From nobody Wed Apr 1 20:43:13 2026 Received: from out162-62-57-137.mail.qq.com (out162-62-57-137.mail.qq.com [162.62.57.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1AA1233EC; Wed, 1 Apr 2026 15:40:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=162.62.57.137 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775058041; cv=none; b=PX3TooNwbJk9wBJnU34YRr8Q80qCDfW2qFahN5espsEQgNUcrvbGocFrawi0kJVlM65obkuOkwW9IpGPsrxiZue+DP7rUoqgf1kQyeXvDOA2dDkDMUPyUPdxA+di3/Jxb9k+L2edABB5pwCMpcPgGkWk9dANl3THVAre4ol6Kgw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775058041; c=relaxed/simple; bh=/mo8BlYMWxHMWWMEK3uiP8ASEHyV3MvEv0DurQfXpW4=; h=Message-ID:From:To:Cc:Subject:Date:MIME-Version:Content-Type; b=BLfspR+XXuHezsW3eGpH9yk/QPiZB1pTfAjw6n5QXI50f/7YJXroD4+hkkE68eC75einwOO0DqfQqV9Yrg1WvDJrSqCDwidPKtSeqfYIT6VXuvUiF4mGeGk58RXqYkS7y3ll2HtmbsBDwaLShiUwtAGAWIsLT2teB/rKG8/8Llk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com; spf=pass smtp.mailfrom=qq.com; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b=ZWoMPif2; arc=none smtp.client-ip=162.62.57.137 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=qq.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b="ZWoMPif2" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1775058028; bh=H/yX2y70+ohfznGw7PFruocS8svbZsUW54HT61f+J5w=; h=From:To:Cc:Subject:Date; b=ZWoMPif29D6G+gvOQp9q6ap6XghLOV0qnb/cNIQZBAM12ZfoaRN2FCqyG6cyjpQhE VelzLR5ayz+MNSGW3ScBk9S00R0EaVfB0zHo/Qlz6Em1DxUHTFbX7wxWrHJ/JNpMe4 YJ4QT2X7JY+2VjokbeAD1x8Cdly9NNFxr5DbfCcI= Received: from localhost.localdomain.localdomain ([27.38.232.100]) by newxmesmtplogicsvrszb51-0.qq.com (NewEsmtp) with SMTP id A1939A4E; Wed, 01 Apr 2026 23:40:25 +0800 X-QQ-mid: xmsmtpt1775058025tk9y8ku22 Message-ID: X-QQ-XMAILINFO: OIkr59++0f4QMUAflFST4X9aQsTRPXuxdV5j7LJ2DIOac2Bh0D0WdbvEigfHuK w04v9Q5FCTINVuSKSXagTw/h1MToQec0o36beolprPNT2onuMha4cWeW4dZmy+LNVjiZNwngk2+h zLKczHe8oh+r12hXyU1wBg81H2PB23BeGQ3kHA2BjqNjvIB2daYaY2xxKsFpJ8AIVR3twWE+Ze86 X2UZnmvpsEj0KeUh7yfJV1P8jG6zboc0EC3KKXS0XYOG97PdVWVwQo9Ny111y7n2Vetbbe3OTzys bqB67gJhAdbIEzjLK5X5a7r/keUtXN89IW3c8c6gbFD9EDu3DKJ6aesE8tURP0cIiW0eu50KmG2q VcTPCK+UBGXfaD0aBY+Hp3BAH6RnQJvxHeUiiBJ2P+lfAR2b5/UM1VufaIFXwbWkz4axUH/ETOty Xm5szRZK/lYRWwhymAdKD45yhE6dCrhfmV8LgRmF2vuIJZRpHIibTaCWVgACeqRFHccURTCr2QB3 6lrkeqv+T0xjMPwotWORK9ep5WR1BVFTa9iHXz5pLqnsTI4gI3zAE7wGrISCHXl875zVZ0R2bWRo F8cMr063sHs6vxeywZP6Mia28kUQBPwyZ9FYDJ1GxeMhu70myh5eO6stf60LK2oaJkEGbqQ2aoLM MRkJLbHdUcb65fkgax9vQE6pgnMwJC1cH9TSziM2LkbQiXFAGaJRYkTlW9HWr/reK109FTteGAvL 2yNykjS+X5r0G/wmCO6djjWF3DddosyN8sc4WSZP6aRK2A7ZrQGxY1K6zAP+oWUYzConb3uAH79Z ST7yPlPV5XvnpGhojemRY09qBPGtUdYdMaLZ5+9nd1MT7y6UgUA9I0uI3DAuSNLclt9CqDrRkzvb 2/y0GdonE5JXMqSJcavrFcn1syjsx08Rh5R+qqxPkgzcvgC6BP0dbCaKOPh6v+6cXk85SawusA0l o9Ar+ASB//kXwmeDJPijvqgiWRrTvCrHuQ+ropvrOZ2ZpDpxMF1lBcdOx1YxNxxPyfZDl7zk9ZY6 iO/HaGg2/E1wTSzWM55fCNBlsdBjH4PWv5HU6ggHFzXnyANDZaR0VlfFgzgK4a1ntCnLXJc+p/xl bpjQUONyfuHufJCBJNSg57eEFkxDlAF7KJC6RP/bDEi6LmpdqbOy+9zO248klDqS5iDxKK X-QQ-XMRINFO: NS+P29fieYNwqS3WCnRCOn9D1NpZuCnCRA== From: Yan Zhu To: alexs@kernel.org, si.yanteng@linux.dev, corbet@lwn.net Cc: dzm91@hust.edu.cn, skhan@linuxfoundation.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, zhuyan2015@qq.com Subject: [PATCH] docs/zh_CN: add module-signing Chinese translation Date: Wed, 1 Apr 2026 23:40:07 +0800 X-OQ-MSGID: <20260401154009.12720-1-zhuyan2015@qq.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Translate .../admin-guide/module-signing.rst into Chinese. Update the translation through commit 0ad9a71933e7 ("modsign: Enable ML-DSA module signing") Signed-off-by: Yan Zhu --- .../zh_CN/admin-guide/module-signing.rst | 242 ++++++++++++++++++ 1 file changed, 242 insertions(+) create mode 100644 Documentation/translations/zh_CN/admin-guide/module-sig= ning.rst diff --git a/Documentation/translations/zh_CN/admin-guide/module-signing.rs= t b/Documentation/translations/zh_CN/admin-guide/module-signing.rst new file mode 100644 index 000000000000..b8c209dd229d --- /dev/null +++ b/Documentation/translations/zh_CN/admin-guide/module-signing.rst @@ -0,0 +1,242 @@ +.. SPDX-License-Identifier: GPL-2.0 +.. include:: ../disclaimer-zh_CN.rst + +:Original: Documentation/admin-guide/module-signing.rst +:=E7=BF=BB=E8=AF=91: + =E6=9C=B1=E5=B2=A9 Yan Zhu + + +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D +=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D + +.. =E7=9B=AE=E5=BD=95 +.. +.. - =E6=A6=82=E8=BF=B0 +.. - =E9=85=8D=E7=BD=AE=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D +.. - =E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=E5=AF=86=E9=92=A5 +.. - =E5=86=85=E6=A0=B8=E4=B8=AD=E7=9A=84=E5=85=AC=E9=92=A5 +.. - =E6=A8=A1=E5=9D=97=E6=89=8B=E5=8A=A8=E7=AD=BE=E5=90=8D +.. - =E5=B7=B2=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97=E5=92=8C=E5=89=A5=E7=A6= =BB +.. - =E5=8A=A0=E8=BD=BD=E5=B7=B2=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97 +.. - =E6=97=A0=E6=95=88=E7=AD=BE=E5=90=8D=E5=92=8C=E6=9C=AA=E7=AD=BE=E5=90= =8D=E6=A8=A1=E5=9D=97 +.. - =E7=AE=A1=E7=90=86/=E4=BF=9D=E6=8A=A4=E7=A7=81=E9=92=A5 + + +=E6=A6=82=E8=BF=B0 +=3D=3D=3D=3D + +=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6= =E5=9C=A8=E5=AE=89=E8=A3=85=E8=BF=87=E7=A8=8B=E4=B8=AD=E5=AF=B9=E6=A8=A1=E5= =9D=97=E8=BF=9B=E8=A1=8C=E5=8A=A0=E5=AF=86=E7=AD=BE=E5=90=8D=EF=BC=8C=E7=84= =B6=E5=90=8E=E5=9C=A8=E5=8A=A0=E8=BD=BD=E6=A8=A1=E5=9D=97=E6=97=B6=E6=A3=80= =E6=9F=A5=E7=AD=BE=E5=90=8D=E3=80=82 +=E8=BF=99=E9=80=9A=E8=BF=87=E7=A6=81=E6=AD=A2=E5=8A=A0=E8=BD=BD=E6=9C=AA= =E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E6=88=96=E4=BD=BF=E7=94=A8=E6= =97=A0=E6=95=88=E5=AF=86=E9=92=A5=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D= =97=E6=9D=A5=E6=8F=90=E9=AB=98=E5=86=85=E6=A0=B8=E5=AE=89=E5=85=A8=E6=80=A7= =E3=80=82 +=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E9=80=9A=E8=BF=87=E4=BD=BF=E6=81=B6= =E6=84=8F=E6=A8=A1=E5=9D=97=E6=9B=B4=E9=9A=BE=E5=8A=A0=E8=BD=BD=E5=88=B0=E5= =86=85=E6=A0=B8=E4=B8=AD=E6=9D=A5=E5=A2=9E=E5=8A=A0=E5=AE=89=E5=85=A8=E6=80= =A7=E3=80=82 +=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=A3=80=E6=9F=A5=E5=9C=A8=E5=86=85= =E6=A0=B8=E4=B8=AD=E5=AE=8C=E6=88=90=EF=BC=8C=E5=9B=A0=E6=AD=A4=E4=B8=8D=E9= =9C=80=E8=A6=81=E5=8F=97=E4=BF=A1=E4=BB=BB=E7=9A=84=E7=94=A8=E6=88=B7=E7=A9= =BA=E9=97=B4=E4=BD=8D=E3=80=82 + +=E6=AD=A4=E6=9C=BA=E5=88=B6=E4=BD=BF=E7=94=A8 X.509 ITU-T =E6=A0=87=E5=87= =86=E8=AF=81=E4=B9=A6=E5=AF=B9=E6=B6=89=E5=8F=8A=E7=9A=84=E5=85=AC=E9=92=A5= =E8=BF=9B=E8=A1=8C=E7=BC=96=E7=A0=81=E3=80=82 +=E7=AD=BE=E5=90=8D=E6=9C=AC=E8=BA=AB=E4=B8=8D=E4=BB=A5=E4=BB=BB=E4=BD=95= =E5=B7=A5=E4=B8=9A=E6=A0=87=E5=87=86=E7=B1=BB=E5=9E=8B=E7=BC=96=E7=A0=81=E3= =80=82 +=E5=86=85=E7=BD=AE=E6=9C=BA=E5=88=B6=E7=9B=AE=E5=89=8D=E4=BB=85=E6=94=AF= =E6=8C=81 RSA=E3=80=81NIST P-384 ECDSA =E5=92=8C NIST FIPS-204 ML-DSA =E5= =85=AC=E9=92=A5=E7=AD=BE=E5=90=8D=E6=A0=87=E5=87=86=EF=BC=88=E5=B0=BD=E7=AE= =A1=E5=AE=83=E6=98=AF=E5=8F=AF=E6=8F=92=E6=8B=94=E7=9A=84=E5=B9=B6=E5=85=81= =E8=AE=B8=E4=BD=BF=E7=94=A8=E5=85=B6=E4=BB=96=E6=A0=87=E5=87=86=EF=BC=89=E3= =80=82 +=E5=AF=B9=E4=BA=8E RSA =E5=92=8C ECDSA=EF=BC=8C=E5=8F=AF=E4=BB=A5=E4=BD=BF= =E7=94=A8=E7=9A=84=E5=8F=AF=E8=83=BD=E7=9A=84=E5=93=88=E5=B8=8C=E7=AE=97=E6= =B3=95=E6=98=AF=E5=A4=A7=E5=B0=8F=E4=B8=BA 256=E3=80=81384 =E5=92=8C 512 = =E7=9A=84 SHA-2 =E5=92=8C SHA-3=EF=BC=88=E7=AE=97=E6=B3=95=E7=94=B1=E7=AD= =BE=E5=90=8D=E4=B8=AD=E7=9A=84=E6=95=B0=E6=8D=AE=E9=80=89=E6=8B=A9=EF=BC=89= =EF=BC=9B +ML-DSA=E4=BC=9A=E8=87=AA=E8=A1=8C=E8=BF=9B=E8=A1=8C=E5=93=88=E5=B8=8C=E8= =BF=90=E7=AE=97=EF=BC=8C=E4=BD=86=E5=85=81=E8=AE=B8=E4=B8=8ESHA512=E5=93=88= =E5=B8=8C=E7=AE=97=E6=B3=95=E7=BB=93=E5=90=88=E7=94=A8=E4=BA=8E=E7=AD=BE=E5= =90=8D=E5=B1=9E=E6=80=A7=E3=80=82 + +=E9=85=8D=E7=BD=AE=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E9=80=9A=E8=BF=87=E8=BF=9B=E5=85=A5=E5=86=85=E6=A0=B8=E9=85=8D=E7=BD=AE= =E7=9A=84 :menuselection:`Enable Loadable Module Support` =E8=8F=9C=E5=8D= =95=E5=B9=B6=E6=89=93=E5=BC=80=E4=BB=A5=E4=B8=8B=E9=80=89=E9=A1=B9=E6=9D=A5= =E5=90=AF=E7=94=A8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6:: + + CONFIG_MODULE_SIG "Module signature verification" + +=E8=BF=99=E6=9C=89=E5=A4=9A=E4=B8=AA=E5=8F=AF=E7=94=A8=E9=80=89=E9=A1=B9= =EF=BC=9A + + (1) :menuselection:`Require modules to be validly signed` + (``CONFIG_MODULE_SIG_FORCE``) + + =E8=BF=99=E6=8C=87=E5=AE=9A=E4=BA=86=E5=86=85=E6=A0=B8=E5=BA=94=E5=A6= =82=E4=BD=95=E5=A4=84=E7=90=86=E5=85=B6=E5=AF=86=E9=92=A5=E6=9C=AA=E7=9F=A5= =E6=88=96=E6=9C=AA=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E3=80=82 + + =E5=A6=82=E6=9E=9C=E5=85=B3=E9=97=AD=EF=BC=88=E5=8D=B3"=E5=AE=BD=E6= =9D=BE=E6=A8=A1=E5=BC=8F"=EF=BC=89=EF=BC=8C=E5=88=99=E5=85=81=E8=AE=B8=E4= =BD=BF=E7=94=A8=E4=B8=8D=E5=8F=AF=E7=94=A8=E5=AF=86=E9=92=A5=E5=92=8C=E6=9C= =AA=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=EF=BC=8C + =E4=BD=86=E5=86=85=E6=A0=B8=E5=B0=86=E8=A2=AB=E6=A0=87=E8=AE=B0=E4=B8= =BA=E5=8F=97=E6=B1=A1=E6=9F=93=EF=BC=8C=E5=B9=B6=E4=B8=94=E7=9B=B8=E5=85=B3= =E6=A8=A1=E5=9D=97=E5=B0=86=E8=A2=AB=E6=A0=87=E8=AE=B0=E4=B8=BA=E5=8F=97=E6= =B1=A1=E6=9F=93=EF=BC=8C=E6=98=BE=E7=A4=BA=E5=AD=97=E7=AC=A6'E'=E3=80=82 + + =E5=A6=82=E6=9E=9C=E6=89=93=E5=BC=80=EF=BC=88=E5=8D=B3"=E9=99=90=E5= =88=B6=E6=A8=A1=E5=BC=8F"=EF=BC=89=EF=BC=8C=E5=8F=AA=E6=9C=89=E5=85=B7=E6= =9C=89=E6=9C=89=E6=95=88=E7=AD=BE=E5=90=8D=E4=B8=94=E5=8F=AF=E7=94=B1=E5=86= =85=E6=A0=B8=E6=8B=A5=E6=9C=89=E7=9A=84=E5=85=AC=E9=92=A5=E9=AA=8C=E8=AF=81= =E7=9A=84=E6=A8=A1=E5=9D=97=E6=89=8D=E4=BC=9A=E8=A2=AB=E5=8A=A0=E8=BD=BD=E3= =80=82 + =E6=89=80=E6=9C=89=E5=85=B6=E4=BB=96=E6=A8=A1=E5=9D=97=E5=B0=86=E7=94= =9F=E6=88=90=E9=94=99=E8=AF=AF=E3=80=82 + + =E6=97=A0=E8=AE=BA=E6=AD=A4=E5=A4=84=E7=9A=84=E8=AE=BE=E7=BD=AE=E5=A6= =82=E4=BD=95=EF=BC=8C=E5=A6=82=E6=9E=9C=E6=A8=A1=E5=9D=97=E7=9A=84=E7=AD=BE= =E5=90=8D=E5=9D=97=E6=97=A0=E6=B3=95=E8=A7=A3=E6=9E=90=EF=BC=8C=E5=AE=83=E5= =B0=86=E8=A2=AB=E7=9B=B4=E6=8E=A5=E6=8B=92=E7=BB=9D=E3=80=82 + + + (2) :menuselection:`Automatically sign all modules` + (``CONFIG_MODULE_SIG_ALL``) + + =E5=A6=82=E6=9E=9C=E6=89=93=E5=BC=80=E6=AD=A4=E9=80=89=E9=A1=B9=EF=BC= =8C=E5=88=99=E5=9C=A8=E6=9E=84=E5=BB=BA=E7=9A=84 modules_install =E9=98=B6= =E6=AE=B5=E6=9C=9F=E9=97=B4=E5=B0=86=E8=87=AA=E5=8A=A8=E7=AD=BE=E5=90=8D=E6= =A8=A1=E5=9D=97=E3=80=82 + =E5=A6=82=E6=9E=9C=E5=85=B3=E9=97=AD=EF=BC=8C=E5=88=99=E5=BF=85=E9=A1= =BB=E4=BD=BF=E7=94=A8=E4=BB=A5=E4=B8=8B=E5=91=BD=E4=BB=A4=E6=89=8B=E5=8A=A8= =E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97:: + + scripts/sign-file + + + (3) :menuselection:`Which hash algorithm should modules be signed with?` + + =E8=BF=99=E6=8F=90=E4=BE=9B=E4=BA=86=E5=AE=89=E8=A3=85=E9=98=B6=E6=AE= =B5=E5=B0=86=E7=94=A8=E4=BA=8E=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97=E7=9A=84= =E5=93=88=E5=B8=8C=E7=AE=97=E6=B3=95=E9=80=89=E6=8B=A9=EF=BC=9A + + =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D + ``CONFIG_MODULE_SIG_SHA256`` :menuselection:`Sign modules with SHA-256` + ``CONFIG_MODULE_SIG_SHA384`` :menuselection:`Sign modules with SHA-384` + ``CONFIG_MODULE_SIG_SHA512`` :menuselection:`Sign modules with SHA-512` + ``CONFIG_MODULE_SIG_SHA3_256`` :menuselection:`Sign modules with SHA3-256` + ``CONFIG_MODULE_SIG_SHA3_384`` :menuselection:`Sign modules with SHA3-384` + ``CONFIG_MODULE_SIG_SHA3_512`` :menuselection:`Sign modules with SHA3-512` + =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D + + =E6=AD=A4=E5=A4=84=E9=80=89=E6=8B=A9=E7=9A=84=E7=AE=97=E6=B3=95=E4=B9= =9F=E5=B0=86=E8=A2=AB=E6=9E=84=E5=BB=BA=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD= =EF=BC=88=E8=80=8C=E4=B8=8D=E6=98=AF=E4=BD=9C=E4=B8=BA=E6=A8=A1=E5=9D=97=EF= =BC=89=EF=BC=8C + =E4=BB=A5=E4=BE=BF=E4=BD=BF=E7=94=A8=E8=AF=A5=E7=AE=97=E6=B3=95=E7=AD= =BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E5=8F=AF=E4=BB=A5=E5=9C=A8=E4=B8=8D= =E5=AF=BC=E8=87=B4=E5=BE=AA=E7=8E=AF=E4=BE=9D=E8=B5=96=E7=9A=84=E6=83=85=E5= =86=B5=E4=B8=8B=E6=A3=80=E6=9F=A5=E5=85=B6=E7=AD=BE=E5=90=8D=E3=80=82 + + + (4) :menuselection:`File name or PKCS#11 URI of module signing key` + (``CONFIG_MODULE_SIG_KEY``) + + =E5=B0=86=E6=AD=A4=E9=80=89=E9=A1=B9=E8=AE=BE=E7=BD=AE=E4=B8=BA=E9=99= =A4=E9=BB=98=E8=AE=A4=E5=80=BC ``certs/signing_key.pem`` =E4=B9=8B=E5=A4=96= =E7=9A=84=E5=85=B6=E4=BB=96=E5=80=BC=E5=B0=86=E7=A6=81=E7=94=A8=E7=AD=BE=E5= =90=8D=E5=AF=86=E9=92=A5=E7=9A=84=E8=87=AA=E5=8A=A8=E7=94=9F=E6=88=90=EF=BC= =8C + =E5=B9=B6=E5=85=81=E8=AE=B8=E4=BD=BF=E7=94=A8=E6=82=A8=E9=80=89=E6=8B= =A9=E7=9A=84=E5=AF=86=E9=92=A5=E5=AF=B9=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97= =E8=BF=9B=E8=A1=8C=E7=AD=BE=E5=90=8D=E3=80=82 + =E6=8F=90=E4=BE=9B=E7=9A=84=E5=AD=97=E7=AC=A6=E4=B8=B2=E5=BA=94=E6=A0= =87=E8=AF=86=E5=8C=85=E5=90=AB=E7=A7=81=E9=92=A5=E5=8F=8A=E5=85=B6=E5=AF=B9= =E5=BA=94=E7=9A=84 PEM =E6=A0=BC=E5=BC=8F X.509 =E8=AF=81=E4=B9=A6=E7=9A=84= =E6=96=87=E4=BB=B6=EF=BC=8C + =E6=88=96=E8=80=85=E5=9C=A8 OpenSSL ENGINE_pkcs11 =E5=8A=9F=E8=83=BD= =E6=AD=A3=E5=B8=B8=E7=9A=84=E7=B3=BB=E7=BB=9F=E4=B8=8A=EF=BC=8C=E4=BD=BF=E7= =94=A8 RFC7512 =E5=AE=9A=E4=B9=89=E7=9A=84 PKCS#11 URI=E3=80=82 + =E5=9C=A8=E5=90=8E=E4=B8=80=E7=A7=8D=E6=83=85=E5=86=B5=E4=B8=8B=EF=BC= =8CPKCS#11 URI =E5=BA=94=E5=BC=95=E7=94=A8=E8=AF=81=E4=B9=A6=E5=92=8C=E7=A7= =81=E9=92=A5=E3=80=82 + + =E5=A6=82=E6=9E=9C=E5=8C=85=E5=90=AB=E7=A7=81=E9=92=A5=E7=9A=84 PEM = =E6=96=87=E4=BB=B6=E5=B7=B2=E5=8A=A0=E5=AF=86=EF=BC=8C=E6=88=96=E8=80=85 PK= CS#11 =E4=BB=A4=E7=89=8C=E9=9C=80=E8=A6=81 PIN=EF=BC=8C + =E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87 ``KBUILD_SIGN_PIN`` =E5=8F=98=E9= =87=8F=E5=9C=A8=E6=9E=84=E5=BB=BA=E6=97=B6=E6=8F=90=E4=BE=9B=E3=80=82 + + + (5) :menuselection:`Additional X.509 keys for default system keyring` + (``CONFIG_SYSTEM_TRUSTED_KEYS``) + + =E6=AD=A4=E9=80=89=E9=A1=B9=E5=8F=AF=E8=AE=BE=E7=BD=AE=E4=B8=BA=E5=8C= =85=E5=90=AB=E9=99=84=E5=8A=A0=E8=AF=81=E4=B9=A6=E7=9A=84 PEM =E7=BC=96=E7= =A0=81=E6=96=87=E4=BB=B6=E7=9A=84=E6=96=87=E4=BB=B6=E5=90=8D=EF=BC=8C + =E8=BF=99=E4=BA=9B=E8=AF=81=E4=B9=A6=E5=B0=86=E9=BB=98=E8=AE=A4=E5=8C= =85=E5=90=AB=E5=9C=A8=E7=B3=BB=E7=BB=9F=E5=AF=86=E9=92=A5=E7=8E=AF=E4=B8=AD= =E3=80=82 + +=E8=AF=B7=E6=B3=A8=E6=84=8F=EF=BC=8C=E5=90=AF=E7=94=A8=E6=A8=A1=E5=9D=97= =E7=AD=BE=E5=90=8D=E4=BC=9A=E4=B8=BA=E5=86=85=E6=A0=B8=E6=9E=84=E5=BB=BA=E8= =BF=87=E7=A8=8B=E6=B7=BB=E5=8A=A0=E5=AF=B9=E6=89=A7=E8=A1=8C=E7=AD=BE=E5=90= =8D=E5=B7=A5=E5=85=B7=E7=9A=84 OpenSSL =E5=BC=80=E5=8F=91=E5=8C=85=E7=9A=84= =E4=BE=9D=E8=B5=96=E3=80=82 + + +=E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=E5=AF=86=E9=92=A5 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E7=94=9F=E6=88=90=E5=92=8C=E6=A3=80=E6=9F=A5=E7=AD=BE=E5=90=8D=E9=9C=80= =E8=A6=81=E5=8A=A0=E5=AF=86=E5=AF=86=E9=92=A5=E5=AF=B9=E3=80=82=E7=A7=81=E9= =92=A5=E7=94=A8=E4=BA=8E=E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=EF=BC=8C=E7=9B= =B8=E5=BA=94=E7=9A=84=E5=85=AC=E9=92=A5=E7=94=A8=E4=BA=8E=E6=A3=80=E6=9F=A5= =E7=AD=BE=E5=90=8D=E3=80=82 +=E7=A7=81=E9=92=A5=E4=BB=85=E5=9C=A8=E6=9E=84=E5=BB=BA=E6=9C=9F=E9=97=B4= =E9=9C=80=E8=A6=81=EF=BC=8C=E4=B9=8B=E5=90=8E=E5=8F=AF=E4=BB=A5=E5=88=A0=E9= =99=A4=E6=88=96=E5=AE=89=E5=85=A8=E5=AD=98=E5=82=A8=E3=80=82 +=E5=85=AC=E9=92=A5=E8=A2=AB=E6=9E=84=E5=BB=BA=E5=88=B0=E5=86=85=E6=A0=B8= =E4=B8=AD=EF=BC=8C=E4=BB=A5=E4=BE=BF=E5=9C=A8=E5=8A=A0=E8=BD=BD=E6=A8=A1=E5= =9D=97=E6=97=B6=E5=8F=AF=E4=BB=A5=E4=BD=BF=E7=94=A8=E5=AE=83=E6=9D=A5=E6=A3= =80=E6=9F=A5=E7=AD=BE=E5=90=8D=E3=80=82 + +=E5=9C=A8=E6=AD=A3=E5=B8=B8=E6=83=85=E5=86=B5=E4=B8=8B=EF=BC=8C=E5=BD=93 `= `CONFIG_MODULE_SIG_KEY`` =E4=BF=9D=E6=8C=81=E9=BB=98=E8=AE=A4=E5=80=BC=E6= =97=B6=EF=BC=8C +=E5=A6=82=E6=9E=9C=E6=96=87=E4=BB=B6=E4=B8=AD=E4=B8=8D=E5=AD=98=E5=9C=A8= =E5=AF=86=E9=92=A5=E5=AF=B9=EF=BC=8C=E5=86=85=E6=A0=B8=E6=9E=84=E5=BB=BA=E5= =B0=86=E4=BD=BF=E7=94=A8 openssl =E8=87=AA=E5=8A=A8=E7=94=9F=E6=88=90=E6=96= =B0=E7=9A=84=E5=AF=86=E9=92=A5=E5=AF=B9:: + + certs/signing_key.pem + +=E5=9C=A8=E6=9E=84=E5=BB=BA vmlinux =E6=9C=9F=E9=97=B4=EF=BC=88=E5=85=AC= =E9=92=A5=E9=9C=80=E8=A6=81=E6=9E=84=E5=BB=BA=E5=88=B0 vmlinux =E4=B8=AD=EF= =BC=89=E4=BD=BF=E7=94=A8=E5=8F=82=E6=95=B0:: + + certs/x509.genkey + +=E6=96=87=E4=BB=B6=EF=BC=88=E5=A6=82=E6=9E=9C=E5=B0=9A=E4=B8=8D=E5=AD=98= =E5=9C=A8=E4=B9=9F=E4=BC=9A=E7=94=9F=E6=88=90=EF=BC=89=E3=80=82 + +=E5=8F=AF=E4=BB=A5=E5=9C=A8 RSA=EF=BC=88``MODULE_SIG_KEY_TYPE_RSA``=EF=BC= =89=E3=80=81ECDSA=EF=BC=88``MODULE_SIG_KEY_TYPE_ECDSA``=EF=BC=89 +=E5=92=8C ML-DSA=EF=BC=88``MODULE_SIG_KEY_TYPE_MLDSA_*``=EF=BC=89=E4=B9=8B= =E9=97=B4=E9=80=89=E6=8B=A9=E7=94=9F=E6=88=90 RSA 4k=E3=80=81NIST P-384 =E5= =AF=86=E9=92=A5=E5=AF=B9=E6=88=96 ML-DSA 44=E3=80=8165 =E6=88=96 87 =E5=AF= =86=E9=92=A5=E5=AF=B9=E3=80=82 + +=E5=BC=BA=E7=83=88=E5=BB=BA=E8=AE=AE=E6=82=A8=E6=8F=90=E4=BE=9B=E8=87=AA= =E5=B7=B1=E7=9A=84 x509.genkey =E6=96=87=E4=BB=B6=E3=80=82 + +=E6=9C=80=E5=80=BC=E5=BE=97=E6=B3=A8=E6=84=8F=E7=9A=84=E6=98=AF=EF=BC=8C= =E5=9C=A8 x509.genkey =E6=96=87=E4=BB=B6=E4=B8=AD=EF=BC=8Creq_distinguished= _name =E9=83=A8=E5=88=86=E5=BA=94=E4=BB=8E=E9=BB=98=E8=AE=A4=E5=80=BC=E6=9B= =B4=E6=94=B9:: + + [ req_distinguished_name ] + #O =3D Unspecified company + CN =3D Build time autogenerated kernel key + #emailAddress =3D unspecified.user@unspecified.company + +=E7=94=9F=E6=88=90=E7=9A=84 RSA =E5=AF=86=E9=92=A5=E5=A4=A7=E5=B0=8F=E4=B9= =9F=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5=E4=B8=8B=E6=96=B9=E5=BC=8F= =E8=AE=BE=E7=BD=AE:: + + [ req ] + default_bits =3D 4096 + +=E4=B9=9F=E5=8F=AF=E4=BB=A5=E4=BD=BF=E7=94=A8=E4=BD=8D=E4=BA=8E Linux =E5= =86=85=E6=A0=B8=E6=BA=90=E4=BB=A3=E7=A0=81=E6=A0=91=E6=A0=B9=E8=8A=82=E7=82= =B9=E4=B8=AD=E7=9A=84 x509.genkey =E5=AF=86=E9=92=A5=E7=94=9F=E6=88=90=E9= =85=8D=E7=BD=AE=E6=96=87=E4=BB=B6=E5=92=8C openssl =E5=91=BD=E4=BB=A4=E6=89= =8B=E5=8A=A8=E7=94=9F=E6=88=90=E5=85=AC=E9=92=A5/=E7=A7=81=E9=92=A5=E6=96= =87=E4=BB=B6=E3=80=82 +=E4=BB=A5=E4=B8=8B=E6=98=AF=E7=94=9F=E6=88=90=E5=85=AC=E9=92=A5/=E7=A7=81= =E9=92=A5=E6=96=87=E4=BB=B6=E7=9A=84=E7=A4=BA=E4=BE=8B:: + + openssl req -new -nodes -utf8 -sha256 -days 36500 -batch -x509 \ + -config x509.genkey -outform PEM -out kernel_key.pem \ + -keyout kernel_key.pem + +=E7=84=B6=E5=90=8E=E5=8F=AF=E4=BB=A5=E5=B0=86=E7=94=9F=E6=88=90=E7=9A=84 k= ernel_key.pem =E6=96=87=E4=BB=B6=E7=9A=84=E5=AE=8C=E6=95=B4=E8=B7=AF=E5=BE= =84=E5=90=8D=E6=8C=87=E5=AE=9A=E5=9C=A8 ``CONFIG_MODULE_SIG_KEY`` =E9=80=89= =E9=A1=B9=E4=B8=AD=EF=BC=8C +=E5=B9=B6=E4=B8=94=E5=B0=86=E4=BD=BF=E7=94=A8=E5=85=B6=E4=B8=AD=E7=9A=84= =E8=AF=81=E4=B9=A6=E5=92=8C=E5=AF=86=E9=92=A5=E8=80=8C=E4=B8=8D=E6=98=AF=E8= =87=AA=E5=8A=A8=E7=94=9F=E6=88=90=E7=9A=84=E5=AF=86=E9=92=A5=E5=AF=B9=E3=80= =82 + + +=E5=86=85=E6=A0=B8=E4=B8=AD=E7=9A=84=E5=85=AC=E9=92=A5 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E5=86=85=E6=A0=B8=E5=8C=85=E5=90=AB=E4=B8=80=E4=B8=AA=E5=8F=AF=E7=94=B1 r= oot =E6=9F=A5=E7=9C=8B=E7=9A=84=E5=85=AC=E9=92=A5=E7=8E=AF=E3=80=82=E5=AE= =83=E4=BB=AC=E5=9C=A8=E5=90=8D=E4=B8=BA ".builtin_trusted_keys" =E7=9A=84= =E5=AF=86=E9=92=A5=E7=8E=AF=E4=B8=AD=EF=BC=8C +=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5=E4=B8=8B=E6=96=B9=E5=BC=8F= =E6=9F=A5=E7=9C=8B:: + + [root@deneb ~]# cat /proc/keys + ... + 223c7853 I------ 1 perm 1f030000 0 0 keyring .builtin_trust= ed_keys: 1 + 302d2d52 I------ 1 perm 1f010000 0 0 asymmetri Fedora kernel = signing key: d69a84e6bce3d216b979e9505b3e3ef9a7118079: X509.RSA a7118079 [] + +=E9=99=A4=E4=BA=86=E4=B8=93=E9=97=A8=E4=B8=BA=E6=A8=A1=E5=9D=97=E7=AD=BE= =E5=90=8D=E7=94=9F=E6=88=90=E7=9A=84=E5=85=AC=E9=92=A5=E5=A4=96=EF=BC=8C=E8= =BF=98=E5=8F=AF=E4=BB=A5=E5=9C=A8 ``CONFIG_SYSTEM_TRUSTED_KEYS`` =E9=85=8D= =E7=BD=AE=E9=80=89=E9=A1=B9=E5=BC=95=E7=94=A8=E7=9A=84 PEM =E7=BC=96=E7=A0= =81=E6=96=87=E4=BB=B6=E4=B8=AD=E6=8F=90=E4=BE=9B=E5=85=B6=E4=BB=96=E5=8F=97= =E4=BF=A1=E4=BB=BB=E7=9A=84=E8=AF=81=E4=B9=A6=E3=80=82 + +=E6=AD=A4=E5=A4=96=EF=BC=8C=E6=9E=B6=E6=9E=84=E4=BB=A3=E7=A0=81=E5=8F=AF= =E4=BB=A5=E4=BB=8E=E7=A1=AC=E4=BB=B6=E5=AD=98=E5=82=A8=E4=B8=AD=E8=8E=B7=E5= =8F=96=E5=85=AC=E9=92=A5=E5=B9=B6=E5=B0=86=E5=85=B6=E6=B7=BB=E5=8A=A0=EF=BC= =88=E4=BE=8B=E5=A6=82=E4=BB=8E UEFI =E5=AF=86=E9=92=A5=E6=95=B0=E6=8D=AE=E5= =BA=93=EF=BC=89=E3=80=82 + +=E6=9C=80=E5=90=8E=EF=BC=8C=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5= =E4=B8=8B=E6=96=B9=E5=BC=8F=E6=B7=BB=E5=8A=A0=E5=85=B6=E4=BB=96=E5=85=AC=E9= =92=A5:: + + keyctl padd asymmetric "" [.builtin_trusted_keys-ID] <[key-file] + +=E4=BE=8B=E5=A6=82:: + + keyctl padd asymmetric "" 0x223c7853