
Chapter XXV. Unified Boot
Chelsio Unified Wire for Linux
351
Secure Boot
Secure Boot
, a high-performance computing software solution is a method to restrict which
binaries can be executed to boot the system. With Secure Boot, the system BIOS will only allow
the execution of boot loaders that carry the cryptographic signature of trusted entities. In other
words, anything run in the BIOS must be “signed” with a key that the system knows is trustworthy.
With each reboot of the server, every executed component is verified.
The following example describes the method to enable Secure Boot on HP ProLiant servers.
Steps may differ slightly on other platforms:
i.
During system boot, press F9 to run the
System Utilities
.
ii.
Select
System Configuration
.
iii. Select
BIOS/Platform Configuration (RBSU)
.
iv. Select
Server Security
.
v. Select
Secure Boot Settings
.
vi. Select
Advanced Secure Boot Options
.
vii. Provide the Platform Key (PK), Key Exchange Key (KEK) and Allowed Signature Database
(DB) to the respective uEFI NVRAM variables.
•
Windows
:
▪
PK: Will be generated at the discretion of the platform owner (OEM).
more information.
▪
http://www.microsoft.com/pkiops/certs/MicCorKEKCA2011_2011-06-24.crt
▪
http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-
▪
http://www.microsoft.com/pkiops/certs/MicCorUEFCA2011_2011-06-
▪
Signature GUID for all the above keys: 77fa9abd-0359-4d32-bd60-28f4e78f784b
•
Linux
:
▪
Use the same values for PK, KEK, Windows DB, uEFI DB and Signature ID as
mentioned above.
▪
In addition, provide the following values:
o
chcert.cer:
Provided in ChelsioUwire-x.x.x.x/Uboot/chelsio_key/
o
Signature GUID for chcert.cer: 0b74ace7-6136-a493-19a9-6104d6d1e432
viii. Reboot the system, run
System Utilities
and go to
Secure Boot Settings
.
ix. Select and enable
Secure Boot Enforcement
and reboot the system.
This is not supported in the current release.
Note
Содержание Terminator 6
Страница 1: ...Chelsio Unified Wire for Linux i...
Страница 15: ...Chapter I Chelsio Unified Wire Chelsio Unified Wire for Linux 15 I Chelsio Unified Wire...
Страница 51: ...Chapter II Network NIC TOE Chelsio Unified Wire for Linux 51 II Network NIC TOE...
Страница 70: ...Chapter III Virtual Function Network vNIC Chelsio Unified Wire for Linux 70 III Virtual Function Network vNIC...
Страница 82: ...Chapter IV iWARP RDMA Chelsio Unified Wire for Linux 82 IV iWARP RDMA...
Страница 99: ...Chapter V iSER Chelsio Unified Wire for Linux 99 V iSER...
Страница 107: ...Chapter VI WD UDP Chelsio Unified Wire for Linux 107 VI WD UDP...
Страница 119: ...Chapter VII WD TOE Chelsio Unified Wire for Linux 119 VII WD TOE...
Страница 125: ...Chapter VIII NVMe oF Chelsio Unified Wire for Linux 125 VIII NVMe oF...
Страница 135: ...Chapter IX LIO iSCSI Target Offload Chelsio Unified Wire for Linux 135 IX LIO iSCSI Target Offload...
Страница 148: ...Chapter X iSCSI PDU Offload Target Chelsio Unified Wire for Linux 148 X iSCSI PDU Offload Target...
Страница 187: ...Chapter XI iSCSI PDU Offload Initiator Chelsio Unified Wire for Linux 187 XI iSCSI PDU Offload Initiator...
Страница 198: ...Chapter XII Crypto Offload Chelsio Unified Wire for Linux 198 XII Crypto Offload...
Страница 211: ...Chapter XIII Data Center Bridging DCB Chelsio Unified Wire for Linux 211 XIII Data Center Bridging DCB...
Страница 223: ...Chapter XIV FCoE Full Offload Initiator Chelsio Unified Wire for Linux 223 XIV FCoE Full Offload Initiator...
Страница 230: ...Chapter XIV FCoE Full Offload Initiator Chelsio Unified Wire for Linux 230...
Страница 235: ...Chapter XV Offload Bonding Chelsio Unified Wire for Linux 235 XV Offload Bonding...
Страница 258: ...Chapter XVIII Offload IPv6 Chelsio Unified Wire for Linux 258 XVIII Offload IPv6...
Страница 265: ...Chapter XIX WD Sniffing and Tracing Chelsio Unified Wire for Linux 265 XIX WD Sniffing and Tracing...
Страница 272: ...Chapter XX Classification and Filtering Chelsio Unified Wire for Linux 272 XX Classification and Filtering...
Страница 297: ...Chapter XXI OVS Kernel Datapath Offload Chelsio Unified Wire for Linux 297 XXI OVS Kernel Datapath Offload...
Страница 311: ...Chapter XXII Ring Backbone Chelsio Unified Wire for Linux 311 XXII Ring Backbone...
Страница 317: ...Chapter XXIII Traffic Management Chelsio Unified Wire for Linux 317 XXIII Traffic Management...
Страница 329: ...Chapter XXIV DPDK Driver Chelsio Unified Wire for Linux 329 XXIV DPDK Driver...
Страница 347: ...Chapter XXV Unified Boot Chelsio Unified Wire for Linux 347 XXV Unified Boot...
Страница 357: ...Chapter XXV Unified Boot Chelsio Unified Wire for Linux 357 iv Boot to EFI Shell...
Страница 427: ...Chapter XXVI Appendix A Chelsio Unified Wire for Linux 427 XXVI Appendix A...