Lennart Pottering ืคืืจื’ืขืœื™ื™ื’ื˜ ืึท ื ื™ื™ึทืข ืœื™ื ื•ืงืก ื•ื•ืขืจืึทืคื™ื™ื“ ืฉื˜ื™ื•ื•ืœ ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ

Lennart Poettering ื”ืื˜ ืคืืจืขืคื ื˜ืœืขื›ื˜ ืึท ืคืึธืจืฉืœืึธื’ ืฆื• ืคืึทืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื“ืขื ืฉื˜ื™ื•ื•ืœ ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ืœื™ื ื•ืงืก ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ืึทื™ืžืขื“ ืฆื• ืกืึทืœื•ื•ื™ื ื’ ื™ื’ื–ื™ืกื˜ื™ื ื’ ืคึผืจืึธื‘ืœืขืžืก ืื•ืŸ ืกื™ืžืคึผืœืึทืคื™ื™ื™ื ื’ ื“ื™ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืึท ืคื•ืœ ื•ื•ืขืจืึทืคื™ื™ื“ ืฉื˜ื™ื•ื•ืœ ื•ื•ืึธืก ืงืึทื ืคืขืจืžื– ื“ื™ ืจื™ืœื™ื™ืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ื™ ืงืขืจืŸ ืื•ืŸ ื“ื™ ืึทื ื“ืขืจืœื™ื™ื™ื ื’ ืกื™ืกื˜ืขื ืกื•ื•ื™ื•ื•ืข. ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ืคืืจืœืื ื’ื˜ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ ื“ื™ ื ื™ื™ึทืข ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ ื–ืขื ืขืŸ ืฉื•ื™ืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื ืงืึธื“ื‘ืึทืกืข ืื•ืŸ ื•ื•ื™ืจืงืŸ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ืึทื–ืึท ื•ื•ื™ systemd-stub, systemd-mesure, systemd-cryptenroll, systemd-cryptsetup, systemd-pcrphase ืื•ืŸ systemd-creds.

ื“ื™ ืคืืจื’ืขืœื™ื™ื’ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ ืงืึธื›ืŸ ืึทืจืึธืคึผ ืฆื• ื“ืขืจ ืฉืึทืคื•ื ื’ ืคื•ืŸ ืึท ืื™ื™ืŸ ื•ื ื™ื•ื•ืขืจืกืึทืœ ื‘ื™ืœื“ UKI (ื•ื ื™ืคื™ืขื“ ืงืขืจื ืขืœ ื‘ื™ืœื“), ืงืึทืžื‘ื™ื™ื ื™ื ื’ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ื‘ื™ืœื“, ืึท ื”ืึทื ื“ืœืขืจ ืคึฟืึทืจ ืœืึธื•ื“ื™ื ื’ ื“ื™ ืงืขืจืŸ ืคึฟื•ืŸ UEFI (UEFI ืฉื˜ื™ื•ื•ืœ ืฉื˜ื•ืคึผ) ืื•ืŸ ื“ื™ ื™ื ื™ื˜ืจื“ ืกื™ืกื˜ืขื ืกื•ื•ื™ื•ื•ืข ืœืึธื•ื“ื™ื“ ืื™ืŸ ื–ื›ึผืจื•ืŸ, ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ืขืจืฉื˜ ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข ืื™ื™ื“ืขืจ ืžืึทื•ื ื˜ื™ื ื’ ื“ื™ ื•ื•ืึธืจืฆืœ FS. ืึทื ืฉื˜ืึธื˜ ืึทืŸ ื™ื ื™ื˜ืจื“ ื‘ืึทืจืึทืŸ ื“ื™ืกืง ื‘ื™ืœื“, ื“ื™ ื’ืื ืฆืข ืกื™ืกื˜ืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคึผืึทืงื™ื“ื–ืฉื“ ืื™ืŸ UKI, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฉืึทืคึฟืŸ ื’ืึธืจ ื•ื•ืขืจืึทืคื™ื™ื“ ืกื™ืกื˜ืขื ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ืœืึธื•ื“ื™ื“ ืื™ืŸ ื‘ืึทืจืึทืŸ. ื“ื™ UKI ื‘ื™ืœื“ ืื™ื– ืคืึธืจืžืึทื˜ื˜ืขื“ ื•ื•ื™ ืึท ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืข ืื™ืŸ PE ืคึฟืึธืจืžืึทื˜, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœืึธื•ื“ื™ื“ ื ื™ื˜ ื‘ืœื•ื™ื– ืžื™ื˜ ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ ื‘ืึธืึธื˜ืœืึธืึทื“ืขืจืก, ืึธื‘ืขืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขืจื•ืคึฟืŸ ื’ืœื™ื™ึทืš ืคึฟื•ืŸ ื“ื™ UEFI ืคื™ืจืžื•ื•ืึทืจืข.

ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืจื•ืคืŸ ืคึฟื•ืŸ UEFI ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื•ืฆืŸ ืึท ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜ ื˜ืฉืขืง ื•ื•ืึธืก ืงืึธื•ื•ืขืจืก ื ื™ื˜ ื‘ืœื•ื™ื– ื“ื™ ืงืขืจืŸ, ืึธื‘ืขืจ ืื•ื™ืš ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ื™ ื™ื ื™ื˜ืจื“. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืจื•ืคืŸ ืคื•ืŸ ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ ื‘ืึธืึธื˜ืœืึธืึทื“ืขืจืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื”ืึทืœื˜ืŸ ืึทื–ืึท ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื•ื•ื™ ืขืงืกืคึผืจืขืก ืคื•ืŸ ืขื˜ืœืขื›ืข ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ื“ื™ ืงืขืจืŸ ืื•ืŸ ืึธื˜ืึทืžืึทื˜ื™ืง ืจืึธื•ืœื‘ืึทืง ืฆื• ืึท ืืจื‘ืขื˜ืŸ ืงืขืจืŸ ืื•ื™ื‘ ืคึผืจืึธื‘ืœืขืžืก ื–ืขื ืขืŸ ื“ื™ื˜ืขืงื˜ืึทื“ ืžื™ื˜ ื“ื™ ื ื™ื™ึท ืงืขืจืŸ ื ืึธืš ื™ื ืกื˜ืึธืœื™ื ื’ ื“ื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ.

ื“ืขืจื•ื•ื™ื™ึทืœ, ืื™ืŸ ืจื•ื‘ึฟ ืœื™ื ื•ืงืก ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ื“ื™ ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ืคึผืจืึธืฆืขืก ื ื™ืฆื˜ ื“ื™ ืงื™ื™ื˜ "ืคื™ืจืžื•ื•ืึทืจืข โ†’ ื“ื™ื“ื–ืฉืึทื˜ืึทืœื™ ื’ืขื—ืชืžืขื˜ ืžื™ืงืจืึธืกืึธืคื˜ ืฉื™ื ืฉื™ื›ื˜ืข โ†’ GRUB ืฉื˜ื™ื•ื•ืœ ืœืึธื•ื“ืขืจ ื“ื™ื“ื–ืฉืึทื˜ืึทืœื™ ื’ืขื—ืชืžืขื˜ ื“ื•ืจืš ื“ื™ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ โ†’ ื“ื™ื’ื™ื˜ืึทืœ ื’ืขื—ืชืžืขื˜ ืœื™ื ื•ืงืก ืงืขืจืŸ โ†’ ื ื™ื˜-ื’ืขื—ืชืžืขื˜ ื™ื ื™ื˜ืจื“ ืกื•ื•ื™ื•ื•ืข โ†’ ื•ื•ืึธืจืฆืœ FS." ื“ื™ ืคืขืœืŸ ืคื•ืŸ ื™ื ื™ื˜ืจื“ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืื™ืŸ ื‘ืขืงืึทื‘ืึธืœืขื“ื™ืง ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืงืจื™ื™ื™ืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก, ื•ื•ื™ื™ึทืœ, ืฆื•ื•ื™ืฉืŸ ืื ื“ืขืจืข, ืื™ืŸ ื“ืขื ืกื•ื•ื™ื•ื•ืข ื“ื™ ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ ื“ืขืงืจื™ืคึผื˜ื™ื ื’ ื“ื™ ื•ื•ืึธืจืฆืœ ื˜ืขืงืข ืกื™ืกื˜ืขื ื–ืขื ืขืŸ ืจื™ื˜ืจื™ื•ื•ื“.

ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื™ื ื™ื˜ืจื“ ื‘ื™ืœื“ ืื™ื– ื ื™ืฉื˜ ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ ื“ื™ ื˜ืขืงืข ืื™ื– ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืื•ื™ืฃ ื“ื™ ื‘ืึทื ื™ืฆืขืจ 'ืก ื”ื™ื’ืข ืกื™ืกื˜ืขื ืื•ืŸ ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ืกืขืจื˜ืึทืคื™ื™ื“ ืžื™ื˜ ืึท ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ื™ื ื•ื•ืขื ื˜ืึทืจ, ื•ื•ืึธืก ื–ื™ื™ืขืจ ืงืึทืžืคึผืœื™ืงื™ื™ืฅ ื“ื™ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ื•ื•ืขืŸ ืื™ืจ ื ื•ืฆืŸ ื“ื™ SecureBoot ืžืึธื“ืข (ืฆื• ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ื™ื ื™ื˜ืจื“, ื“ื™ ื‘ืึทื ื™ืฆืขืจ ื“ืึทืจืฃ ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ื–ื™ื™ืขืจ ืื™ื™ื’ืขื ืข ืฉืœื™ืกืœืขืŸ ืื•ืŸ ืœืึธื“ืŸ ื–ื™ื™ ืื™ืŸ ื“ื™ UEFI ืคื™ืจืžื•ื•ืึทืจืข). ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ ืงืจืึทื ื˜ ืฉื˜ื™ื•ื•ืœ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ื˜ื•ื˜ ื ื™ืฉื˜ ืœืึธื–ืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ TPM PCR (ืคึผืœืึทื˜ืคืึธืจื ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ ืจืขื“ื–ืฉื™ืกื˜ืขืจ) ืจืขื“ื–ืฉื™ืกื˜ืขืจื– ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜ ืคื•ืŸ ื‘ืึทื ื™ืฆืขืจ ืคึผืœืึทืฅ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ืื ื“ืขืจืข ื•ื•ื™ ืฉื™ื, ื’ืจื•ื‘ ืื•ืŸ ื“ื™ ืงืขืจืŸ. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื™ื’ื–ื™ืกื˜ื™ื ื’ ืคึผืจืึธื‘ืœืขืžืก, ื“ื™ ืงืึทืžืคึผืœืขืงืกื™ื˜ื™ ืคื•ืŸ ืึทืคึผื“ื™ื™ื˜ื™ื ื’ ื“ื™ ื‘ืึธืึธื˜ืœืึธืึทื“ืขืจ ืื•ืŸ ื“ื™ ื™ื ืึทื‘ื™ืœื™ื˜ื™ ืฆื• ื‘ืึทื’ืจืขื ืขืฆืŸ ืึทืงืกืขืก ืฆื• ืฉืœื™ืกืœืขืŸ ืื™ืŸ ื“ื™ TPM ืคึฟืึทืจ ืขืœื˜ืขืจืข ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ื“ื™ ืึทืก ื•ื•ืึธืก ื”ืึธื‘ืŸ ื•ื•ืขืจืŸ ื™ืจืขืœืึทื•ื•ืึทื ื˜ ื ืึธืš ื™ื ืกื˜ืึธืœื™ื ื’ ื“ื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื–ืขื ืขืŸ ืื•ื™ืš ื“ืขืจืžืื ื˜.

ื“ื™ ื”ื•ื™ืคึผื˜ ืฆื™ืœืŸ ืคื•ืŸ ื™ื ื˜ืจืึธื•ื“ื•ืกื™ื ื’ ื“ื™ ื ื™ื™ึทืข ืœืึธื•ื“ื™ื ื’ ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ ื–ืขื ืขืŸ:

  • ืคึผืจืึทื•ื•ื™ื™ื“ื™ื ื’ ืึท ื’ืึธืจ ื•ื•ืขืจืึทืคื™ื™ื“ ืฉื˜ื™ื•ื•ืœ ืคึผืจืึธืฆืขืก ื•ื•ืึธืก ืกืคึผืึทื ืก ืคื•ืŸ ืคื™ืจืžื•ื•ืึทืจืข ืฆื• ื‘ืึทื ื™ืฆืขืจ ืคึผืœืึทืฅ, ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ื’ื™ืœื˜ื™ืงื™ื™ึทื˜ ืื•ืŸ ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜ ืคื•ืŸ ื“ื™ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ื•ื•ืึธืก ื–ืขื ืขืŸ ืœืึธื•ื“ื™ื“.
  • ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืงืึทื ื˜ืจืึธื•ืœื“ ืจืขืกื•ืจืกืŸ ืฆื• TPM PCR ืจืขื“ื–ืฉื™ืกื˜ืขืจื–, ืืคื’ืขืฉื™ื™ื“ื˜ ื“ื•ืจืš ื‘ืึทื–ื™ืฆืขืจ.
  • ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคืึทืจ-ืจืขื›ืขื ืขืŸ PCR ื•ื•ืึทืœื•ืขืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืงืขืจืŸ, ื™ื ื™ื˜ืจื“, ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื•ืŸ ื”ื™ื’ืข ืกื™ืกื˜ืขื ืฉื™ื™ึทืŸ ื’ืขื ื™ืฆื˜ ื‘ืขืฉืึทืก ืฉื˜ื™ื•ื•ืœ.
  • ืฉื•ืฅ ืงืขื’ืŸ ืจืึธื•ืœื‘ืึทืง ืื ืคืืœืŸ ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ืจืึธื•ืœื™ื ื’ ืฆื•ืจื™ืง ืฆื• ืึท ืคืจื™ืขืจื“ื™ืงืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืกื™ืกื˜ืขื.
  • ืคืึทืจืคึผืึธืฉืขื˜ืขืจืŸ ืื•ืŸ ืคืึทืจื’ืจืขืกืขืจืŸ ื“ื™ ืจื™ืœื™ื™ืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ.
  • ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืึทืก ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ื•ื•ืึธืก ื˜ืึธืŸ ื ื™ื˜ ื“ืึทืจืคืŸ ืฉื™ื™ึทืขืš-ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืึธื“ืขืจ ื”ื™ื’ืข ืคึผืจืึทื•ื•ื™ื–ืฉืึทื ื– ืคื•ืŸ TPM-ืคึผืจืึธื˜ืขืงื˜ืขื“ ืจืขืกื•ืจืกืŸ.
  • ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ื’ืจื™ื™ื˜ ืคึฟืึทืจ ื•ื•ื™ื™ึทื˜ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืฆื• ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืจื™ื›ื˜ื™ืง ืคื•ืŸ ื“ื™ ืœืึธื•ื“ื™ื“ ืึทืก ืื•ืŸ ืกืขื˜ื˜ื™ื ื’ืก.
  • ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฆื•ื˜ืฉืขืคึผืขืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื“ืึทื˜ืŸ ืฆื• ื–ื™ื›ืขืจ ืฉื˜ื™ื•ื•ืœ ืกื˜ืึทื’ืขืก, ืœืžืฉืœ, ื™ืงืกื˜ืจืึทืงื˜ื™ื ื’ ืขื ืงืจื™ืคึผืฉืึทืŸ ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ ื“ื™ ื•ื•ืึธืจืฆืœ ื˜ืขืงืข ืกื™ืกื˜ืขื ืคึฟื•ืŸ ื“ื™ TPM.
  • ืคึผืจืึทื•ื•ื™ื™ื“ื™ื ื’ ืึท ื–ื™ื›ืขืจ, ืึธื˜ืึทืžืึทื˜ื™ืง ืื•ืŸ ื‘ืึทื ื™ืฆืขืจ-ืคืจื™ื™ ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ืึทื ืœืึทืงื™ื ื’ ืฉืœื™ืกืœืขืŸ ืฆื• ื“ืขืงืจื™ืคึผื˜ ืึท ื•ื•ืึธืจืฆืœ ืฆืขื˜ื™ื™ืœื•ื ื’ ืคืึธืจ.
  • ื ื™ืฆืŸ ื˜ืฉื™ืคึผืก ื•ื•ืึธืก ืฉื˜ื™ืฆืŸ ื“ื™ TPM 2.0 ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’, ืžื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฆื•ืจื™ืงืงืจื™ื’ืŸ ืฆื• ืกื™ืกื˜ืขืžืขืŸ ืึธืŸ TPM.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’