[Problem feedback] 在导入新的安全启动证书后不能正常启动
Tofloor
poster avatar
虔诚的阿库西斯教徒
deepin
2025-04-16 08:32
Author

在导入我的移动硬盘里的自签名证书后,开启安全启动启动电脑内的deepin时会提示以下错误:

IMG_20250415_224653.jpg

即使恢复出厂设置,并使用 mokutil删除导入的证书,问题依然存在。

mokutil --list-enrolled返回的结果如下:

# mokutil --list-enrolled
[key 1]
SHA1 Fingerprint: e4:a4:d8:5f:eb:a0:f5:28:9d:e5:ca:5e:7f:89:08:e3:58:68:d1:3b
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0c:56:87:95:2b:8f:7e:68:ce:f7:d3:f9:b6:e5:57:50:54:d8:fb:a4
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=CN, ST=Hubei, L=Wuhan, O=Wuhan Deepin Technology Co., Ltd., OU=Secure Boot Maintenance Department., CN=Deepin Secure Boot CA
        Validity
            Not Before: Jun 10 12:42:56 2020 GMT
            Not After : Jun  3 12:42:56 2050 GMT
        Subject: C=CN, ST=Hubei, L=Wuhan, O=Wuhan Deepin Technology Co., Ltd., OU=Secure Boot Maintenance Department., CN=Deepin Secure Boot CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    00:b6:c1:fd:20:83:ce:c0:03:8c:2c:d0:e9:d4:5c:
                    f0:09:e1:4b:d4:e1:ee:a3:5b:2d:dd:dc:b6:7d:63:
                    73:f7:0d:76:d8:5b:6e:02:ac:36:5a:6b:a8:22:ca:
                    65:0c:3a:e1:25:e7:19:42:0e:3f:6a:c0:71:ba:7c:
                    0b:e3:45:78:a6:12:e4:46:10:2e:48:af:a9:e2:00:
                    01:55:d2:ae:2b:03:5d:07:a6:e8:a0:51:0a:5c:fc:
                    f7:de:f1:25:72:0b:4f:c5:d9:9c:58:fc:73:8a:2c:
                    8f:fa:4d:5a:3e:08:a0:71:8f:50:15:1a:e8:90:e8:
                    48:9a:4c:5e:ad:ae:aa:10:6a:f6:a7:44:8b:56:aa:
                    38:f5:be:d2:ac:67:f9:1b:a6:f0:10:69:6b:df:36:
                    ac:ca:8c:51:7d:a7:65:33:7e:8c:a6:ef:20:b4:73:
                    57:97:4c:4b:d1:21:58:39:de:c8:4e:1d:64:bc:fc:
                    be:75:5b:fe:a1:c9:2f:12:8f:e5:f8:cf:ab:70:68:
                    39:98:df:cd:a5:8c:7c:e2:02:6b:65:f6:aa:51:29:
                    4c:3a:13:69:e6:6e:70:16:59:26:a9:2a:d6:f8:25:
                    ae:9b:2c:c6:a4:8d:0c:a7:9a:13:31:9c:4c:e9:ce:
                    4c:2d:a9:4a:dd:e9:c0:c4:f7:b4:2b:31:17:18:98:
                    57:f6:36:16:56:ef:fd:41:8f:e4:71:3d:4b:de:06:
                    db:ee:97:65:31:0f:d6:db:b5:80:f3:fd:65:2d:2f:
                    16:11:db:c2:21:d7:61:6a:75:8b:f2:67:79:20:6e:
                    8e:fd:e7:f3:46:38:be:be:55:fe:d2:e6:d8:83:1e:
                    29:98:17:aa:e2:f8:a3:64:f5:28:d2:39:62:07:9c:
                    f0:89:29:20:08:60:d8:d2:21:ea:38:0e:58:74:21:
                    24:47:4c:8c:f0:f7:d6:3b:27:5c:d5:1d:d1:e6:69:
                    78:b2:67:0c:8f:6a:11:91:55:0b:76:20:57:a7:c3:
                    db:06:88:bc:aa:26:9b:4c:69:c5:2d:84:f8:c3:52:
                    51:e9:6f:10:d7:36:e1:0a:34:91:31:9a:63:96:62:
                    6e:54:51:28:53:8d:d9:2a:3d:82:4c:93:c7:16:c2:
                    c2:1b:cf:b2:ce:77:bf:2a:be:af:5c:29:66:ad:10:
                    37:2d:74:16:4a:38:cf:38:68:1b:b5:9d:c2:05:c9:
                    df:80:2b:8e:8c:c2:88:e5:74:90:ae:e0:28:d7:08:
                    70:47:73:2d:95:6b:a5:06:94:39:0d:d3:d8:00:83:
                    9b:09:60:9d:e6:73:c4:26:57:7a:1b:5b:ee:50:b5:
                    f7:69:5c:1d:d2:b3:45:13:cb:27:13:f1:28:26:f0:
                    bb:c8:5b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            Authority Information Access: 
                CA Issuers - URI:https://www.deepin.com/crt/secure-boot-ca
            Netscape Cert Type: 
                SSL Client, SSL Server, S/MIME, Object Signing, SSL CA, S/MIME CA, Object Signing CA
            X509v3 Extended Key Usage: 
                Code Signing
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Subject Key Identifier: 
                46:84:59:49:14:E0:59:AE:E3:27:90:69:57:48:A1:85:C6:7D:81:A0
            X509v3 Authority Key Identifier: 
                46:84:59:49:14:E0:59:AE:E3:27:90:69:57:48:A1:85:C6:7D:81:A0
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        8c:8d:ff:96:de:cb:43:b8:a9:df:a9:31:b4:1e:18:0e:52:94:
        e7:8c:5d:cf:0c:78:dc:09:75:64:5a:89:d9:73:76:07:e2:09:
        e4:ad:00:07:c1:be:14:0c:c8:fd:ff:fc:8e:7b:e8:4a:b1:49:
        a8:a5:a5:ce:4f:5a:7f:51:46:d0:99:cf:c2:76:9e:c8:5d:01:
        b1:80:f9:31:c8:4c:60:f6:d3:46:03:bd:2e:57:e4:b8:c5:ed:
        ab:a3:da:93:36:37:f2:d3:08:0c:5a:d2:ce:f9:69:9d:55:3e:
        ce:06:c7:80:7f:97:bc:dd:85:38:b8:1d:a5:1f:f7:72:1a:87:
        72:8a:75:79:f2:7f:d0:8d:d4:ad:0d:92:2e:24:22:cb:a8:ac:
        68:d7:af:0d:4d:8f:9d:ca:f6:dc:5b:3f:cd:37:ab:c0:66:3b:
        31:e9:1f:d4:86:ab:21:fd:f0:b3:87:2f:86:ec:0c:bb:a8:90:
        fc:b3:6d:de:18:2c:b4:5b:a1:9b:ec:74:39:fb:18:02:84:03:
        d6:26:b7:e8:55:73:71:3c:bd:80:64:fe:01:ed:27:43:df:e2:
        db:a2:75:c1:e5:4e:4e:87:d3:c6:65:e4:c8:04:46:1e:62:9a:
        bd:60:47:06:d8:68:7e:fa:18:92:00:90:e4:2c:fd:0f:22:68:
        79:96:4e:c9:45:ee:83:86:b6:d0:fb:23:53:57:98:5c:9e:c5:
        75:62:ca:06:c1:fa:9e:de:7a:ab:a5:ed:de:e4:fc:0f:ae:d6:
        8e:3b:96:7a:17:d3:b8:56:2a:f8:9e:7a:ef:e7:0a:19:8c:f9:
        12:3e:04:54:05:b5:80:8e:89:5e:5a:d4:3c:42:c5:5f:a3:ba:
        dc:80:12:67:a3:8e:1c:ec:06:cb:80:8d:a3:1f:b3:a0:94:8d:
        a1:94:31:2d:7e:58:a9:27:51:8b:d9:aa:90:94:77:e0:9c:91:
        74:f3:01:16:fd:f9:ec:6e:68:0b:eb:b5:0b:94:f7:53:f4:a0:
        4d:ac:ff:ca:07:29:d0:d2:10:e9:c4:55:9f:b8:01:eb:50:22:
        33:9c:da:54:91:d6:a3:85:a8:2f:f8:1c:38:93:1a:db:57:ec:
        29:8f:1b:62:75:9b:09:1a:43:ab:dd:6d:e7:37:c1:46:ec:dc:
        83:34:fa:7d:3d:65:bb:ef:70:3d:27:4a:27:d2:65:d9:62:4a:
        73:c1:0b:75:18:6e:62:17:2c:46:84:4c:dc:c9:ac:13:79:6c:
        ba:6c:a3:68:0e:27:71:2f:2b:c1:03:f6:a2:e4:65:65:bd:a0:
        7b:a4:66:ee:ca:94:f1:11:46:dd:3a:9a:11:17:c8:fb:c3:09:
        40:3a:ec:53:f1:41:a2:11

现在不知道怎么解决

Reply Favorite View the author
All Replies
欢乐马
deepin
2025-04-16 09:14
#1

shim的签名被破坏了,可以重新安装一下grub试一下

Reply View the author
虔诚的阿库西斯教徒
deepin
2025-04-16 09:21
#2
欢乐马

shim的签名被破坏了,可以重新安装一下grub试一下

apt reinstall grub-efi-amd64-signed grub-efi-amd64-bin试过了,不行

Reply View the author
花雨落逝
Moderator
2025-04-16 09:46
#3

有个笨办法不知道有没有效果,chroot进去 ,aptitude reinstall '~i' 来重新安装已安装的所有软件包

Reply View the author
虔诚的阿库西斯教徒
deepin
2025-04-16 10:35
#4
花雨落逝

有个笨办法不知道有没有效果,chroot进去 ,aptitude reinstall '~i' 来重新安装已安装的所有软件包

感觉重新安装没有用,我对比了哈希值是一样的,实在无法理解我安装新的证书会影响deepin的shim。

# b2sum /usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed /boot/efi/EFI/deepin/grubx64.efi 
7420d7eb640f73e9f66d01a07377581041b902ba5e08b40184861f048663465f8463fcb3ce2d22078fb32a6ab494d99ecb836d538f00e6c1819af54602fceae4  /usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed
7420d7eb640f73e9f66d01a07377581041b902ba5e08b40184861f048663465f8463fcb3ce2d22078fb32a6ab494d99ecb836d538f00e6c1819af54602fceae4  /boot/efi/EFI/deepin/grubx64.efi
# b2sum /usr/lib/shim/*.signed  /boot/efi/EFI/deepin/fbx64.efi /boot/efi/EFI/deepin/mmx64.efi  /boot/efi/EFI/deepin/shimx64.efi 
fb992702902c75a00d85306bdf88011e6dfed87c2d9c48a18436abf3619e93377f70caacbe821b17a8f9ae2b00225b9d1c86e3d1e7d791894d0e4e7679da903c  /usr/lib/shim/fbx64.efi.signed
8e3c65693e10344cdc17ff51bc8e743a151e425ad73ead9759732f952d8d6d8b1eebf1b2b4bd3082171e10a20f6f733a52406ea2d727ff995a31cc4d9cddbc98  /usr/lib/shim/mmx64.efi.signed
dc6f8a3ecb4b34f05d9dee00767c17bfadfe5740a7419e21d99a63924c18e73d7351ee2246c13b39bbe397e82ce2ecf65d52b66535d40794a58bd47c3351874d  /usr/lib/shim/shimx64.efi.signed
fb992702902c75a00d85306bdf88011e6dfed87c2d9c48a18436abf3619e93377f70caacbe821b17a8f9ae2b00225b9d1c86e3d1e7d791894d0e4e7679da903c  /boot/efi/EFI/deepin/fbx64.efi
8e3c65693e10344cdc17ff51bc8e743a151e425ad73ead9759732f952d8d6d8b1eebf1b2b4bd3082171e10a20f6f733a52406ea2d727ff995a31cc4d9cddbc98  /boot/efi/EFI/deepin/mmx64.efi
dc6f8a3ecb4b34f05d9dee00767c17bfadfe5740a7419e21d99a63924c18e73d7351ee2246c13b39bbe397e82ce2ecf65d52b66535d40794a58bd47c3351874d  /boot/efi/EFI/deepin/shimx64.efi
Reply View the author
花雨落逝
Moderator
2025-04-16 14:08
#5
虔诚的阿库西斯教徒

感觉重新安装没有用,我对比了哈希值是一样的,实在无法理解我安装新的证书会影响deepin的shim。

# b2sum /usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed /boot/efi/EFI/deepin/grubx64.efi 
7420d7eb640f73e9f66d01a07377581041b902ba5e08b40184861f048663465f8463fcb3ce2d22078fb32a6ab494d99ecb836d538f00e6c1819af54602fceae4  /usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed
7420d7eb640f73e9f66d01a07377581041b902ba5e08b40184861f048663465f8463fcb3ce2d22078fb32a6ab494d99ecb836d538f00e6c1819af54602fceae4  /boot/efi/EFI/deepin/grubx64.efi
# b2sum /usr/lib/shim/*.signed  /boot/efi/EFI/deepin/fbx64.efi /boot/efi/EFI/deepin/mmx64.efi  /boot/efi/EFI/deepin/shimx64.efi 
fb992702902c75a00d85306bdf88011e6dfed87c2d9c48a18436abf3619e93377f70caacbe821b17a8f9ae2b00225b9d1c86e3d1e7d791894d0e4e7679da903c  /usr/lib/shim/fbx64.efi.signed
8e3c65693e10344cdc17ff51bc8e743a151e425ad73ead9759732f952d8d6d8b1eebf1b2b4bd3082171e10a20f6f733a52406ea2d727ff995a31cc4d9cddbc98  /usr/lib/shim/mmx64.efi.signed
dc6f8a3ecb4b34f05d9dee00767c17bfadfe5740a7419e21d99a63924c18e73d7351ee2246c13b39bbe397e82ce2ecf65d52b66535d40794a58bd47c3351874d  /usr/lib/shim/shimx64.efi.signed
fb992702902c75a00d85306bdf88011e6dfed87c2d9c48a18436abf3619e93377f70caacbe821b17a8f9ae2b00225b9d1c86e3d1e7d791894d0e4e7679da903c  /boot/efi/EFI/deepin/fbx64.efi
8e3c65693e10344cdc17ff51bc8e743a151e425ad73ead9759732f952d8d6d8b1eebf1b2b4bd3082171e10a20f6f733a52406ea2d727ff995a31cc4d9cddbc98  /boot/efi/EFI/deepin/mmx64.efi
dc6f8a3ecb4b34f05d9dee00767c17bfadfe5740a7419e21d99a63924c18e73d7351ee2246c13b39bbe397e82ce2ecf65d52b66535d40794a58bd47c3351874d  /boot/efi/EFI/deepin/shimx64.efi

抱歉,我也不是很懂,只能帮你到这了

Reply View the author
虔诚的阿库西斯教徒
deepin
2025-04-16 15:06
#6
花雨落逝

抱歉,我也不是很懂,只能帮你到这了

不管如何,感谢你的回复

Reply View the author
花雨落逝
Moderator
2025-04-19 10:06
#7
虔诚的阿库西斯教徒

不管如何,感谢你的回复

不客气

Reply View the author
气氛组组长
deepin
2025-04-24 10:43
#8

你已经搞得差不多了,换一下shim就行,参考这里:https://bbs.deepin.org/post/286586

Reply View the author