Rev 1.8
32
Mellanox Technologies
For more information on the script usage, you can run
mlnx_fpga_updater.sh -h.
5.1.5 UEFI Secure Boot
All kernel modules included in MLNX_OFED for RHEL7 are signed with x.509 key to support
loading the modules when Secure Boot is enabled.
5.1.5.1 Enrolling Mellanox's x.509 Public Key On your Systems
In order to support loading MLNX_OFED drivers when an OS supporting Secure Boot boots on
a UEFI-based system with Secure Boot enabled, the Mellanox x.509 public key should be added
to the UEFI Secure Boot key database and loaded onto the system key ring by the kernel.
Follow these steps below to add the Mellanox's x.509 public key to your system:
Step 1.
Download the x.509 public key.
Step 2.
Add the public key to the MOK list using the mokutil utility.
You will be asked to enter and confirm a password for this MOK enrollment request.
Step 3.
Reboot the system.
The pending MOK key enrollment request will be noticed by
shim.efi
and it will launch
MokManager.efi
to allow you to complete the enrollment from the UEFI console. You will need
to enter the password you previously associated with this request and confirm the enrollment.
Once done, the public key is added to the MOK list, which is persistent. Once a key is in the
MOK list, it will be automatically propagated to the system key ring and subsequent will be
booted when the UEFI Secure Boot is enabled.
Its is recommended to perform firmware and FPGA upgrade on Mellanox Innova IPsec
cards using this script only.
Prior to adding the Mellanox's x.509 public key to your system, please make sure:
• the 'mokutil' package is installed on your system
• the system is booted in UEFI mode
# wget http://www.mellanox.com/downloads/ofed/mlnx_signing_key_pub.der
# mokutil --import mlnx_signing_key_pub.der
To see what keys have been added to the system key ring on the current boot, install the
'keyutils' package and run:
#keyctl list %:.system_keyring
Содержание Innova IPsec
Страница 1: ...Mellanox Technologies www mellanox com Mellanox Innova IPsec Ethernet Adapter Card User Manual Rev 1 8...
Страница 53: ...Specifications Rev 1 8 53 Mellanox Technologies Figure 5 Mechanical Drawing of MNV101512A BCIT 167 65 68 90...
Страница 54: ...Rev 1 8 54 Mellanox Technologies 9 5 Bracket Mechanical Drawing Figure 6 Single Port Tall Bracket 21 6 120 02...
Страница 55: ...Specifications Rev 1 8 55 Mellanox Technologies Figure 7 Single Port Short Bracket 80 3 22 83...