From nobody Tue Jun 16 10:24:50 2026 Received: from out162-62-57-49.mail.qq.com (out162-62-57-49.mail.qq.com [162.62.57.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0DABFBE5E; Sat, 18 Apr 2026 04:45:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=162.62.57.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776487534; cv=none; b=qxlePuzQo9DCSIzlGSwI1blaQjrDSElwU7Mnc+lhskSLQOPOIPRUKItSjTXf1VQP0To3nIqEcv746WT2udWOxkMnYp1vGCum1WAiPcFWkNjaiHM4VMzrl207vlkUzJBAAAJm1VUJa15nfHWYvPg15jvpUmj0AtyixATe3meF370= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776487534; c=relaxed/simple; bh=7UPRQOJvmySRVgCNDNcQSJmzWK2mLqvLdApY3ixLPBs=; h=Message-ID:From:To:Cc:Subject:Date:MIME-Version:Content-Type; b=DjETbR3+9v4iGvd9mTcb5y1OhkdcFiBE0+o9m2kJjTy4HLX0lJ7+R/kQILrxuKW48GJ1BbN9q7qR9NGMXjTQ1iWZqEDtY5dGBolvXQaBhiyoQEZxQCTzRJY5+IOb8s0PL+5jvlsn8ERAmCnlXlqpr7DnhI2T5aEfWDp2+8/YfrI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com; spf=pass smtp.mailfrom=qq.com; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b=d9c1TcOC; arc=none smtp.client-ip=162.62.57.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=qq.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b="d9c1TcOC" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1776487520; bh=uvTI3AQuIDKjeCiff8BQPAnMQ7N7CK5QvOVDatfbp+w=; h=From:To:Cc:Subject:Date; b=d9c1TcOCjErwDIuVbDkA/wlsPcNqTlyKtkbl+3mxykR9MM+fiNSSTtsDBrwLmYQUh PSRjeogJbGzuVIJozTCeoeFUiOmesFs7gCkr5sZ7lwu1Pts9Jt5QvILDJEpv9NEOcs zyT9m+TFRIEq5AUIO67B7ejoOQ5lMI2H4ugpvGGU= Received: from localhost.localdomain.localdomain ([27.38.232.147]) by newxmesmtplogicsvrszb51-0.qq.com (NewEsmtp) with SMTP id B50B868B; Sat, 18 Apr 2026 12:45:16 +0800 X-QQ-mid: xmsmtpt1776487516twggn3c90 Message-ID: X-QQ-XMAILINFO: NUaRPsENHoCK57kIHMStElvsgIlNEN916X9ndn9yyXszlc6Ck4HZGmyBftmjF+ prsyKmk/OVZ4PNWDKJickf3inrRrE52nrHJEHa7+Bn3I2U2YgaCjaMwtUk16DkPUURfvRazt57E9 jQR0s6AxOtpg+S+HUX8fN04ILIlnWxF6nLxUoyXRbEliZ0beXy6c9ZwJYVJMgKDsGzCUdKvkEzwZ 01HJzEq6JK+vjXIb1K/hH7gMtQQn7krB/XiRP6vq0t2uZsFszDGPw04iMCKprBBOTDIqUAOQOChC ANORHRv79z91VrEP9PMmNqOWb+XqEhW151bBYSZ2Dj9Mirl4sDuTLOq3kTLN8y4yUnTNJxRerXe2 1C9FLm+SPa+brKfqb/nIO+CMSNeSItM8WhMt2jWWcBIxLGYFuh48asXaWchwQktQ1RZkcRrOl42e VWGh4ef4yEPgPD5Y4AFcsqrWvbmfM+Zyl51wSDeMKPTeJFLKHyfsfuBmvuX9P7i67a7/Cdla8aSI mYjz12wP0AQ1A5X82NgG3aet/MKpdsaU9L+FRDuUkglPNKgUMYaK31d9v/Ouiq4pNO6emqE/V4n1 7A3rwyya8LeAFPchc+fV9Uo8oKAuraoLc3i9DlhW3YU84kXqUZwVx+2qWjdAOGY/uAR7CZ+hdpXx 2Si5Wu+5flfZ47HyZNFbCSRWarHmG2HAKQ+1AISdFZQUltNX445VGCUjcisQEDNb4t6fnSqjclCR oq69bXBc8a6+nl3HIhowoxByvPdJqZVeFznFUX9zgR6jyFo65/1M+nUNXR4W13kNZzc9faSMm9n9 9jCDMfrLE5vnZDXZdhX9yqKgmPO8RxgheVX/ZCGezHLb9q5QYf+bQtbU3cPFet098F98l+QLOaIU 0Cnx4S4nyjgT+Xh8GxkgMnkC87+dPn2h2BhHr4IiJpmKr+DgZTDgvZcN+8IZr/C+TLMfO/lkxwIw F+uHALY3V+zlrXcCH3qHxKS2HanaJDF+f0wAzzyG+6R3kJvIwKuPoDHNnD9hByriURORwS0Ww/iM 5nR0eabJMTvrYXF1+uwHZptZvY5yTycpGib2F0TP1Eiv8AlqZSl42v6dIR1O6gybDCcGcQ4Iit3K YbTmCw X-QQ-XMRINFO: M/715EihBoGS47X28/vv4NpnfpeBLnr4Qg== From: Yan Zhu To: seakeel@gmail.com, alexs@kernel.org, si.yanteng@linux.dev, corbet@lwn.net Cc: dzm91@hust.edu.cn, skhan@linuxfoundation.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, zhuyan2015@qq.com Subject: [PATCH v3] docs/zh_CN: add module-signing Chinese translation Date: Sat, 18 Apr 2026 12:45:13 +0800 X-OQ-MSGID: X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Translate .../admin-guide/module-signing.rst into Chinese. Update the translation through commit 0ad9a71933e7 ("modsign: Enable ML-DSA module signing") Signed-off-by: Yan Zhu --- .../zh_CN/admin-guide/module-signing.rst | 249 ++++++++++++++++++ 1 file changed, 249 insertions(+) create mode 100644 Documentation/translations/zh_CN/admin-guide/module-sig= ning.rst diff --git a/Documentation/translations/zh_CN/admin-guide/module-signing.rs= t b/Documentation/translations/zh_CN/admin-guide/module-signing.rst new file mode 100644 index 000000000000..04b0f1cbafd5 --- /dev/null +++ b/Documentation/translations/zh_CN/admin-guide/module-signing.rst @@ -0,0 +1,249 @@ +.. SPDX-License-Identifier: GPL-2.0 +.. include:: ../disclaimer-zh_CN.rst + +:Original: Documentation/admin-guide/module-signing.rst +:=E7=BF=BB=E8=AF=91: + =E6=9C=B1=E5=B2=A9 Yan Zhu + + +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D +=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D + +.. =E7=9B=AE=E5=BD=95 +.. +.. - =E6=A6=82=E8=BF=B0 +.. - =E9=85=8D=E7=BD=AE=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D +.. - =E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=E5=AF=86=E9=92=A5 +.. - =E5=86=85=E6=A0=B8=E4=B8=AD=E7=9A=84=E5=85=AC=E9=92=A5 +.. - =E6=A8=A1=E5=9D=97=E6=89=8B=E5=8A=A8=E7=AD=BE=E5=90=8D +.. - =E5=B7=B2=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97=E5=92=8C=E5=89=A5=E7=A6= =BB +.. - =E5=8A=A0=E8=BD=BD=E5=B7=B2=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97 +.. - =E6=97=A0=E6=95=88=E7=AD=BE=E5=90=8D=E5=92=8C=E6=9C=AA=E7=AD=BE=E5=90= =8D=E6=A8=A1=E5=9D=97 +.. - =E7=AE=A1=E7=90=86/=E4=BF=9D=E6=8A=A4=E7=A7=81=E9=92=A5 + + +=E6=A6=82=E8=BF=B0 +=3D=3D=3D=3D + +=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6= =E5=9C=A8=E5=AE=89=E8=A3=85=E8=BF=87=E7=A8=8B=E4=B8=AD=E5=AF=B9=E6=A8=A1=E5= =9D=97=E8=BF=9B=E8=A1=8C=E5=8A=A0=E5=AF=86=E7=AD=BE=E5=90=8D=EF=BC=8C=E7=84= =B6=E5=90=8E=E5=9C=A8=E5=8A=A0=E8=BD=BD=E6=A8=A1=E5=9D=97=E6=97=B6=E6=A3=80= =E6=9F=A5=E7=AD=BE=E5=90=8D=E3=80=82=E8=BF=99 +=E9=80=9A=E8=BF=87=E7=A6=81=E6=AD=A2=E5=8A=A0=E8=BD=BD=E6=9C=AA=E7=AD=BE= =E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E6=88=96=E4=BD=BF=E7=94=A8=E6=97=A0=E6= =95=88=E5=AF=86=E9=92=A5=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E6=9D= =A5=E6=8F=90=E9=AB=98=E5=86=85=E6=A0=B8=E5=AE=89=E5=85=A8=E6=80=A7=E3=80=82= =E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E9=80=9A +=E8=BF=87=E4=BD=BF=E6=81=B6=E6=84=8F=E6=A8=A1=E5=9D=97=E6=9B=B4=E9=9A=BE= =E5=8A=A0=E8=BD=BD=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD=E6=9D=A5=E5=A2=9E=E5= =8A=A0=E5=AE=89=E5=85=A8=E6=80=A7=E3=80=82=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90= =8D=E6=A3=80=E6=9F=A5=E5=9C=A8=E5=86=85=E6=A0=B8=E4=B8=AD=E5=AE=8C=E6=88=90= =EF=BC=8C=E5=9B=A0=E6=AD=A4=E4=B8=8D=E9=9C=80 +=E8=A6=81=E5=8F=97=E4=BF=A1=E4=BB=BB=E7=9A=84=E7=94=A8=E6=88=B7=E7=A9=BA= =E9=97=B4=E4=BD=8D=E3=80=82 + +=E6=AD=A4=E6=9C=BA=E5=88=B6=E4=BD=BF=E7=94=A8 X.509 ITU-T =E6=A0=87=E5=87= =86=E8=AF=81=E4=B9=A6=E5=AF=B9=E6=B6=89=E5=8F=8A=E7=9A=84=E5=85=AC=E9=92=A5= =E8=BF=9B=E8=A1=8C=E7=BC=96=E7=A0=81=E3=80=82=E7=AD=BE=E5=90=8D=E6=9C=AC=E8= =BA=AB=E4=B8=8D=E4=BB=A5=E4=BB=BB=E4=BD=95=E5=B7=A5=E4=B8=9A=E6=A0=87=E5=87= =86 +=E7=B1=BB=E5=9E=8B=E7=BC=96=E7=A0=81=E3=80=82=E5=86=85=E7=BD=AE=E6=9C=BA= =E5=88=B6=E7=9B=AE=E5=89=8D=E4=BB=85=E6=94=AF=E6=8C=81 RSA=E3=80=81NIST P-3= 84 ECDSA =E5=92=8C NIST FIPS-204 ML-DSA +=E5=85=AC=E9=92=A5=E7=AD=BE=E5=90=8D=E6=A0=87=E5=87=86=EF=BC=88=E5=B0=BD= =E7=AE=A1=E5=AE=83=E6=98=AF=E5=8F=AF=E6=8F=92=E6=8B=94=E7=9A=84=E5=B9=B6=E5= =85=81=E8=AE=B8=E4=BD=BF=E7=94=A8=E5=85=B6=E4=BB=96=E6=A0=87=E5=87=86=EF=BC= =89=E3=80=82=E5=AF=B9=E4=BA=8E RSA =E5=92=8C ECDSA=EF=BC=8C=E5=8F=AF=E4=BB= =A5=E4=BD=BF +=E7=94=A8=E7=9A=84=E5=8F=AF=E8=83=BD=E7=9A=84=E5=93=88=E5=B8=8C=E7=AE=97= =E6=B3=95=E6=98=AF=E5=A4=A7=E5=B0=8F=E4=B8=BA 256=E3=80=81384 =E5=92=8C 512= =E7=9A=84 SHA-2 =E5=92=8C SHA-3=EF=BC=88=E7=AE=97=E6=B3=95=E7=94=B1=E7=AD= =BE=E5=90=8D=E4=B8=AD=E7=9A=84 +=E6=95=B0=E6=8D=AE=E9=80=89=E6=8B=A9=EF=BC=89=EF=BC=9BML-DSA=E4=BC=9A=E8= =87=AA=E8=A1=8C=E8=BF=9B=E8=A1=8C=E5=93=88=E5=B8=8C=E8=BF=90=E7=AE=97=EF=BC= =8C=E4=BD=86=E5=85=81=E8=AE=B8=E4=B8=8ESHA512=E5=93=88=E5=B8=8C=E7=AE=97=E6= =B3=95=E7=BB=93=E5=90=88=E7=94=A8=E4=BA=8E=E7=AD=BE=E5=90=8D=E5=B1=9E=E6=80= =A7=E3=80=82 + +=E9=85=8D=E7=BD=AE=E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E9=80=9A=E8=BF=87=E8=BF=9B=E5=85=A5=E5=86=85=E6=A0=B8=E9=85=8D=E7=BD=AE= =E7=9A=84 :menuselection:`Enable Loadable Module Support` =E8=8F=9C=E5=8D= =95=E5=B9=B6=E6=89=93 +=E5=BC=80=E4=BB=A5=E4=B8=8B=E9=80=89=E9=A1=B9=E6=9D=A5=E5=90=AF=E7=94=A8= =E6=A8=A1=E5=9D=97=E7=AD=BE=E5=90=8D=E6=9C=BA=E5=88=B6:: + + CONFIG_MODULE_SIG "Module signature verification" + +=E8=BF=99=E6=9C=89=E5=A4=9A=E4=B8=AA=E5=8F=AF=E7=94=A8=E9=80=89=E9=A1=B9= =EF=BC=9A + + (1) :menuselection:`Require modules to be validly signed` + (``CONFIG_MODULE_SIG_FORCE``) + + =E8=BF=99=E6=8C=87=E5=AE=9A=E4=BA=86=E5=86=85=E6=A0=B8=E5=BA=94=E5=A6= =82=E4=BD=95=E5=A4=84=E7=90=86=E5=85=B6=E5=AF=86=E9=92=A5=E6=9C=AA=E7=9F=A5= =E6=88=96=E6=9C=AA=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=E3=80=82 + + =E5=A6=82=E6=9E=9C=E5=85=B3=E9=97=AD=EF=BC=88=E5=8D=B3"=E5=AE=BD=E6= =9D=BE=E6=A8=A1=E5=BC=8F"=EF=BC=89=EF=BC=8C=E5=88=99=E5=85=81=E8=AE=B8=E4= =BD=BF=E7=94=A8=E4=B8=8D=E5=8F=AF=E7=94=A8=E5=AF=86=E9=92=A5=E5=92=8C=E6=9C= =AA=E7=AD=BE=E5=90=8D=E7=9A=84=E6=A8=A1=E5=9D=97=EF=BC=8C=E4=BD=86=E5=86=85= =E6=A0=B8=E5=B0=86=E8=A2=AB + =E6=A0=87=E8=AE=B0=E4=B8=BA=E5=8F=97=E6=B1=A1=E6=9F=93=EF=BC=8C=E5=B9= =B6=E4=B8=94=E7=9B=B8=E5=85=B3=E6=A8=A1=E5=9D=97=E5=B0=86=E8=A2=AB=E6=A0=87= =E8=AE=B0=E4=B8=BA=E5=8F=97=E6=B1=A1=E6=9F=93=EF=BC=8C=E6=98=BE=E7=A4=BA=E5= =AD=97=E7=AC=A6'E'=E3=80=82 + + =E5=A6=82=E6=9E=9C=E6=89=93=E5=BC=80=EF=BC=88=E5=8D=B3"=E9=99=90=E5= =88=B6=E6=A8=A1=E5=BC=8F"=EF=BC=89=EF=BC=8C=E5=8F=AA=E6=9C=89=E5=85=B7=E6= =9C=89=E6=9C=89=E6=95=88=E7=AD=BE=E5=90=8D=E4=B8=94=E5=8F=AF=E7=94=B1=E5=86= =85=E6=A0=B8=E6=8B=A5=E6=9C=89=E7=9A=84=E5=85=AC=E9=92=A5=E9=AA=8C=E8=AF=81= =E7=9A=84=E6=A8=A1=E5=9D=97 + =E6=89=8D=E4=BC=9A=E8=A2=AB=E5=8A=A0=E8=BD=BD=E3=80=82=E6=89=80=E6=9C= =89=E5=85=B6=E4=BB=96=E6=A8=A1=E5=9D=97=E5=B0=86=E7=94=9F=E6=88=90=E9=94=99= =E8=AF=AF=E3=80=82 + + =E6=97=A0=E8=AE=BA=E6=AD=A4=E5=A4=84=E7=9A=84=E8=AE=BE=E7=BD=AE=E5=A6= =82=E4=BD=95=EF=BC=8C=E5=A6=82=E6=9E=9C=E6=A8=A1=E5=9D=97=E7=9A=84=E7=AD=BE= =E5=90=8D=E5=9D=97=E6=97=A0=E6=B3=95=E8=A7=A3=E6=9E=90=EF=BC=8C=E5=AE=83=E5= =B0=86=E8=A2=AB=E7=9B=B4=E6=8E=A5=E6=8B=92=E7=BB=9D=E3=80=82 + + + (2) :menuselection:`Automatically sign all modules` + (``CONFIG_MODULE_SIG_ALL``) + + =E5=A6=82=E6=9E=9C=E6=89=93=E5=BC=80=E6=AD=A4=E9=80=89=E9=A1=B9=EF=BC= =8C=E5=88=99=E5=9C=A8=E6=9E=84=E5=BB=BA=E7=9A=84 modules_install =E9=98=B6= =E6=AE=B5=E6=9C=9F=E9=97=B4=E5=B0=86=E8=87=AA=E5=8A=A8=E7=AD=BE=E5=90=8D=E6= =A8=A1=E5=9D=97=E3=80=82 + =E5=A6=82=E6=9E=9C=E5=85=B3=E9=97=AD=EF=BC=8C=E5=88=99=E5=BF=85=E9=A1= =BB=E4=BD=BF=E7=94=A8=E4=BB=A5=E4=B8=8B=E5=91=BD=E4=BB=A4=E6=89=8B=E5=8A=A8= =E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97:: + + scripts/sign-file + + + (3) :menuselection:`Which hash algorithm should modules be signed with?` + + =E8=BF=99=E6=8F=90=E4=BE=9B=E4=BA=86=E5=AE=89=E8=A3=85=E9=98=B6=E6=AE= =B5=E5=B0=86=E7=94=A8=E4=BA=8E=E7=AD=BE=E5=90=8D=E6=A8=A1=E5=9D=97=E7=9A=84= =E5=93=88=E5=B8=8C=E7=AE=97=E6=B3=95=E9=80=89=E6=8B=A9=EF=BC=9A + + =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + ``CONFIG_MODULE_SIG_SHA256`` :menuselection:`Sign modules with SHA-256` + ``CONFIG_MODULE_SIG_SHA384`` :menuselection:`Sign modules with SHA-384` + ``CONFIG_MODULE_SIG_SHA512`` :menuselection:`Sign modules with SHA-512` + ``CONFIG_MODULE_SIG_SHA3_256`` :menuselection:`Sign modules with SHA3-256` + ``CONFIG_MODULE_SIG_SHA3_384`` :menuselection:`Sign modules with SHA3-384` + ``CONFIG_MODULE_SIG_SHA3_512`` :menuselection:`Sign modules with SHA3-512` + =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + + =E6=AD=A4=E5=A4=84=E9=80=89=E6=8B=A9=E7=9A=84=E7=AE=97=E6=B3=95=E4=B9= =9F=E5=B0=86=E8=A2=AB=E6=9E=84=E5=BB=BA=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD= =EF=BC=88=E8=80=8C=E4=B8=8D=E6=98=AF=E4=BD=9C=E4=B8=BA=E6=A8=A1=E5=9D=97=EF= =BC=89=EF=BC=8C=E4=BB=A5=E4=BE=BF=E4=BD=BF=E7=94=A8=E8=AF=A5=E7=AE=97=E6=B3= =95=E7=AD=BE=E5=90=8D=E7=9A=84 + =E6=A8=A1=E5=9D=97=E5=8F=AF=E4=BB=A5=E5=9C=A8=E4=B8=8D=E5=AF=BC=E8=87= =B4=E5=BE=AA=E7=8E=AF=E4=BE=9D=E8=B5=96=E7=9A=84=E6=83=85=E5=86=B5=E4=B8=8B= =E6=A3=80=E6=9F=A5=E5=85=B6=E7=AD=BE=E5=90=8D=E3=80=82 + + + (4) :menuselection:`File name or PKCS#11 URI of module signing key` + (``CONFIG_MODULE_SIG_KEY``) + + =E5=B0=86=E6=AD=A4=E9=80=89=E9=A1=B9=E8=AE=BE=E7=BD=AE=E4=B8=BA=E9=99= =A4=E9=BB=98=E8=AE=A4=E5=80=BC ``certs/signing_key.pem`` =E4=B9=8B=E5=A4=96= =E7=9A=84=E5=85=B6=E4=BB=96=E5=80=BC=E5=B0=86=E7=A6=81=E7=94=A8=E7=AD=BE=E5= =90=8D + =E5=AF=86=E9=92=A5=E7=9A=84=E8=87=AA=E5=8A=A8=E7=94=9F=E6=88=90=EF=BC= =8C=E5=B9=B6=E5=85=81=E8=AE=B8=E4=BD=BF=E7=94=A8=E6=82=A8=E9=80=89=E6=8B=A9= =E7=9A=84=E5=AF=86=E9=92=A5=E5=AF=B9=E5=86=85=E6=A0=B8=E6=A8=A1=E5=9D=97=E8= =BF=9B=E8=A1=8C=E7=AD=BE=E5=90=8D=E3=80=82=E6=8F=90=E4=BE=9B=E7=9A=84=E5=AD= =97=E7=AC=A6=E4=B8=B2=E5=BA=94 + =E6=A0=87=E8=AF=86=E5=8C=85=E5=90=AB=E7=A7=81=E9=92=A5=E5=8F=8A=E5=85= =B6=E5=AF=B9=E5=BA=94=E7=9A=84 PEM =E6=A0=BC=E5=BC=8F X.509 =E8=AF=81=E4=B9= =A6=E7=9A=84=E6=96=87=E4=BB=B6=EF=BC=8C=E6=88=96=E8=80=85=E5=9C=A8 OpenSSL + ENGINE_pkcs11 =E5=8A=9F=E8=83=BD=E6=AD=A3=E5=B8=B8=E7=9A=84=E7=B3=BB= =E7=BB=9F=E4=B8=8A=EF=BC=8C=E4=BD=BF=E7=94=A8 RFC7512 =E5=AE=9A=E4=B9=89=E7= =9A=84 PKCS#11 URI=E3=80=82=E5=9C=A8=E5=90=8E=E4=B8=80 + =E7=A7=8D=E6=83=85=E5=86=B5=E4=B8=8B=EF=BC=8CPKCS#11 URI =E5=BA=94=E5= =BC=95=E7=94=A8=E8=AF=81=E4=B9=A6=E5=92=8C=E7=A7=81=E9=92=A5=E3=80=82 + + =E5=A6=82=E6=9E=9C=E5=8C=85=E5=90=AB=E7=A7=81=E9=92=A5=E7=9A=84 PEM = =E6=96=87=E4=BB=B6=E5=B7=B2=E5=8A=A0=E5=AF=86=EF=BC=8C=E6=88=96=E8=80=85 PK= CS#11 =E4=BB=A4=E7=89=8C=E9=9C=80=E8=A6=81 PIN=EF=BC=8C=E5=8F=AF=E4=BB=A5= =E9=80=9A=E8=BF=87 + ``KBUILD_SIGN_PIN`` =E5=8F=98=E9=87=8F=E5=9C=A8=E6=9E=84=E5=BB=BA=E6= =97=B6=E6=8F=90=E4=BE=9B=E3=80=82 + + + (5) :menuselection:`Additional X.509 keys for default system keyring` + (``CONFIG_SYSTEM_TRUSTED_KEYS``) + + =E6=AD=A4=E9=80=89=E9=A1=B9=E5=8F=AF=E8=AE=BE=E7=BD=AE=E4=B8=BA=E5=8C= =85=E5=90=AB=E9=99=84=E5=8A=A0=E8=AF=81=E4=B9=A6=E7=9A=84 PEM =E7=BC=96=E7= =A0=81=E6=96=87=E4=BB=B6=E7=9A=84=E6=96=87=E4=BB=B6=E5=90=8D=EF=BC=8C=E8=BF= =99=E4=BA=9B=E8=AF=81=E4=B9=A6=E5=B0=86=E9=BB=98=E8=AE=A4=E5=8C=85=E5=90=AB= =E5=9C=A8 + =E7=B3=BB=E7=BB=9F=E5=AF=86=E9=92=A5=E7=8E=AF=E4=B8=AD=E3=80=82 + +=E8=AF=B7=E6=B3=A8=E6=84=8F=EF=BC=8C=E5=90=AF=E7=94=A8=E6=A8=A1=E5=9D=97= =E7=AD=BE=E5=90=8D=E4=BC=9A=E4=B8=BA=E5=86=85=E6=A0=B8=E6=9E=84=E5=BB=BA=E8= =BF=87=E7=A8=8B=E6=B7=BB=E5=8A=A0=E5=AF=B9=E6=89=A7=E8=A1=8C=E7=AD=BE=E5=90= =8D=E5=B7=A5=E5=85=B7=E7=9A=84OpenSSL=E5=BC=80=E5=8F=91=E5=8C=85=E7=9A=84= =E4=BE=9D=E8=B5=96=E3=80=82 + + +=E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=E5=AF=86=E9=92=A5 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E7=94=9F=E6=88=90=E5=92=8C=E6=A3=80=E6=9F=A5=E7=AD=BE=E5=90=8D=E9=9C=80= =E8=A6=81=E5=8A=A0=E5=AF=86=E5=AF=86=E9=92=A5=E5=AF=B9=E3=80=82=E7=A7=81=E9= =92=A5=E7=94=A8=E4=BA=8E=E7=94=9F=E6=88=90=E7=AD=BE=E5=90=8D=EF=BC=8C=E7=9B= =B8=E5=BA=94=E7=9A=84=E5=85=AC=E9=92=A5=E7=94=A8=E4=BA=8E=E6=A3=80=E6=9F=A5= =E7=AD=BE=E5=90=8D=E3=80=82=E7=A7=81=E9=92=A5 +=E4=BB=85=E5=9C=A8=E6=9E=84=E5=BB=BA=E6=9C=9F=E9=97=B4=E9=9C=80=E8=A6=81= =EF=BC=8C=E4=B9=8B=E5=90=8E=E5=8F=AF=E4=BB=A5=E5=88=A0=E9=99=A4=E6=88=96=E5= =AE=89=E5=85=A8=E5=AD=98=E5=82=A8=E3=80=82=E5=85=AC=E9=92=A5=E8=A2=AB=E6=9E= =84=E5=BB=BA=E5=88=B0=E5=86=85=E6=A0=B8=E4=B8=AD=EF=BC=8C=E4=BB=A5=E4=BE=BF= =E5=9C=A8=E5=8A=A0=E8=BD=BD=E6=A8=A1=E5=9D=97 +=E6=97=B6=E5=8F=AF=E4=BB=A5=E4=BD=BF=E7=94=A8=E5=AE=83=E6=9D=A5=E6=A3=80= =E6=9F=A5=E7=AD=BE=E5=90=8D=E3=80=82 + +=E5=9C=A8=E6=AD=A3=E5=B8=B8=E6=83=85=E5=86=B5=E4=B8=8B=EF=BC=8C=E5=BD=93 `= `CONFIG_MODULE_SIG_KEY`` =E4=BF=9D=E6=8C=81=E9=BB=98=E8=AE=A4=E5=80=BC=E6= =97=B6=EF=BC=8C=E5=A6=82=E6=9E=9C=E6=96=87=E4=BB=B6=E4=B8=AD=E4=B8=8D=E5=AD= =98=E5=9C=A8=E5=AF=86 +=E9=92=A5=E5=AF=B9=EF=BC=8C=E5=86=85=E6=A0=B8=E6=9E=84=E5=BB=BA=E5=B0=86= =E4=BD=BF=E7=94=A8 openssl =E8=87=AA=E5=8A=A8=E7=94=9F=E6=88=90=E6=96=B0=E7= =9A=84=E5=AF=86=E9=92=A5=E5=AF=B9:: + + certs/signing_key.pem + +=E5=9C=A8=E6=9E=84=E5=BB=BA vmlinux =E6=9C=9F=E9=97=B4=EF=BC=88=E5=85=AC= =E9=92=A5=E9=9C=80=E8=A6=81=E6=9E=84=E5=BB=BA=E5=88=B0 vmlinux =E4=B8=AD=EF= =BC=89=E4=BD=BF=E7=94=A8=E5=8F=82=E6=95=B0:: + + certs/x509.genkey + +=E6=96=87=E4=BB=B6=EF=BC=88=E5=A6=82=E6=9E=9C=E5=B0=9A=E4=B8=8D=E5=AD=98= =E5=9C=A8=E4=B9=9F=E4=BC=9A=E7=94=9F=E6=88=90=EF=BC=89=E3=80=82 + +=E5=8F=AF=E4=BB=A5=E5=9C=A8 RSA=EF=BC=88``MODULE_SIG_KEY_TYPE_RSA``=EF=BC= =89=E3=80=81 +ECDSA=EF=BC=88``MODULE_SIG_KEY_TYPE_ECDSA``=EF=BC=89=E5=92=8C +ML-DSA=EF=BC=88``MODULE_SIG_KEY_TYPE_MLDSA_*``=EF=BC=89=E4=B9=8B=E9=97=B4= =E9=80=89=E6=8B=A9=E7=94=9F=E6=88=90 RSA 4k=E3=80=81NIST P-384 +=E5=AF=86=E9=92=A5=E5=AF=B9=E6=88=96 ML-DSA 44=E3=80=8165 =E6=88=96 87 =E5= =AF=86=E9=92=A5=E5=AF=B9=E3=80=82 + +=E5=BC=BA=E7=83=88=E5=BB=BA=E8=AE=AE=E6=82=A8=E6=8F=90=E4=BE=9B=E8=87=AA= =E5=B7=B1=E7=9A=84 x509.genkey =E6=96=87=E4=BB=B6=E3=80=82 + +=E6=9C=80=E5=80=BC=E5=BE=97=E6=B3=A8=E6=84=8F=E7=9A=84=E6=98=AF=EF=BC=8C= =E5=9C=A8 x509.genkey =E6=96=87=E4=BB=B6=E4=B8=AD=EF=BC=8Creq_distinguished= _name =E9=83=A8=E5=88=86=E5=BA=94=E4=BB=8E=E9=BB=98=E8=AE=A4=E5=80=BC +=E6=9B=B4=E6=94=B9:: + + [ req_distinguished_name ] + #O =3D Unspecified company + CN =3D Build time autogenerated kernel key + #emailAddress =3D unspecified.user@unspecified.company + +=E7=94=9F=E6=88=90=E7=9A=84 RSA =E5=AF=86=E9=92=A5=E5=A4=A7=E5=B0=8F=E4=B9= =9F=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5=E4=B8=8B=E6=96=B9=E5=BC=8F= =E8=AE=BE=E7=BD=AE:: + + [ req ] + default_bits =3D 4096 + +=E4=B9=9F=E5=8F=AF=E4=BB=A5=E4=BD=BF=E7=94=A8=E4=BD=8D=E4=BA=8E Linux =E5= =86=85=E6=A0=B8=E6=BA=90=E4=BB=A3=E7=A0=81=E6=A0=91=E6=A0=B9=E8=8A=82=E7=82= =B9=E4=B8=AD=E7=9A=84 x509.genkey =E5=AF=86=E9=92=A5=E7=94=9F=E6=88=90=E9= =85=8D=E7=BD=AE=E6=96=87=E4=BB=B6=E5=92=8C +openssl =E5=91=BD=E4=BB=A4=E6=89=8B=E5=8A=A8=E7=94=9F=E6=88=90=E5=85=AC=E9= =92=A5/=E7=A7=81=E9=92=A5=E6=96=87=E4=BB=B6=E3=80=82=E4=BB=A5=E4=B8=8B=E6= =98=AF=E7=94=9F=E6=88=90=E5=85=AC=E9=92=A5/=E7=A7=81=E9=92=A5=E6=96=87=E4= =BB=B6=E7=9A=84=E7=A4=BA=E4=BE=8B:: + + openssl req -new -nodes -utf8 -sha256 -days 36500 -batch -x509 \ + -config x509.genkey -outform PEM -out kernel_key.pem \ + -keyout kernel_key.pem + +=E7=84=B6=E5=90=8E=E5=8F=AF=E4=BB=A5=E5=B0=86=E7=94=9F=E6=88=90=E7=9A=84 k= ernel_key.pem =E6=96=87=E4=BB=B6=E7=9A=84=E5=AE=8C=E6=95=B4=E8=B7=AF=E5=BE= =84=E5=90=8D=E6=8C=87=E5=AE=9A=E5=9C=A8 +``CONFIG_MODULE_SIG_KEY``=E9=80=89=E9=A1=B9=E4=B8=AD=EF=BC=8C=E5=B9=B6=E4= =B8=94=E5=B0=86=E4=BD=BF=E7=94=A8=E5=85=B6=E4=B8=AD=E7=9A=84=E8=AF=81=E4=B9= =A6=E5=92=8C=E5=AF=86=E9=92=A5=E8=80=8C=E4=B8=8D=E6=98=AF=E8=87=AA=E5=8A=A8= =E7=94=9F=E6=88=90=E7=9A=84 +=E5=AF=86=E9=92=A5=E5=AF=B9=E3=80=82 + + +=E5=86=85=E6=A0=B8=E4=B8=AD=E7=9A=84=E5=85=AC=E9=92=A5 +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +=E5=86=85=E6=A0=B8=E5=8C=85=E5=90=AB=E4=B8=80=E4=B8=AA=E5=8F=AF=E7=94=B1 r= oot =E6=9F=A5=E7=9C=8B=E7=9A=84=E5=85=AC=E9=92=A5=E7=8E=AF=E3=80=82=E5=AE= =83=E4=BB=AC=E5=9C=A8=E5=90=8D=E4=B8=BA ".builtin_trusted_keys" =E7=9A=84= =E5=AF=86 +=E9=92=A5=E7=8E=AF=E4=B8=AD=EF=BC=8C=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87= =E4=BB=A5=E4=B8=8B=E6=96=B9=E5=BC=8F=E6=9F=A5=E7=9C=8B:: + + [root@deneb ~]# cat /proc/keys + ... + 223c7853 I------ 1 perm 1f030000 0 0 keyring .builtin_trust= ed_keys: 1 + 302d2d52 I------ 1 perm 1f010000 0 0 asymmetri Fedora kernel = signing key: d69a84e6bce3d216b979e9505b3e3ef9a7118079: X509.RSA a7118079 [] + +=E9=99=A4=E4=BA=86=E4=B8=93=E9=97=A8=E4=B8=BA=E6=A8=A1=E5=9D=97=E7=AD=BE= =E5=90=8D=E7=94=9F=E6=88=90=E7=9A=84=E5=85=AC=E9=92=A5=E5=A4=96=EF=BC=8C=E8= =BF=98=E5=8F=AF=E4=BB=A5=E5=9C=A8 ``CONFIG_SYSTEM_TRUSTED_KEYS`` =E9=85=8D= =E7=BD=AE +=E9=80=89=E9=A1=B9=E5=BC=95=E7=94=A8=E7=9A=84 PEM =E7=BC=96=E7=A0=81=E6=96= =87=E4=BB=B6=E4=B8=AD=E6=8F=90=E4=BE=9B=E5=85=B6=E4=BB=96=E5=8F=97=E4=BF=A1= =E4=BB=BB=E7=9A=84=E8=AF=81=E4=B9=A6=E3=80=82 + +=E6=AD=A4=E5=A4=96=EF=BC=8C=E6=9E=B6=E6=9E=84=E4=BB=A3=E7=A0=81=E5=8F=AF= =E4=BB=A5=E4=BB=8E=E7=A1=AC=E4=BB=B6=E5=AD=98=E5=82=A8=E4=B8=AD=E8=8E=B7=E5= =8F=96=E5=85=AC=E9=92=A5=E5=B9=B6=E5=B0=86=E5=85=B6=E6=B7=BB=E5=8A=A0=EF=BC= =88=E4=BE=8B=E5=A6=82=E4=BB=8E UEFI =E5=AF=86=E9=92=A5=E6=95=B0=E6=8D=AE=E5= =BA=93=EF=BC=89=E3=80=82 + +=E6=9C=80=E5=90=8E=EF=BC=8C=E5=8F=AF=E4=BB=A5=E9=80=9A=E8=BF=87=E4=BB=A5= =E4=B8=8B=E6=96=B9=E5=BC=8F=E6=B7=BB=E5=8A=A0=E5=85=B6=E4=BB=96=E5=85=AC=E9= =92=A5:: + + keyctl padd asymmetric "" [.builtin_trusted_keys-ID] <[key-file] + +=E4=BE=8B=E5=A6=82:: + + keyctl padd asymmetric "" 0x223c7853