LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-30-2023, 12:14 AM   #1
anthonyforwood
LQ Newbie
 
Registered: Dec 2022
Location: Vancouver, BC
Distribution: Ubuntu 22.04.03 LTS w/ Gnome 42.9 and X11
Posts: 29

Rep: Reputation: 1
Question What to do about kernel lockdown?[


I made a disk image of an external HDD (sdb) in Disks a while back and stored it on a partition on another external HDD. After having changed the USB ports for my several different external HDDs over time, I realized that the name associated with the original HDD (sdb) wasn't using the same port as it originally had been, and not really understanding (until now) that the image file is constantly updated, I thought I could just delete the image file, which I did.

When I later ran dmesg -w while doing something else, I got a message that said /dev/mem, /dev/kmem, and one of my ports (can't remember the exact port # at this point) were restricted and referred me to see man kernel_lockdown.7, where I discovered I shouldn't have erased the image file. Everything has been fine otherwise, but there are obviously issues with EFI and Secure Boot mode, now that I've rebooted my system.

Running dmesg after rebooting, I get:

[ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7

There's a note in the man file that I don't understand:

Quote:
NOTES
The Kernel Lockdown feature is enabled by CONFIG_SECURITY_LOCKDOWN_LSM. The lsm=lsm1,...,lsmN command line parameter
controls the sequence of the initialization of Linux Security Modules. It must contain the string lockdown to enable
the Kernel Lockdown feature. If the command line parameter is not specified, the initialization falls back to the value
of the deprecated security= command line parameter and further to the value of CONFIG_LSM.
What do I need to do to fix this problem and put things back in order? Any help would be appreciated.
 
Old 05-30-2023, 05:26 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
This message:
Code:
[ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
is not indicating an error. It just indicates that your computer is in secure boot mode. It is generally a good thing that your firmware and boot image can't be tampered with, even if your computer is infected with malware.

It's not clear to me that you have a problem that needs to be fixed. Disk names are not consistent between reboots if you add or remove drives. This is normal. The kernel doesn't change, it just names the drives in the order they are found.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
bpftrace on ubuntu fails with Kernel lockdown is enabled and set to 'confidentiality' clivesa Linux - Kernel 1 06-30-2021 11:04 PM
Question for signing module in kernel 5.4 with lockdown enabled l12436 Linux - Kernel 0 11-28-2019 12:45 PM
LXer: Linux Kernel 5.4 Officially Released with exFAT Support, Kernel Lockdown Feature LXer Syndicated Linux News 0 11-24-2019 08:41 PM
"Linux Kernel Finally Gets Its Lockdown" jamison20000e Linux - Security 1 10-05-2019 10:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration