跳转到主内容

Secure Boot Customization Guide

28 页 · 900.53 KB · PDF

Secure Boot Customization Guide

July 2017 L01780-001

Disclaimer

The information contained in this document, including URL, other web site references, and other specification documents are subject to change without notice and are provided for informational purposes only. No licenses concerning any intellectual property are being granted, expressly or impliedly, by the disclosure of the information contained in this document. Furthermore, neither Hewlett Packard nor any of its subsidiaries makes any warranties of any nature regarding the use of the information contained in this document, and thus the entire risk, if any, resulting from the use of information within this document is the sole responsibility of the user. Also, the names of the technologies, actual companies, and products mentioned in this document may be trademarks of their respective owners. Complying with all applicable copyright and trademark laws is the sole responsibility of the user of this document. Without limiting any rights under copyright, no part of this document may be reproduced, stored, or transmitted in any form or by any means without the express written consent of HP Development Company, L.P.

HP Development Company, L.P. or its subsidiaries may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering the subject matter in this document. Except where expressly provided in any written license from HP Development Company, L.P. or its subsidiaries, the furnishing of this document, or any ideas contained within, does not grant any license to these ideas, patents, trademarks, copyrights, or other intellectual property.

Technical whitepaper

Version No.Revised byChanges
0.1Chris StewartInitial Baseline
0.2Chris StewartAugment PK and KEK import procedures to show sample for self-signed keys.
1.0Chris StewartAdd disclaimer
1.1Joe David, Jason AydelotteClarifications and formatting revisions

Table Caption: This table outlines the version history of a document, detailing the version number, who made the revisions, and a summary of the changes implemented in each version.

Table of contents

1 Introduction ...........................................................................................................................7
2 Setting up a customized Secure Boot environment ..............................................................8
2.1 Backup existing Secure Boot configuration .....................................................................................................8
2.2 Place your HP PC in Secure Boot setup mode .................................................................................................9
2.3 Obtain PK and KEK public keys ......................................................................................................................10
2.4 Self-signing certificates .................................................................................................................................10
2.4.1 Generate a new PK ............................................................................................................................11
2.4.2 Generate a new KEK ..........................................................................................................................13
2.5 Install the new PK ..........................................................................................................................................13
2.5.1 PK: Create a valid SetVariable() package ............................................................................................15
2.5.2 Import PK using Windows tools .........................................................................................................15
2.6 Install the new PK-signed KEK .......................................................................................................................16
2.6.1 KEK: Create a valid SetVariable() package ..........................................................................................17
2.6.2 Import KEK Using Windows Tools ......................................................................................................18
2.7 Install the New KEK-signed DB and DBX ........................................................................................................19
2.7.1 DB ......................................................................................................................................................19
2.7.2 DBX ....................................................................................................................................................22
2.8 Enable Secure Boot Once More .....................................................................................................................24
2.9 Add Additional Certificates to DB or DBX .......................................................................................................24
2.9.1 DB ......................................................................................................................................................25
2.9.2 DBX ....................................................................................................................................................27
3 References ..........................................................................................................................28

Table Caption: This table outlines a detailed procedure for setting up a customized Secure Boot environment on an HP PC, covering backup, key generation, installation, and management of Platform Key (PK), Key Exchange Key (KEK), Signature Database (DB), and Forbidden Signature Database (DBX).

List of figures

**Table Caption: This table serves as a detailed index for a document, mapping figure numbers to their titles and corresponding page numbers, likely illustrating steps in a technical process related to Secure Boot configuration. The figures range from initial setup

免费加入 iFixit,阅读完整文档 (28 页)

我们需要您注册一个免费账户,以帮助屏蔽机器人,并确保iFixit始终为人类用户服务。

浏览统计数据:

过去 24 小时: 0

过去 7 天: 1

过去 30 天: 6

总计 68