UEFI Secure Boot용 AWS 바이너리 블롭(blob) 만들기

UEFI Secure Boot용 AWS 바이너리 블롭(blob) 만들기 (Create the AWS binary blob for UEFI Secure Boot)

다음 단계로 AMI 생성 중에 UEFI Secure Boot 변수를 커스터마이즈할 수 있어요. 이 단계에서 사용하는 KEK는 2021년 9월 기준 최신 값이에요. Microsoft가 KEK를 갱신하면 최신 KEK를 사용해야 해요.

출처: 문서

본문

AWS 바이너리 블롭 만들기

  1. 빈 PK 서명 목록(signature list)을 만들어요.
touch empty_key.crt
cert-to-efi-sig-list empty_key.crt PK.esl
  1. KEK 인증서를 다운로드해요.
https://go.microsoft.com/fwlink/?LinkId=321185
  1. KEK 인증서를 UEFI 서명 목록(siglist)으로 감싸요.
sbsiglist --owner 77fa9abd-0359-4d32-bd60-28f4e78f784b --type x509 --output MS_Win_KEK.esl MicCorKEKCA2011_2011-06-24.crt
  1. Microsoft의 db 인증서를 다운로드해요.
https://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt
https://www.microsoft.com/pkiops/certs/MicCorUEFCA2011_2011-06-27.crt
  1. db 서명 목록을 생성해요.
sbsiglist --owner 77fa9abd-0359-4d32-bd60-28f4e78f784b --type x509 --output MS_Win_db.esl MicWinProPCA2011_2011-10-19.crt
sbsiglist --owner 77fa9abd-0359-4d32-bd60-28f4e78f784b --type x509 --output MS_UEFI_db.esl MicCorUEFCA2011_2011-06-27.crt
cat MS_Win_db.esl MS_UEFI_db.esl > MS_db.esl
  1. Unified Extensible Firmware Interface Forum은 더 이상 DBX 파일을 제공하지 않아요. 이제 Microsoft가 GitHub에서 제공해요. 최신 DBX 업데이트를 https://github.com/microsoft/secureboot_objects 의 Microsoft Secure Boot 업데이트 저장소에서 다운로드해요.
  2. 서명된 update-binary를 풀어요. 아래의 스크립트 내용으로 SplitDbxContent.ps1을 만들어요. 또는 PowerShell Gallery에서 Install-Script -Name SplitDbxContent으로 스크립트를 설치할 수 있어요.
    # Get file from script input
    $file = Get-Content -Encoding Byte $args[0]
    # Identify file signature
    $chop = $file[40..($file.Length - 1)]
    if (($chop[0] -ne 0x30) -or ($chop[1] -ne 0x82 )) {
        Write-Error "Cannot find signature"
        exit 1
    }
    # Signature is known to be ASN size plus header of 4 bytes
    $sig_length = ($chop[2] * 256) + $chop[3] + 4
    $sig = $chop[0..($sig_length - 1)]
    if ($sig_length -gt ($file.Length + 40)) {
        Write-Error "Signature longer than file size!"
        exit 1
    }
    # Content is everything else
    $content = $file[0..39] + $chop[$sig_length..($chop.Length - 1)]
    # Write signature and content to files
    Set-Content -Encoding Byte signature.p7 $sig
    Set-Content -Encoding Byte content.bin $content

이 스크립트를 사용해 서명된 DBX 파일을 풀어요.

PS C:\Windows\system32> SplitDbxContent.ps1 .\dbx.bin

이렇게 하면 signature.p7과 content.bin 두 파일이 생성돼요. 다음 단계에서 content.bin을 사용해요. 8. uefivars.py 스크립트로 UEFI 변수 저장소를 만들어요.

./uefivars.py -i none -o aws -O uefiblob-microsoft-keys-empty-pk.bin -P ~/PK.esl -K ~/MS_Win_KEK.esl --db ~/MS_db.esl --dbx ~/content.bin
  1. 바이너리 블롭과 UEFI 변수 저장소를 확인해요.
./uefivars.py -i aws -I uefiblob-microsoft-keys-empty-pk.bin -o json | less
  1. 같은 도구에 다시 전달해서 블롭을 갱신할 수 있어요.
./uefivars.py -i aws -I uefiblob-microsoft-keys-empty-pk.bin -o aws -O uefiblob-microsoft-keys-empty-pk.bin -P ~/PK.esl -K ~/MS_Win_KEK.esl --db ~/MS_db.esl --dbx ~/content.bin
예상 출력:
Replacing PK
Replacing KEK
Replacing db
Replacing dbx

더 알아보기 (Learn more)