From nobody Sun Jun 14 06:55:10 2026 Received: from xmbghk7.mail.qq.com (xmbghk7.mail.qq.com [43.163.128.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 30A671624D5; Wed, 22 Apr 2026 15:13:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=43.163.128.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776870787; cv=none; b=W8jmVCTyTkMc7E2brHUIBCLBt6Pt6DW6FOs7UaDCf0nUa6kEZgXwKse12LSTijXkHHZfoyzpBOWTVolR74be58jC3BiFId1ihQAp6xKnNc2mCRrQpdDY1I/taLdwjRWYtNlbTvbk74cbB9xEIAgitThu4jXstsjyFXByJGGOPJA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776870787; c=relaxed/simple; bh=WDQjtfVm4zj/Vig9Dz2w6ywdnOiFMcv6pewQEVUZMI4=; h=Message-ID:From:To:Cc:Subject:Date:MIME-Version:Content-Type; b=AgQauBLrdlwDb+KZYd+apCRsFBvP3bXgpNzRVe+RKYfZPluQxebWeMMYEbAHX6CTH2Pc2710/6fbtB/T8kup+m8acOSW2dMSe5CSQGFvq4n961CC8NxXYE85cIWWIEPG49tLK58igqIBEEZFG+TtE7IT+4i/ndNqRARisozCjJw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com; spf=pass smtp.mailfrom=qq.com; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b=C1Cm/Lp3; arc=none smtp.client-ip=43.163.128.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=qq.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b="C1Cm/Lp3" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1776870774; bh=Y5DcVm/eGuMpyBHKegrITty4mu3Dzcw4Y2Pwvcs/9Yw=; h=From:To:Cc:Subject:Date; b=C1Cm/Lp3Ss+WAPd7xmSfpX7R5UIyVCuiXXtsfSrrRbzYIqOBcoY8nECWhX3MirANd dVRbu3M5HAhvF+niO+4B4jQYMX8mTL52K7GRxZ9tN08XiO/nXgRM4gSj++VUEmIslJ YgClqrKW/m0/gjVmVKGADHyBz6bT9W2CDTpQ9mEI= Received: from localhost.localdomain.localdomain ([163.125.232.153]) by newxmesmtplogicsvrsza53-0.qq.com (NewEsmtp) with SMTP id 3340DE42; Wed, 22 Apr 2026 23:12:52 +0800 X-QQ-mid: xmsmtpt1776870772tqgeg5n6w Message-ID: X-QQ-XMAILINFO: ODQfruXGvXma3BfOqc9Mr04gOn54F5k07Od+/7JYRjDmpPrI7VeEwv4B28zAsd S+VnLVrVfgO2ju9L/vZMXB3Euxi4EPO3kxTmLQaluC2tGz3a6HdR/++eW9U8BJop43JbvsB2TSmf bkLQueXkijH3j9UQgzHMTTp7GHqjIwFMTYQnQjIPyC8jU5wX0pyBYRX1wfQTYjXG6EFQEV1WVP94 rp6eP3LQzfrlf+np/lodB3YWYNS2+jWcMQi3HUk4rWkL81YPdtrL8N3tF8kLhK6NlHxwXFdYLZmd sqsns7SIridM7UrMQubJUZ/3mHkKDcNObMh6V2OeXp3697SZ6oBfkYgR36gCXWm0RG+tUNbHC1wj hUOl+bgsWb2ReuXzQ6XyZ2DW2XIBLbygYzAwGBcvkM2csx4GdkHtOXvJTcb4bZNJLVX9cMrS4NvZ WnmDERKjXm/ztCckv7AJErZeop1lQ0gEVSHmy1xsOxFXnU9aVCxbGHaYiod+r+2CtqrpZnTVDlAu C3W0Fa3sdo13EOr9Vg/XbveHpM2YGR/pvs4FbyYn4GFLIovytwu08E6HLOAH8c7YY0wqAonNbuPE aeysB5cztFmbt17Ex+MsGeYHkER2LODcqLUlOmYrRXXUmNw/hOZp7cC6wWdXkXNRRDPC0d2NSVUF YlytDdLbRWMcuevR2HeGabF+V7iOg7MUYQFk3LkBsWLQOLzqFvjHVi7zFtsIyz14etus4QrNId7P DF4+k0lxHlgRLzoeDmZeSrFji7CqtZI7XqHc5IwOPjDwmJ/ZCbGNUSoVcXbrr1fk2h41gi7pP2c5 wUjRK2Iom1UZISpdR2gDocwX4ckSnhUzYXnaHzzZfnh6xkgL6FOqWZHBujm/GW/b890ZNbDq0wQX 3bjP43UO3xeSQ46sFz+B/xLDRLy4JEFM5CAcW6hupYe6aWpynZX2JBj53OltqNoysDZ6LF0fBG4D gKltQmwni22Vqlh1EA5kiI1JS9ovbQLBNLhr78gnB0uZpdo/xoZeGiCRRUDnlNw6cVKQKP+qUrqA jBaKxRmL2u8w3dveWltpQ3CBwiUtEAlqnJJQviNDiVJjzYs2zk9Mf/feYK25Xg7smbeAg8Tf0FNr BzQM6YAL4GWfgbp/Gq5M9VSF58pM9lIkAjDtHtdy82SOL4lP1fccrl7inT+Bax3NyJluoD/gDrPE YwwgstTSoLYjsgtfvV+FSYJzuaOOvX83nzY+M= X-QQ-XMRINFO: NI4Ajvh11aEjEMj13RCX7UuhPEoou2bs1g== From: Yan Zhu To: seakeel@gmail.com, alexs@kernel.org, si.yanteng@linux.dev, corbet@lwn.net Cc: dzm91@hust.edu.cn, skhan@linuxfoundation.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, lkp@intel.com, zhuyan2015@qq.com Subject: [PATCH v5] docs/zh_CN: add module-signing Chinese translation Date: Wed, 22 Apr 2026 23:11:30 +0800 X-OQ-MSGID: X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Translate .../admin-guide/module-signing.rst into Chinese. Update the translation through commit 0ad9a71933e7 ("modsign: Enable ML-DSA module signing") Reported-by: kernel test robot Closes: https://lore.kernel.org/oe-kbuild-all/202604182216.Qpd5KifK-lkp@int= el.com/ Signed-off-by: Yan Zhu --- v4->v5: Fix the format error of line 157. v3->v4: Add patch change description. v2->v3: Fix line 87 and 94 without tab indentation. v1->v2: Fixed the issue of some lines exceeding 80 characters and alignment. --- --- .../zh_CN/admin-guide/module-signing.rst | 250 ++++++++++++++++++ 1 file changed, 250 insertions(+) create mode 100644 Documentation/translations/zh_CN/admin-guide/module-sig= ning.rst diff --git a/Documentation/translations/zh_CN/admin-guide/module-signing.rs= t b/Documentation/translations/zh_CN/admin-guide/module-signing.rst new file mode 100644 index 000000000000..b5671224f102 --- /dev/null +++ b/Documentation/translations/zh_CN/admin-guide/module-signing.rst @@ -0,0 +1,250 @@ +.. SPDX-License-Identifier: GPL-2.0 +.. include:: ../disclaimer-zh_CN.rst + +:Original: Documentation/admin-guide/module-signing.rst +:=E7=BF=BB=E8=AF=91: + =E6=9C=B1=E5=B2=A9 Yan Zhu + + +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D +=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +.. =E7=9B=AE=E5=BD=95 +.. +.. - =E6=A6=82=E8=BF=B0 +.. - =E9=85=8D=E7=BD=AE=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D +.. - =E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=E5=AF=86=E9=92=A5 +.. - =E5=86=85=E6=A0=B8=E4=B8=AD=E7=9A=84=E5=85=AC=E9=92=A5 +.. - =E6=A8=A1=E5=9D=97=E6=89=8B=E5=8A=A8=E7=AD=BE=E5=90=8D +.. - =E5=B7=B2=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97=E5=92=8C=E5=89=A5=E7=A6= =BB +.. - =E5=8A=A0=E8=BD=BD=E5=B7=B2=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97 +.. - =E6=97=A0=E6=95=88=E7=AD=BE=E5=90=8D=E5=92=8C=E6=9C=AA=E7=AD=BE=E5=90= =8D=E6=A8=A1=E5=9D=97 +.. - =E7=AE=A1=E7=90=86/=E4=BF=9D=E6=8A=A4=E7=A7=81=E9=92=A5 + + +=E6=A6=82=E8=BF=B0 +=3D=3D=3D=3D + +=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6= =E5=9C=A8=E5=AE=89=E8=A3=85=E8=BF=87=E7=A8=8B=E4=B8=AD=E5=AF=B9=E6=A8=A1=E5= =9D=97=E8=BF=9B=E8=A1=8C=E5=8A=A0=E5=AF=86=E7=AD=BE=E5=90=8D=EF=BC=8C=E7=84= =B6=E5=90=8E=E5=9C=A8=E5=8A=A0=E8=BD=BD=E6=A8=A1=E5=9D=97=E6=97=B6=E6=A3=80= =E6=9F=A5=E7=AD=BE=E5=90=8D=E3=80=82=E8=BF=99 +=E9=80=9A=E8=BF=87=E7=A6=81=E6=AD=A2=E5=8A=A0=E8=BD=BD=E6=9C=AA=E7=AD=BE= =E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E6=88=96=E4=BD=BF=E7=94=A8=E6=97=A0=E6= =95=88=E5=AF=86=E9=92=A5=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E6=9D= =A5=E6=8F=90=E9=AB=98=E5=86=85=E6=A0=B8=E5=AE=89=E5=85=A8=E6=80=A7=E3=80=82= =E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E9=80=9A +=E8=BF=87=E4=BD=BF=E6=81=B6=E6=84=8F=E6=A8=A1=E5=9D=97=E6=9B=B4=E9=9A=BE= =E5=8A=A0=E8=BD=BD=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD=E6=9D=A5=E5=A2=9E=E5= =8A=A0=E5=AE=89=E5=85=A8=E6=80=A7=E3=80=82=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90= =8D=E6=A3=80=E6=9F=A5=E5=9C=A8=E5=86=85=E6=A0=B8=E4=B8=AD=E5=AE=8C=E6=88=90= =EF=BC=8C=E5=9B=A0=E6=AD=A4=E4=B8=8D=E9=9C=80 +=E8=A6=81=E5=8F=97=E4=BF=A1=E4=BB=BB=E7=9A=84=E7=94=A8=E6=88=B7=E7=A9=BA= =E9=97=B4=E4=BD=8D=E3=80=82 + +=E6=AD=A4=E6=9C=BA=E5=88=B6=E4=BD=BF=E7=94=A8 X.509 ITU-T =E6=A0=87=E5=87= =86=E8=AF=81=E4=B9=A6=E5=AF=B9=E6=B6=89=E5=8F=8A=E7=9A=84=E5=85=AC=E9=92=A5= =E8=BF=9B=E8=A1=8C=E7=BC=96=E7=A0=81=E3=80=82=E7=AD=BE=E5=90=8D=E6=9C=AC=E8= =BA=AB=E4=B8=8D=E4=BB=A5=E4=BB=BB=E4=BD=95=E5=B7=A5=E4=B8=9A=E6=A0=87=E5=87= =86 +=E7=B1=BB=E5=9E=8B=E7=BC=96=E7=A0=81=E3=80=82=E5=86=85=E7=BD=AE=E6=9C=BA= =E5=88=B6=E7=9B=AE=E5=89=8D=E4=BB=85=E6=94=AF=E6=8C=81 RSA=E3=80=81NIST P-3= 84 ECDSA =E5=92=8C NIST FIPS-204 ML-DSA +=E5=85=AC=E9=92=A5=E7=AD=BE=E5=90=8D=E6=A0=87=E5=87=86=EF=BC=88=E5=B0=BD= =E7=AE=A1=E5=AE=83=E6=98=AF=E5=8F=AF=E6=8F=92=E6=8B=94=E7=9A=84=E5=B9=B6=E5= =85=81=E8=AE=B8=E4=BD=BF=E7=94=A8=E5=85=B6=E4=BB=96=E6=A0=87=E5=87=86=EF=BC= =89=E3=80=82=E5=AF=B9=E4=BA=8E RSA =E5=92=8C ECDSA=EF=BC=8C=E5=8F=AF=E4=BB= =A5=E4=BD=BF +=E7=94=A8=E7=9A=84=E5=8F=AF=E8=83=BD=E7=9A=84=E5=93=88=E5=B8=8C=E7=AE=97= =E6=B3=95=E6=98=AF=E5=A4=A7=E5=B0=8F=E4=B8=BA 256=E3=80=81384 =E5=92=8C 512= =E7=9A=84 SHA-2 =E5=92=8C SHA-3=EF=BC=88=E7=AE=97=E6=B3=95=E7=94=B1=E7=AD= =BE=E5=90=8D=E4=B8=AD=E7=9A=84 +=E6=95=B0=E6=8D=AE=E9=80=89=E6=8B=A9=EF=BC=89=EF=BC=9BML-DSA =E4=BC=9A=E8= =87=AA=E8=A1=8C=E8=BF=9B=E8=A1=8C=E5=93=88=E5=B8=8C=E8=BF=90=E7=AE=97=EF=BC= =8C=E4=BD=86=E5=85=81=E8=AE=B8=E4=B8=8E SHA512 =E5=93=88=E5=B8=8C=E7=AE=97= =E6=B3=95=E7=BB=93=E5=90=88=E7=94=A8=E4=BA=8E=E7=AD=BE=E5=90=8D=E5=B1=9E +=E6=80=A7=E3=80=82 + +=E9=85=8D=E7=BD=AE=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E9=80=9A=E8=BF=87=E8=BF=9B=E5=85=A5=E5=86=85=E6=A0=B8=E9=85=8D=E7=BD=AE= =E7=9A=84 :menuselection:`Enable Loadable Module Support` =E8=8F=9C=E5=8D= =95=E5=B9=B6=E6=89=93 +=E5=BC=80=E4=BB=A5=E4=B8=8B=E9=80=89=E9=A1=B9=E6=9D=A5=E5=90=AF=E7=94=A8= =E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6:: + + CONFIG_MODULE_SIG "Module signature verification" + +=E8=BF=99=E6=9C=89=E5=A4=9A=E4=B8=AA=E5=8F=AF=E7=94=A8=E9=80=89=E9=A1=B9= =EF=BC=9A + + (1) :menuselection:`Require modules to be validly signed` + (``CONFIG_MODULE_SIG_FORCE``) + + =E8=BF=99=E6=8C=87=E5=AE=9A=E4=BA=86=E5=86=85=E6=A0=B8=E5=BA=94=E5=A6= =82=E4=BD=95=E5=A4=84=E7=90=86=E5=85=B6=E5=AF=86=E9=92=A5=E6=9C=AA=E7=9F=A5= =E6=88=96=E6=9C=AA=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E3=80=82 + + =E5=A6=82=E6=9E=9C=E5=85=B3=E9=97=AD=EF=BC=88=E5=8D=B3"=E5=AE=BD=E6= =9D=BE=E6=A8=A1=E5=BC=8F"=EF=BC=89=EF=BC=8C=E5=88=99=E5=85=81=E8=AE=B8=E4= =BD=BF=E7=94=A8=E4=B8=8D=E5=8F=AF=E7=94=A8=E5=AF=86=E9=92=A5=E5=92=8C=E6=9C= =AA=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=EF=BC=8C=E4=BD=86=E5=86=85= =E6=A0=B8=E5=B0=86=E8=A2=AB + =E6=A0=87=E8=AE=B0=E4=B8=BA=E5=8F=97=E6=B1=A1=E6=9F=93=EF=BC=8C=E5=B9= =B6=E4=B8=94=E7=9B=B8=E5=85=B3=E6=A8=A1=E5=9D=97=E5=B0=86=E8=A2=AB=E6=A0=87= =E8=AE=B0=E4=B8=BA=E5=8F=97=E6=B1=A1=E6=9F=93=EF=BC=8C=E6=98=BE=E7=A4=BA=E5= =AD=97=E7=AC=A6'E'=E3=80=82 + + =E5=A6=82=E6=9E=9C=E6=89=93=E5=BC=80=EF=BC=88=E5=8D=B3"=E9=99=90=E5= =88=B6=E6=A8=A1=E5=BC=8F"=EF=BC=89=EF=BC=8C=E5=8F=AA=E6=9C=89=E5=85=B7=E6= =9C=89=E6=9C=89=E6=95=88=E7=AD=BE=E5=90=8D=E4=B8=94=E5=8F=AF=E7=94=B1=E5=86= =85=E6=A0=B8=E6=8B=A5=E6=9C=89=E7=9A=84=E5=85=AC=E9=92=A5=E9=AA=8C=E8=AF=81= =E7=9A=84=E6=A8=A1=E5=9D=97 + =E6=89=8D=E4=BC=9A=E8=A2=AB=E5=8A=A0=E8=BD=BD=E3=80=82=E6=89=80=E6=9C= =89=E5=85=B6=E4=BB=96=E6=A8=A1=E5=9D=97=E5=B0=86=E7=94=9F=E6=88=90=E9=94=99= =E8=AF=AF=E3=80=82 + + =E6=97=A0=E8=AE=BA=E6=AD=A4=E5=A4=84=E7=9A=84=E8=AE=BE=E7=BD=AE=E5=A6= =82=E4=BD=95=EF=BC=8C=E5=A6=82=E6=9E=9C=E6=A8=A1=E5=9D=97=E7=9A=84=E7=AD=BE= =E5=90=8D=E5=9D=97=E6=97=A0=E6=B3=95=E8=A7=A3=E6=9E=90=EF=BC=8C=E5=AE=83=E5= =B0=86=E8=A2=AB=E7=9B=B4=E6=8E=A5=E6=8B=92=E7=BB=9D=E3=80=82 + + + (2) :menuselection:`Automatically sign all modules` + (``CONFIG_MODULE_SIG_ALL``) + + =E5=A6=82=E6=9E=9C=E6=89=93=E5=BC=80=E6=AD=A4=E9=80=89=E9=A1=B9=EF=BC= =8C=E5=88=99=E5=9C=A8=E6=9E=84=E5=BB=BA=E7=9A=84 modules_install =E9=98=B6= =E6=AE=B5=E6=9C=9F=E9=97=B4=E5=B0=86=E8=87=AA=E5=8A=A8=E7=AD=BE=E5=90=8D=E6= =A8=A1=E5=9D=97=E3=80=82 + =E5=A6=82=E6=9E=9C=E5=85=B3=E9=97=AD=EF=BC=8C=E5=88=99=E5=BF=85=E9=A1= =BB=E4=BD=BF=E7=94=A8=E4=BB=A5=E4=B8=8B=E5=91=BD=E4=BB=A4=E6=89=8B=E5=8A=A8= =E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97:: + + scripts/sign-file + + + (3) :menuselection:`Which hash algorithm should modules be signed with?` + + =E8=BF=99=E6=8F=90=E4=BE=9B=E4=BA=86=E5=AE=89=E8=A3=85=E9=98=B6=E6=AE= =B5=E5=B0=86=E7=94=A8=E4=BA=8E=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97=E7=9A=84= =E5=93=88=E5=B8=8C=E7=AE=97=E6=B3=95=E9=80=89=E6=8B=A9=EF=BC=9A + + =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + ``CONFIG_MODULE_SIG_SHA256`` :menuselection:`Sign modules with SHA-256` + ``CONFIG_MODULE_SIG_SHA384`` :menuselection:`Sign modules with SHA-384` + ``CONFIG_MODULE_SIG_SHA512`` :menuselection:`Sign modules with SHA-512` + ``CONFIG_MODULE_SIG_SHA3_256`` :menuselection:`Sign modules with SHA3-256` + ``CONFIG_MODULE_SIG_SHA3_384`` :menuselection:`Sign modules with SHA3-384` + ``CONFIG_MODULE_SIG_SHA3_512`` :menuselection:`Sign modules with SHA3-512` + =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + + =E6=AD=A4=E5=A4=84=E9=80=89=E6=8B=A9=E7=9A=84=E7=AE=97=E6=B3=95=E4=B9= =9F=E5=B0=86=E8=A2=AB=E6=9E=84=E5=BB=BA=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD= =EF=BC=88=E8=80=8C=E4=B8=8D=E6=98=AF=E4=BD=9C=E4=B8=BA=E6=A8=A1=E5=9D=97=EF= =BC=89=EF=BC=8C=E4=BB=A5=E4=BE=BF=E4=BD=BF=E7=94=A8=E8=AF=A5=E7=AE=97=E6=B3= =95=E7=AD=BE=E5=90=8D=E7=9A=84 + =E6=A8=A1=E5=9D=97=E5=8F=AF=E4=BB=A5=E5=9C=A8=E4=B8=8D=E5=AF=BC=E8=87= =B4=E5=BE=AA=E7=8E=AF=E4=BE=9D=E8=B5=96=E7=9A=84=E6=83=85=E5=86=B5=E4=B8=8B= =E6=A3=80=E6=9F=A5=E5=85=B6=E7=AD=BE=E5=90=8D=E3=80=82 + + + (4) :menuselection:`File name or PKCS#11 URI of module signing key` + (``CONFIG_MODULE_SIG_KEY``) + + =E5=B0=86=E6=AD=A4=E9=80=89=E9=A1=B9=E8=AE=BE=E7=BD=AE=E4=B8=BA=E9=99= =A4=E9=BB=98=E8=AE=A4=E5=80=BC ``certs/signing_key.pem`` =E4=B9=8B=E5=A4=96= =E7=9A=84=E5=85=B6=E4=BB=96=E5=80=BC=E5=B0=86=E7=A6=81=E7=94=A8=E7=AD=BE=E5= =90=8D + =E5=AF=86=E9=92=A5=E7=9A=84=E8=87=AA=E5=8A=A8=E7=94=9F=E6=88=90=EF=BC= =8C=E5=B9=B6=E5=85=81=E8=AE=B8=E4=BD=BF=E7=94=A8=E6=82=A8=E9=80=89=E6=8B=A9= =E7=9A=84=E5=AF=86=E9=92=A5=E5=AF=B9=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E8= =BF=9B=E8=A1=8C=E7=AD=BE=E5=90=8D=E3=80=82=E6=8F=90=E4=BE=9B=E7=9A=84=E5=AD= =97=E7=AC=A6=E4=B8=B2=E5=BA=94 + =E6=A0=87=E8=AF=86=E5=8C=85=E5=90=AB=E7=A7=81=E9=92=A5=E5=8F=8A=E5=85= =B6=E5=AF=B9=E5=BA=94=E7=9A=84 PEM =E6=A0=BC=E5=BC=8F X.509 =E8=AF=81=E4=B9= =A6=E7=9A=84=E6=96=87=E4=BB=B6=EF=BC=8C=E6=88=96=E8=80=85=E5=9C=A8 OpenSSL + ENGINE_pkcs11 =E5=8A=9F=E8=83=BD=E6=AD=A3=E5=B8=B8=E7=9A=84=E7=B3=BB= =E7=BB=9F=E4=B8=8A=EF=BC=8C=E4=BD=BF=E7=94=A8 RFC7512 =E5=AE=9A=E4=B9=89=E7= =9A=84 PKCS#11 URI=E3=80=82=E5=9C=A8=E5=90=8E=E4=B8=80 + =E7=A7=8D=E6=83=85=E5=86=B5=E4=B8=8B=EF=BC=8CPKCS#11 URI =E5=BA=94=E5= =BC=95=E7=94=A8=E8=AF=81=E4=B9=A6=E5=92=8C=E7=A7=81=E9=92=A5=E3=80=82 + + =E5=A6=82=E6=9E=9C=E5=8C=85=E5=90=AB=E7=A7=81=E9=92=A5=E7=9A=84 PEM = =E6=96=87=E4=BB=B6=E5=B7=B2=E5=8A=A0=E5=AF=86=EF=BC=8C=E6=88=96=E8=80=85 PK= CS#11 =E4=BB=A4=E7=89=8C=E9=9C=80=E8=A6=81 PIN=EF=BC=8C=E5=8F=AF=E4=BB=A5= =E9=80=9A=E8=BF=87 + ``KBUILD_SIGN_PIN`` =E5=8F=98=E9=87=8F=E5=9C=A8=E6=9E=84=E5=BB=BA=E6= =97=B6=E6=8F=90=E4=BE=9B=E3=80=82 + + + (5) :menuselection:`Additional X.509 keys for default system keyring` + (``CONFIG_SYSTEM_TRUSTED_KEYS``) + + =E6=AD=A4=E9=80=89=E9=A1=B9=E5=8F=AF=E8=AE=BE=E7=BD=AE=E4=B8=BA=E5=8C= =85=E5=90=AB=E9=99=84=E5=8A=A0=E8=AF=81=E4=B9=A6=E7=9A=84 PEM =E7=BC=96=E7= =A0=81=E6=96=87=E4=BB=B6=E7=9A=84=E6=96=87=E4=BB=B6=E5=90=8D=EF=BC=8C=E8=BF= =99=E4=BA=9B=E8=AF=81=E4=B9=A6=E5=B0=86=E9=BB=98=E8=AE=A4=E5=8C=85=E5=90=AB= =E5=9C=A8 + =E7=B3=BB=E7=BB=9F=E5=AF=86=E9=92=A5=E7=8E=AF=E4=B8=AD=E3=80=82 + +=E8=AF=B7=E6=B3=A8=E6=84=8F=EF=BC=8C=E5=90=AF=E7=94=A8=E6=A8=A1=E5=9D=97= =E7=AD=BE=E5=90=8D=E4=BC=9A=E4=B8=BA=E5=86=85=E6=A0=B8=E6=9E=84=E5=BB=BA=E8= =BF=87=E7=A8=8B=E6=B7=BB=E5=8A=A0=E5=AF=B9=E6=89=A7=E8=A1=8C=E7=AD=BE=E5=90= =8D=E5=B7=A5=E5=85=B7=E7=9A=84 OpenSSL =E5=BC=80=E5=8F=91=E5=8C=85=E7=9A=84= =E4=BE=9D=E8=B5=96=E3=80=82 + + +=E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=E5=AF=86=E9=92=A5 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E7=94=9F=E6=88=90=E5=92=8C=E6=A3=80=E6=9F=A5=E7=AD=BE=E5=90=8D=E9=9C=80= =E8=A6=81=E5=8A=A0=E5=AF=86=E5=AF=86=E9=92=A5=E5=AF=B9=E3=80=82=E7=A7=81=E9= =92=A5=E7=94=A8=E4=BA=8E=E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=EF=BC=8C=E7=9B= =B8=E5=BA=94=E7=9A=84=E5=85=AC=E9=92=A5=E7=94=A8=E4=BA=8E=E6=A3=80=E6=9F=A5= =E7=AD=BE=E5=90=8D=E3=80=82=E7=A7=81=E9=92=A5 +=E4=BB=85=E5=9C=A8=E6=9E=84=E5=BB=BA=E6=9C=9F=E9=97=B4=E9=9C=80=E8=A6=81= =EF=BC=8C=E4=B9=8B=E5=90=8E=E5=8F=AF=E4=BB=A5=E5=88=A0=E9=99=A4=E6=88=96=E5= =AE=89=E5=85=A8=E5=AD=98=E5=82=A8=E3=80=82=E5=85=AC=E9=92=A5=E8=A2=AB=E6=9E= =84=E5=BB=BA=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD=EF=BC=8C=E4=BB=A5=E4=BE=BF= =E5=9C=A8=E5=8A=A0=E8=BD=BD=E6=A8=A1=E5=9D=97 +=E6=97=B6=E5=8F=AF=E4=BB=A5=E4=BD=BF=E7=94=A8=E5=AE=83=E6=9D=A5=E6=A3=80= =E6=9F=A5=E7=AD=BE=E5=90=8D=E3=80=82 + +=E5=9C=A8=E6=AD=A3=E5=B8=B8=E6=83=85=E5=86=B5=E4=B8=8B=EF=BC=8C=E5=BD=93 `= `CONFIG_MODULE_SIG_KEY`` =E4=BF=9D=E6=8C=81=E9=BB=98=E8=AE=A4=E5=80=BC=E6= =97=B6=EF=BC=8C=E5=A6=82=E6=9E=9C=E6=96=87=E4=BB=B6=E4=B8=AD=E4=B8=8D=E5=AD= =98=E5=9C=A8=E5=AF=86 +=E9=92=A5=E5=AF=B9=EF=BC=8C=E5=86=85=E6=A0=B8=E6=9E=84=E5=BB=BA=E5=B0=86= =E4=BD=BF=E7=94=A8 openssl =E8=87=AA=E5=8A=A8=E7=94=9F=E6=88=90=E6=96=B0=E7= =9A=84=E5=AF=86=E9=92=A5=E5=AF=B9:: + + certs/signing_key.pem + +=E5=9C=A8=E6=9E=84=E5=BB=BA vmlinux =E6=9C=9F=E9=97=B4=EF=BC=88=E5=85=AC= =E9=92=A5=E9=9C=80=E8=A6=81=E6=9E=84=E5=BB=BA=E5=88=B0 vmlinux =E4=B8=AD=EF= =BC=89=E4=BD=BF=E7=94=A8=E5=8F=82=E6=95=B0:: + + certs/x509.genkey + +=E6=96=87=E4=BB=B6=EF=BC=88=E5=A6=82=E6=9E=9C=E5=B0=9A=E4=B8=8D=E5=AD=98= =E5=9C=A8=E4=B9=9F=E4=BC=9A=E7=94=9F=E6=88=90=EF=BC=89=E3=80=82 + +=E5=8F=AF=E4=BB=A5=E5=9C=A8 RSA=EF=BC=88``MODULE_SIG_KEY_TYPE_RSA``=EF=BC= =89=E3=80=81 +ECDSA=EF=BC=88``MODULE_SIG_KEY_TYPE_ECDSA``=EF=BC=89=E5=92=8C +ML-DSA=EF=BC=88``MODULE_SIG_KEY_TYPE_MLDSA_*``=EF=BC=89=E4=B9=8B=E9=97=B4= =E9=80=89=E6=8B=A9=E7=94=9F=E6=88=90 RSA 4k=E3=80=81NIST P-384 +=E5=AF=86=E9=92=A5=E5=AF=B9=E6=88=96 ML-DSA 44=E3=80=8165 =E6=88=96 87 =E5= =AF=86=E9=92=A5=E5=AF=B9=E3=80=82 + +=E5=BC=BA=E7=83=88=E5=BB=BA=E8=AE=AE=E6=82=A8=E6=8F=90=E4=BE=9B=E8=87=AA= =E5=B7=B1=E7=9A=84 x509.genkey =E6=96=87=E4=BB=B6=E3=80=82 + +=E6=9C=80=E5=80=BC=E5=BE=97=E6=B3=A8=E6=84=8F=E7=9A=84=E6=98=AF=EF=BC=8C= =E5=9C=A8 x509.genkey =E6=96=87=E4=BB=B6=E4=B8=AD=EF=BC=8Creq_distinguished= _name =E9=83=A8=E5=88=86=E5=BA=94=E4=BB=8E=E9=BB=98=E8=AE=A4=E5=80=BC +=E6=9B=B4=E6=94=B9:: + + [ req_distinguished_name ] + #O =3D Unspecified company + CN =3D Build time autogenerated kernel key + #emailAddress =3D unspecified.user@unspecified.company + +=E7=94=9F=E6=88=90=E7=9A=84 RSA =E5=AF=86=E9=92=A5=E5=A4=A7=E5=B0=8F=E4=B9= =9F=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5=E4=B8=8B=E6=96=B9=E5=BC=8F= =E8=AE=BE=E7=BD=AE:: + + [ req ] + default_bits =3D 4096 + +=E4=B9=9F=E5=8F=AF=E4=BB=A5=E4=BD=BF=E7=94=A8=E4=BD=8D=E4=BA=8E Linux =E5= =86=85=E6=A0=B8=E6=BA=90=E4=BB=A3=E7=A0=81=E6=A0=91=E6=A0=B9=E8=8A=82=E7=82= =B9=E4=B8=AD=E7=9A=84 x509.genkey =E5=AF=86=E9=92=A5=E7=94=9F=E6=88=90=E9= =85=8D=E7=BD=AE=E6=96=87=E4=BB=B6=E5=92=8C +openssl =E5=91=BD=E4=BB=A4=E6=89=8B=E5=8A=A8=E7=94=9F=E6=88=90=E5=85=AC=E9= =92=A5/=E7=A7=81=E9=92=A5=E6=96=87=E4=BB=B6=E3=80=82=E4=BB=A5=E4=B8=8B=E6= =98=AF=E7=94=9F=E6=88=90=E5=85=AC=E9=92=A5/=E7=A7=81=E9=92=A5=E6=96=87=E4= =BB=B6=E7=9A=84=E7=A4=BA=E4=BE=8B:: + + openssl req -new -nodes -utf8 -sha256 -days 36500 -batch -x509 \ + -config x509.genkey -outform PEM -out kernel_key.pem \ + -keyout kernel_key.pem + +=E7=84=B6=E5=90=8E=E5=8F=AF=E4=BB=A5=E5=B0=86=E7=94=9F=E6=88=90=E7=9A=84 k= ernel_key.pem =E6=96=87=E4=BB=B6=E7=9A=84=E5=AE=8C=E6=95=B4=E8=B7=AF=E5=BE= =84=E5=90=8D=E6=8C=87=E5=AE=9A=E5=9C=A8 +``CONFIG_MODULE_SIG_KEY`` =E9=80=89=E9=A1=B9=E4=B8=AD=EF=BC=8C=E5=B9=B6=E4= =B8=94=E5=B0=86=E4=BD=BF=E7=94=A8=E5=85=B6=E4=B8=AD=E7=9A=84=E8=AF=81=E4=B9= =A6=E5=92=8C=E5=AF=86=E9=92=A5=E8=80=8C=E4=B8=8D=E6=98=AF=E8=87=AA=E5=8A=A8= =E7=94=9F=E6=88=90=E7=9A=84 +=E5=AF=86=E9=92=A5=E5=AF=B9=E3=80=82 + + +=E5=86=85=E6=A0=B8=E4=B8=AD=E7=9A=84=E5=85=AC=E9=92=A5 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E5=86=85=E6=A0=B8=E5=8C=85=E5=90=AB=E4=B8=80=E4=B8=AA=E5=8F=AF=E7=94=B1 r= oot =E6=9F=A5=E7=9C=8B=E7=9A=84=E5=85=AC=E9=92=A5=E7=8E=AF=E3=80=82=E5=AE= =83=E4=BB=AC=E5=9C=A8=E5=90=8D=E4=B8=BA ".builtin_trusted_keys" =E7=9A=84= =E5=AF=86 +=E9=92=A5=E7=8E=AF=E4=B8=AD=EF=BC=8C=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87= =E4=BB=A5=E4=B8=8B=E6=96=B9=E5=BC=8F=E6=9F=A5=E7=9C=8B:: + + [root@deneb ~]# cat /proc/keys + ... + 223c7853 I------ 1 perm 1f030000 0 0 keyring .builtin_trust= ed_keys: 1 + 302d2d52 I------ 1 perm 1f010000 0 0 asymmetri Fedora kernel = signing key: d69a84e6bce3d216b979e9505b3e3ef9a7118079: X509.RSA a7118079 [] + +=E9=99=A4=E4=BA=86=E4=B8=93=E9=97=A8=E4=B8=BA=E6=A8=A1=E5=9D=97=E7=AD=BE= =E5=90=8D=E7=94=9F=E6=88=90=E7=9A=84=E5=85=AC=E9=92=A5=E5=A4=96=EF=BC=8C=E8= =BF=98=E5=8F=AF=E4=BB=A5=E5=9C=A8 ``CONFIG_SYSTEM_TRUSTED_KEYS`` =E9=85=8D= =E7=BD=AE +=E9=80=89=E9=A1=B9=E5=BC=95=E7=94=A8=E7=9A=84 PEM =E7=BC=96=E7=A0=81=E6=96= =87=E4=BB=B6=E4=B8=AD=E6=8F=90=E4=BE=9B=E5=85=B6=E4=BB=96=E5=8F=97=E4=BF=A1= =E4=BB=BB=E7=9A=84=E8=AF=81=E4=B9=A6=E3=80=82 + +=E6=AD=A4=E5=A4=96=EF=BC=8C=E6=9E=B6=E6=9E=84=E4=BB=A3=E7=A0=81=E5=8F=AF= =E4=BB=A5=E4=BB=8E=E7=A1=AC=E4=BB=B6=E5=AD=98=E5=82=A8=E4=B8=AD=E8=8E=B7=E5= =8F=96=E5=85=AC=E9=92=A5=E5=B9=B6=E5=B0=86=E5=85=B6=E6=B7=BB=E5=8A=A0=EF=BC= =88=E4=BE=8B=E5=A6=82=E4=BB=8E UEFI =E5=AF=86=E9=92=A5=E6=95=B0=E6=8D=AE=E5= =BA=93=EF=BC=89=E3=80=82 + +=E6=9C=80=E5=90=8E=EF=BC=8C=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5= =E4=B8=8B=E6=96=B9=E5=BC=8F=E6=B7=BB=E5=8A=A0=E5=85=B6=E4=BB=96=E5=85=AC=E9= =92=A5:: + + keyctl padd asymmetric "" [.builtin_trusted_keys-ID] <[key-file] + +=E4=BE=8B=E5=A6=82:: + + keyctl padd asymmetric "" 0x223c7853