LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-11-2018, 05:56 PM   #1
gglq000
Member
 
Registered: Mar 2012
Posts: 65

Rep: Reputation: Disabled
Format of linux ko modules


I am doing some investigation on secure boot features. I got the overall understanding of how trust chain from firmware all the way to kernel modules.
Basically how bootloader, shim.efi, grubx64.efi care chain signed.
For shim.efi, grubx64.efi I did some own experimental verification to see how it is signed.

For that I wrote simple python script that extracts certificate (public part) from its blob and display it. My python script works on these modules because those *efi files are PE/PE+ compatible module. Therefore I can see the public part of cert-s embedded in those blob.

However I grabbed some of the ko modules from linux using lsmod, modinfo and when try to parse using some scripts, it does not work. Apparently the linux ko files are not PE/PE+ compatible. Can someone shed some light on how these ko modules are built? Thanks.,
 
Old 12-12-2018, 11:43 AM   #2
lougavulin
Member
 
Registered: Jul 2018
Distribution: Slackware,x86_64,current
Posts: 279

Rep: Reputation: 100Reputation: 100
Did you read Kernel module signing facility ?

And maybe also, rebuild your kernel without modules you don't need.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Linux Security Modules Sans Modules LXer Syndicated Linux News 0 10-20-2007 11:01 PM
Re: modprobe: Note: /etc/modules.conf is more recent than lib/modules/2.4.9/modules.d Andy.M Linux - General 1 01-24-2002 01:50 AM
Re: modprobe: Note: /etc/modules.conf is more recent than lib/modules/2.4.9/modules.d Andy.M Linux - Newbie 2 01-24-2002 01:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration