΠΎ Linux β Π½Π΅ Π·Π°Π²Π΅ΡΠ΅Π½Π½ΠΎΠ΅ ΠΎΠΊΡΡΠΆΠ΅Π½ΠΈΠ΅ initrd β ΠΊΠΎΡΠ½Π΅Π²Π°Ρ Π€Π‘Β». ΠΡΡΡΡΡΡΠ²ΠΈΠ΅ Π²Π΅ΡΠΈΡΠΈΠΊΠ°ΡΠΈΠΈ initrd Π² ΡΡΠ°Π΄ΠΈΡΠΈΠΎΠ½Π½ΡΡ Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²Π°Ρ ΡΠΎΠ·Π΄Π°ΡΡ ΠΏΡΠΎΠ±Π»Π΅ΠΌΡ Ρ Π±Π΅Π·ΠΎΠΏΠ°ΡΠ½ΠΎΡΡΡΡ, ΡΠ°ΠΊ ΠΊΠ°ΠΊ ΡΡΠ΅Π΄ΠΈ ΠΏΡΠΎΡΠ΅Π³ΠΎ Π² Π΄Π°Π½Π½ΠΎΠΌ ΠΎΠΊΡΡΠΆΠ΅Π½ΠΈΠΈ ΠΎΡΡΡΠ΅ΡΡΠ²Π»ΡΠ΅ΡΡΡ ΠΈΠ·Π²Π»Π΅ΡΠ΅Π½ΠΈΠ΅ ΠΊΠ»ΡΡΠ΅ΠΉ Π΄Π»Ρ ΡΠ°ΡΡΠΈΡΡΠΎΠ²ΠΊΠΈ ΠΊΠΎΡΠ½Π΅Π²ΠΎΠΉ Π€Π‘.
Ukuqinisekiswa komfanekiso we-initrd akuxhaswanga kuba le fayile yenziwe kwinkqubo yendawo yomsebenzisi kwaye ayinakuqinisekiswa ngotyikityo lwedijithali lwekhithi yokuhambisa, enzima kakhulu umbutho wokuqinisekisa xa usebenzisa imo yeSecureBoot (ukuqinisekisa i-initrd, i umsebenzisi ufuna ukwenza ezabo izitshixo kwaye azilayishe kwi-firmware ye-UEFI). Ukongezelela, umbutho wangoku we-boot awuvumeli ukusetyenziswa kolwazi oluvela kwi-TPM PCR (iRejista yoLungiselelo lwePlatform) ukulawula ingqibelelo yamacandelo esithuba somsebenzisi ngaphandle kwe-shim, i-grub kunye ne-kernel. Phakathi kweengxaki ezikhoyo, ubunzima bokuhlaziya i-bootloader kunye nokungakwazi ukukhawulela ukufikelela kwizitshixo kwi-TPM kwiinguqulelo ezindala ze-OS eziye zangabalulekanga emva kokufaka ukuhlaziywa nazo zikhankanyiwe.
Iinjongo eziphambili zokwazisa uyilo olutsha lokulayisha zezi:
- Ukubonelela ngenkqubo ye-boot eqinisekisiwe ngokupheleleyo esuka kwi-firmware ukuya kwindawo yomsebenzisi, eqinisekisa ukunyaniseka kunye nokunyaniseka kwamacandelo alayishwayo.
- Ukudibanisa izixhobo ezilawulwayo kwiirejista ze-TPM zePCR, ezahlulwe ngumnini.
- Ukukwazi ukubala kwangaphambili amaxabiso ePCR ngokusekwe kwikernel, initrd, uqwalaselo kunye ne-ID yenkqubo yendawo esetyenziswa ngexesha lokuqalisa.
- Ukukhuselwa kuhlaselo lokubuyela emva olunxulunyaniswa nokubuyela umva kuguqulelo olusesichengeni lwangaphambili lwenkqubo.
- Yenza lula kwaye wandise ukuthembeka kohlaziyo.
- Inkxaso yohlaziyo lwe-OS olungadingi ukuphinda kufakwe isicelo okanye unikezelo lwasekhaya lwezibonelelo ezikhuselweyo zeTPM.
- Inkqubo ilungele ukuqinisekiswa okude ukuze kuqinisekiswe ukuchaneka kwe-OS elayishiweyo kunye nezicwangciso.
- Ukukwazi ukuncamathela idata enovakalelo kwizigaba ezithile zokuqalisa, umzekelo, ukukhupha izitshixo zoguqulelo oluntsonkothileyo kwinkqubo yefayile yengcambu kwi TPM.
- Ukubonelela ngenkqubo ekhuselekileyo, ezenzekelayo, kunye nengahlawulelwayo yomsebenzisi yokuvula izitshixo zokususa uguqulelo lwenkqubo yokwahlula iingcambu.
- Ukusetyenziswa kweetshiphusi ezixhasa ukucaciswa kwe-TPM 2.0, kunye nokukwazi ukubuyela umva kwiinkqubo ngaphandle kwe-TPM.
umthombo: opennet.ru
