<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="et">
	<id>https://www.auul.pri.ee/wiki/index.php?action=history&amp;feed=atom&amp;title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF</id>
	<title>UEFI Secure Boot kasutamine virtuaalse riistvaraga OVMF - Redigeerimiste ajalugu</title>
	<link rel="self" type="application/atom+xml" href="https://www.auul.pri.ee/wiki/index.php?action=history&amp;feed=atom&amp;title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF"/>
	<link rel="alternate" type="text/html" href="https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;action=history"/>
	<updated>2026-05-03T18:24:19Z</updated>
	<subtitle>Selle lehekülje redigeerimiste ajalugu</subtitle>
	<generator>MediaWiki 1.39.13</generator>
	<entry>
		<id>https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;diff=749&amp;oldid=prev</id>
		<title>Imre: /* Kernel Lockdown */</title>
		<link rel="alternate" type="text/html" href="https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;diff=749&amp;oldid=prev"/>
		<updated>2023-09-03T15:55:42Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Kernel Lockdown&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;et&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;←Vanem redaktsioon&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Redaktsioon: 3. september 2023, kell 18:55&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;280. rida:&lt;/td&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;280. rida:&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 2: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 2: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 3: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 3: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# dmesg -T | tail -n 4&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[Sun Sep  3 18:17:01 2023] Lockdown: blktrace: debugfs access is restricted; see man kernel_lockdown.7&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[Sun Sep  3 18:17:01 2023] Lockdown: blktrace: debugfs access is restricted; see man kernel_lockdown.7&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[Sun Sep  3 18:17:01 2023] Lockdown: blktrace: debugfs access is restricted; see man kernel_lockdown.7&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[Sun Sep  3 18:17:01 2023] Lockdown: blktrace: debugfs access is restricted; see man kernel_lockdown.7&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Imre</name></author>
	</entry>
	<entry>
		<id>https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;diff=748&amp;oldid=prev</id>
		<title>Imre – 3. september 2023, kell 15:38</title>
		<link rel="alternate" type="text/html" href="https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;diff=748&amp;oldid=prev"/>
		<updated>2023-09-03T15:38:20Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;et&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;←Vanem redaktsioon&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Redaktsioon: 3. september 2023, kell 18:38&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;259. rida:&lt;/td&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;259. rida:&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;info: SetupMode=1 SecureBoot=0 SecureBootEnable=0 CustomMode=0 VendorKeys=1&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;info: SetupMode=1 SecureBoot=0 SecureBootEnable=0 CustomMode=0 VendorKeys=1&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;info: SetupMode=0 SecureBoot=1 SecureBootEnable=1 CustomMode=0 VendorKeys=0&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;info: SetupMode=0 SecureBoot=1 SecureBootEnable=1 CustomMode=0 VendorKeys=0&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===2023 sügis märkused===&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Kernel Lockdown====&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Osutub, et Ubuntu v. 20.04, Debian v. 11 jt käitumisele on iseloomulik, et SB enabled režiimis rakendataks automaatselt 'kernel lockdown'. See avaldub nt selliselt&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# mokutil --sb-state&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;SecureBoot enabled&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# blktrace -a discard -d /dev/vda -o - | blkparse -i -&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thread 1 failed open /sys/kernel/debug/block/vda/trace1: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thread 0 failed open /sys/kernel/debug/block/vda/trace0: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thread 3 failed open /sys/kernel/debug/block/vda/trace3: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thread 2 failed open /sys/kernel/debug/block/vda/trace2: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 0: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 1: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 2: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FAILED to start thread on CPU 3: 1/Operation not permitted&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Imre</name></author>
	</entry>
	<entry>
		<id>https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;diff=746&amp;oldid=prev</id>
		<title>Imre: Uus lehekülg: '===Sissejuhatus===  UEFI Secure Boot ...  ===Tööpõhimõte===  Kui arvutil on Secure Boot UEFI haldusliideses välja lülitatud, siiski saab  * operatsioonisüsteemi seest mokutil abil tegeleda võtmetega * käivitades efishellist MokManager.efi rakendust tegeleda võtmetega  Need käsud grub proptis töötavad sarnaselt nagu linux ja initrd, aga kasutavad 'EFI handover protocol' protokolli   grub&gt; linuxefi ...  grub&gt; initrdefi ...  ===Käivitamine===  Tundub, et Secure B...'</title>
		<link rel="alternate" type="text/html" href="https://www.auul.pri.ee/wiki/index.php?title=UEFI_Secure_Boot_kasutamine_virtuaalse_riistvaraga_OVMF&amp;diff=746&amp;oldid=prev"/>
		<updated>2023-09-03T15:32:53Z</updated>

		<summary type="html">&lt;p&gt;Uus lehekülg: &amp;#039;===Sissejuhatus===  UEFI Secure Boot ...  ===Tööpõhimõte===  Kui arvutil on Secure Boot UEFI haldusliideses välja lülitatud, siiski saab  * operatsioonisüsteemi seest mokutil abil tegeleda võtmetega * käivitades efishellist MokManager.efi rakendust tegeleda võtmetega  Need käsud grub proptis töötavad sarnaselt nagu linux ja initrd, aga kasutavad &amp;#039;EFI handover protocol&amp;#039; protokolli   grub&amp;gt; linuxefi ...  grub&amp;gt; initrdefi ...  ===Käivitamine===  Tundub, et Secure B...&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Uus lehekülg&lt;/b&gt;&lt;/p&gt;&lt;div&gt;===Sissejuhatus===&lt;br /&gt;
&lt;br /&gt;
UEFI Secure Boot ...&lt;br /&gt;
&lt;br /&gt;
===Tööpõhimõte===&lt;br /&gt;
&lt;br /&gt;
Kui arvutil on Secure Boot UEFI haldusliideses välja lülitatud, siiski saab&lt;br /&gt;
&lt;br /&gt;
* operatsioonisüsteemi seest mokutil abil tegeleda võtmetega&lt;br /&gt;
* käivitades efishellist MokManager.efi rakendust tegeleda võtmetega&lt;br /&gt;
&lt;br /&gt;
Need käsud grub proptis töötavad sarnaselt nagu linux ja initrd, aga kasutavad 'EFI handover protocol' protokolli&lt;br /&gt;
&lt;br /&gt;
 grub&amp;gt; linuxefi ...&lt;br /&gt;
 grub&amp;gt; initrdefi ...&lt;br /&gt;
&lt;br /&gt;
===Käivitamine===&lt;br /&gt;
&lt;br /&gt;
Tundub, et Secure Boot võimelise OVMF saab 2016 sügisel Debian v. 9 Stretch paketihaldusest&lt;br /&gt;
&lt;br /&gt;
 # apt-get install ovmf qemu-system-x86 xterm&lt;br /&gt;
&lt;br /&gt;
fail&lt;br /&gt;
&lt;br /&gt;
 /usr/share/qemu/OVMF.fd&lt;br /&gt;
&lt;br /&gt;
Käivitamiseks sobib öelda&lt;br /&gt;
&lt;br /&gt;
 # qemu-system-x86_64 -enable-kvm -pflash /var/tmp/o/OVMF.fd&lt;br /&gt;
&lt;br /&gt;
ja seejärel efi shellis öelda 'exit' ning jõutakse Setup keskkonda.&lt;br /&gt;
&lt;br /&gt;
===QEMU===&lt;br /&gt;
&lt;br /&gt;
PK jt sertifikaatide OVMF.fd tõmmisesse lisamiseks tuleb serdid tekitada (või kopeerida valmis serdid, nt Canonicali oma)&lt;br /&gt;
&lt;br /&gt;
 # TODO&lt;br /&gt;
&lt;br /&gt;
kävitada uefi keskkond&lt;br /&gt;
&lt;br /&gt;
 # qemu-system-x86_64 --enable-kvm -net none -m 384 -pflash /usr/share/qemu/OVMF.fd -hda fat:/home/sb/fat&lt;br /&gt;
&lt;br /&gt;
Kiire ad-hoc virtuaalse arvuti juurutamiseks sobib öelda nt&lt;br /&gt;
&lt;br /&gt;
 # qemu-system-x86_64 --enable-kvm -m 1536 \&lt;br /&gt;
   -drive file=/usr/share/qemu/OVMF.fd,if=pflash \&lt;br /&gt;
   -drive file=/dev/system/root_ubu1604,if=ide \&lt;br /&gt;
   -drive file=ubuntu-16.04-server-amd64.iso,if=ide,media=cdrom \&lt;br /&gt;
   -net nic -net tap,ifname=tap0,script=no,downscript=no&lt;br /&gt;
&lt;br /&gt;
Kasulikud lisamaterjalid&lt;br /&gt;
&lt;br /&gt;
* https://wiki.archlinux.org/index.php/QEMU&lt;br /&gt;
* https://help.ubuntu.com/community/Installation/QemuEmulator&lt;br /&gt;
* https://wiki.debian.org/QEMU&lt;br /&gt;
&lt;br /&gt;
===Signeerimine===&lt;br /&gt;
&lt;br /&gt;
 # apt-get install sbsigntool&lt;br /&gt;
&lt;br /&gt;
failisüsteemi tekivad&lt;br /&gt;
&lt;br /&gt;
* sbverify&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
UEFI muutujate esitamine&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# efi-readvar&lt;br /&gt;
Variable PK, length 1448&lt;br /&gt;
PK: List 0, type X509&lt;br /&gt;
    Signature 0, size 1420, owner f5a96b31-dba0-4faa-a42a-7a0c9832768e&lt;br /&gt;
        Subject:&lt;br /&gt;
            O=Hewlett-Packard Company, OU=Long Lived CodeSigning Certificate, CN=HP UEFI Secure Boot 2013 PK Key&lt;br /&gt;
        Issuer:&lt;br /&gt;
            C=US, O=Hewlett-Packard Company, CN=Hewlett-Packard Printing Device Infrastructure CA&lt;br /&gt;
Variable KEK, length 4310&lt;br /&gt;
KEK: List 0, type X509&lt;br /&gt;
    Signature 0, size 1421, owner f5a96b31-dba0-4faa-a42a-7a0c9832768e&lt;br /&gt;
        Subject:&lt;br /&gt;
            O=Hewlett-Packard Company, OU=Long Lived CodeSigning Certificate, CN=HP UEFI Secure Boot 2013 KEK key&lt;br /&gt;
        Issuer:&lt;br /&gt;
            C=US, O=Hewlett-Packard Company, CN=Hewlett-Packard Printing Device Infrastructure CA&lt;br /&gt;
KEK: List 1, type X509&lt;br /&gt;
    Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b&lt;br /&gt;
        Subject:&lt;br /&gt;
            C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011&lt;br /&gt;
        Issuer:&lt;br /&gt;
            C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root&lt;br /&gt;
KEK: List 2, type X509&lt;br /&gt;
    Signature 0, size 1273, owner 2879c886-57ee-45cc-b126-f92f24f906b9&lt;br /&gt;
        Subject:&lt;br /&gt;
            CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team, emailAddress=build@suse.de&lt;br /&gt;
        Issuer:&lt;br /&gt;
            CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team, emailAddress=build@suse.de&lt;br /&gt;
Variable db, length 5915&lt;br /&gt;
db: List 0, type X509&lt;br /&gt;
    Signature 0, size 1420, owner f5a96b31-dba0-4faa-a42a-7a0c9832768e&lt;br /&gt;
        Subject:&lt;br /&gt;
            O=Hewlett-Packard Company, OU=Long Lived CodeSigning Certificate, CN=HP UEFI Secure Boot 2013 DB key&lt;br /&gt;
        Issuer:&lt;br /&gt;
            C=US, O=Hewlett-Packard Company, CN=Hewlett-Packard Printing Device Infrastructure CA&lt;br /&gt;
db: List 1, type X509&lt;br /&gt;
    Signature 0, size 1572, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b&lt;br /&gt;
        Subject:&lt;br /&gt;
            C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011&lt;br /&gt;
        Issuer:&lt;br /&gt;
            C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root&lt;br /&gt;
db: List 2, type X509&lt;br /&gt;
    Signature 0, size 1515, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b&lt;br /&gt;
        Subject:&lt;br /&gt;
            C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011&lt;br /&gt;
        Issuer:&lt;br /&gt;
            C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010&lt;br /&gt;
db: List 3, type X509&lt;br /&gt;
    Signature 0, size 1296, owner 2879c886-57ee-45cc-b126-f92f24f906b9&lt;br /&gt;
        Subject:&lt;br /&gt;
            CN=SUSE Linux Enterprise Secure Boot Signkey, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team, emailAddress=build@suse.de&lt;br /&gt;
        Issuer:&lt;br /&gt;
            CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team, emailAddress=build@suse.de&lt;br /&gt;
Variable dbx, length 76&lt;br /&gt;
dbx: List 0, type SHA256&lt;br /&gt;
    Signature 0, size 48, owner 00000000-0000-0000-0000-000000000000&lt;br /&gt;
        Hash:6e340b9cffb37a989ca544e6bb780a2c78901d3fb33738768511a30617afa01d&lt;br /&gt;
Variable MokList has no entries&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
kus&lt;br /&gt;
&lt;br /&gt;
* PK - riistvara tootja sertifikaat (O=Hewlett-Packard Company, OU=Long Lived CodeSigning Certificate, CN=HP UEFI Secure Boot 2013 PK Key)&lt;br /&gt;
* KEK - muu hulgas US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
Komplektide salvestamine&lt;br /&gt;
&lt;br /&gt;
 # efi-readvar -v PK -o old_PK.esl&lt;br /&gt;
 # efi-readvar -v KEK -o old_KEK.esl&lt;br /&gt;
 # efi-readvar -v db -o old_db.esl&lt;br /&gt;
 # efi-readvar -v dbx -o old_dbx.esl&lt;br /&gt;
 # mokutil --export&lt;br /&gt;
&lt;br /&gt;
Komplektide kustutamine toimub UEFI Setup keskkonnast, tulemusena&lt;br /&gt;
&lt;br /&gt;
 # efi-readvar &lt;br /&gt;
 Variable PK has no entries&lt;br /&gt;
 Variable KEK has no entries&lt;br /&gt;
 Variable db has no entries&lt;br /&gt;
 Variable dbx has no entries&lt;br /&gt;
 Variable MokList has no entries&lt;br /&gt;
&lt;br /&gt;
GRUB efi rakenduse signeerimine&lt;br /&gt;
&lt;br /&gt;
 # mv /boot/efi/EFI/ubuntu/grubx64.efi /boot/efi/EFI/ubuntu/grubx64-orig.efi&lt;br /&gt;
 # sbsign --key PK.key --cert PK.crt --output /boot/efi/EFI/ubuntu/grubx64.efi /boot/efi/EFI/ubuntu/grubx64-orig.efi&lt;br /&gt;
&lt;br /&gt;
GRUB efi rakenduse kontrollimine&lt;br /&gt;
&lt;br /&gt;
 # sbverify --cert /home/sb/fat/PK.crt /boot/efi/EFI/ubuntu/grubx64.efi &lt;br /&gt;
 Signature verification OK&lt;br /&gt;
&lt;br /&gt;
MOK (Machine's Own Key) ...&lt;br /&gt;
&lt;br /&gt;
.efi rakenduse signeerijate esitamiseks&lt;br /&gt;
&lt;br /&gt;
 # sbverify --verbose /boot/efi/EFI/ubuntu/shimx64.efi &lt;br /&gt;
 warning: data remaining[1170360 vs 1289424]: gaps between PE/COFF sections?&lt;br /&gt;
 image signature issuers:&lt;br /&gt;
  - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011&lt;br /&gt;
 image signature certificates:&lt;br /&gt;
  - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/OU=MOPR/CN=Microsoft Windows UEFI Driver Publisher&lt;br /&gt;
    issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011&lt;br /&gt;
  - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011&lt;br /&gt;
    issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root&lt;br /&gt;
 certificate store:&lt;br /&gt;
 PKCS7 verification failed&lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
Signeeritud faili signatuuri salvestamine&lt;br /&gt;
&lt;br /&gt;
 # sbattach --detach vmlinuz-4.8.0-22-generic.efi.signature vmlinuz-4.8.0-22-generic.efi.signed&lt;br /&gt;
&lt;br /&gt;
Kas secure boot on sisse lülitatud, saab küsida töötavas süsteemis&lt;br /&gt;
&lt;br /&gt;
 # cat /proc/sys/kernel/secure_boot&lt;br /&gt;
 1&lt;br /&gt;
 &lt;br /&gt;
 # cat /proc/sys/kernel/moksbstate_disabled&lt;br /&gt;
 0&lt;br /&gt;
&lt;br /&gt;
 # mokutil --sb-state&lt;br /&gt;
 SecureBoot enabled&lt;br /&gt;
&lt;br /&gt;
GRUB2 efi rakenduse signeerimine&lt;br /&gt;
&lt;br /&gt;
 $ openssl genrsa -out test-key.rsa 2048&lt;br /&gt;
 $ openssl req -new -x509 -sha256 \&lt;br /&gt;
        -subj '/CN=test-key' -key test-key.rsa -out test-cert.pem&lt;br /&gt;
 $ openssl x509 -in test-cert.pem -inform PEM \&lt;br /&gt;
        -out test-cert.der -outform DER&lt;br /&gt;
&lt;br /&gt;
 $ sbsign --key test-key.rsa --cert test-cert.pem \&lt;br /&gt;
        --output grubx64.efi /boot/efi/efi/ubuntu/grubx64.efi&lt;br /&gt;
&lt;br /&gt;
Ubuntu signeeritud grubx64.efi efi rakenduse moodustamine, tekib /boot/efi/EFI/ubuntu/grubx64.efi&lt;br /&gt;
&lt;br /&gt;
 # grub-install --uefi-secure-boot&lt;br /&gt;
&lt;br /&gt;
===MOK===&lt;br /&gt;
&lt;br /&gt;
MOK andmestikust sertifikaadi exportimine&lt;br /&gt;
&lt;br /&gt;
 # mkdir /var/tmp/mok-export&lt;br /&gt;
 # cd /var/tmp/mok-export&lt;br /&gt;
 # mokutil --export&lt;br /&gt;
 # ls -ld&lt;br /&gt;
 16806721      4 -rw-r--r--   1  root     root         1080 Dec 25 00:48 ./MOK-0001.der&lt;br /&gt;
 16806724      4 -rw-r--r--   1  root     root          876 Dec 25 00:48 ./MOK-0002.der&lt;br /&gt;
&lt;br /&gt;
MOK andmestikku sertifikaadi importimine&lt;br /&gt;
&lt;br /&gt;
 # mokutil --import sertifikaadinimi.der&lt;br /&gt;
 input password: xxxx&lt;br /&gt;
 input password again: xxxx&lt;br /&gt;
&lt;br /&gt;
Muudatuse kehtestamiseks tuleb arvutit rebootida ja kui shim.efi rakendus käivitab mok.efi rakendust (nagu ta ikka teeb), siis ta avastab, et laaditud on sertifikaat ja küsib, kas seda kasutada. Tegevus toimib konsoolil. Antud juhul vastata jaatavalt ja seejuures tuleb sisetada sama 'xxxx' parool.&lt;br /&gt;
&lt;br /&gt;
MOK andmestikus olevate sertifikaatide nimekirja küsimine&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# mokutil --list-enrolled | egrep -i 'SHA1|Issuer'&lt;br /&gt;
SHA1 Fingerprint: 76:a0:92:06:58:00:bf:37:69:01:c3:72:cd:55:a9:0e:1f:de:d2:e0&lt;br /&gt;
        Issuer: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority&lt;br /&gt;
SHA1 Fingerprint: 7e:68:65:1d:52:68:5f:7b:f5:8e:a0:1d:78:4d:2f:90:d3:f4:0f:0a&lt;br /&gt;
        Issuer: CN=Fedora Secure Boot CA&lt;br /&gt;
                CA Issuers - URI:https://fedoraproject.org/wiki/Features/SecureBoot&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Misc===&lt;br /&gt;
&lt;br /&gt;
Ubuntu efitools paketis on huvitavaid efi rakendusi, nt KeyTool PK, KEK, DB, DBX ja MOK andmestike haldamiseks&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# dpkg -L efitools | egrep &amp;quot;\.efi$&amp;quot;&lt;br /&gt;
/usr/share/efitools/efi/HelloWorld.efi&lt;br /&gt;
/usr/share/efitools/efi/HashTool.efi&lt;br /&gt;
/usr/share/efitools/efi/Loader.efi&lt;br /&gt;
/usr/share/efitools/efi/UpdateVars.efi&lt;br /&gt;
/usr/share/efitools/efi/PreLoader.efi&lt;br /&gt;
/usr/share/efitools/efi/ReadVars.efi&lt;br /&gt;
/usr/share/efitools/efi/LockDown.efi&lt;br /&gt;
/usr/share/efitools/efi/KeyTool.efi&lt;br /&gt;
/usr/share/efitools/efi/SetNull.efi&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Siin ja seal soovitatakse lähtestada OVMF võtmete komplektid sedasi&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
FS0:\&amp;gt; EnrollDefaultKeys.efi&lt;br /&gt;
info: SetupMode=1 SecureBoot=0 SecureBootEnable=0 CustomMode=0 VendorKeys=1&lt;br /&gt;
info: SetupMode=0 SecureBoot=1 SecureBootEnable=1 CustomMode=0 VendorKeys=0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Kasulikud lisamaterjalid===&lt;br /&gt;
&lt;br /&gt;
* http://resources.infosecinstitute.com/uefi-and-tpm/&lt;br /&gt;
* http://www.tianocore.org/ovmf/&lt;br /&gt;
* https://wiki.ubuntu.com/UEFI/OVMF&lt;br /&gt;
* https://wiki.ubuntu.com/SecurityTeam/SecureBoot&lt;br /&gt;
* http://wiki.qemu.org/Features/PC_System_Flash&lt;br /&gt;
* http://blog.system76.com/post/139138591598/howto-qemu-w-ubuntu-xenial-host-uefi-guest&lt;br /&gt;
* https://prosauce.org/blog/2015/10/31/booting-linux-securely&lt;br /&gt;
* https://docs.fedoraproject.org/en-US/Fedora_Draft_Documentation/0.1/html/UEFI_Secure_Boot_Guide/sect-UEFI_Secure_Boot_Guide-What_is_Secure_Boot-Microsoft_Implementation.html&lt;br /&gt;
* http://bazaar.launchpad.net/~ubuntu-bugcontrol/qa-regression-testing/master/download/head:/canonicalmasterpubli-20121127224415-zwfgigzh3kstgk0g-3/canonical-master-public.der&lt;br /&gt;
* http://www.linuxjournal.com/content/take-control-your-pc-uefi-secure-boot&lt;br /&gt;
* https://www.suse.com/documentation/sled11/book_sle_admin/data/sec_uefi_secboot.html&lt;br /&gt;
* https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Configuring_Secure_Boot&lt;br /&gt;
* http://www.linuxquestions.org/questions/slackware-14/slackware64-14-1-uefi-booting-with-secure-boot-enabled-4175532990/&lt;br /&gt;
* https://www.hpe.com/h20195/V2/getpdf.aspx/4AA5-4496ENW.pdf&lt;br /&gt;
* https://wiki.ubuntu.com/UEFI/SecureBoot/DKMS&lt;br /&gt;
* https://en.opensuse.org/openSUSE:UEFI_Secure_boot_using_qemu-kvm&lt;br /&gt;
* https://fedoraproject.org/wiki/Using_UEFI_with_QEMU&lt;br /&gt;
* http://vfio.blogspot.com.ee/2014/09/ovmf-split-image-support.html&lt;br /&gt;
* http://www.labbott.name/blog/2016/09/15/secure-ish-boot-with-qemu/&lt;br /&gt;
* https://ruderich.org/simon/notes/secure-boot-with-grub-and-signed-linux-and-initrd&lt;br /&gt;
* https://github.com/JohnstonJ/ubuntu-secure-boot&lt;br /&gt;
* https://forums.virtualbox.org/viewtopic.php?f=7&amp;amp;t=77363&amp;amp;start=15 - tuuma mooduli juurutamise kohta hea thread&lt;br /&gt;
* https://sourceware.org/systemtap/wiki/SecureBoot&lt;br /&gt;
* http://www.linux-magazine.com/index.php/layout/set/print/Issues/2014/164/The-State-of-Secure-Boot/(tagID)/154&lt;/div&gt;</summary>
		<author><name>Imre</name></author>
	</entry>
</feed>