Skip to main content

secure-boot

Report UEFI Secure Boot configuration on an Intel edge platform - enabled state, Setup Mode, and enrolled PK/KEK/db keys. Use when asked about Secure Boot status or boot chain key enrollment.

소스 정보

저장소
open-edge-platform/trusted-compute
최근 소스 활동
2026년 8월 11일 05:15
감지된 SKILL.md 언어
영어
스타
25
포크
4

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
secure-boot
description
Report UEFI Secure Boot configuration on an Intel edge platform - enabled state, Setup Mode, and enrolled PK/KEK/db keys. Use when asked about Secure Boot status or boot chain key enrollment.
metadata
{"openclaw":{"emoji":"🔒","os":["linux"],"requires":{"bins":"[Truncated]"}}}
# Secure Boot Configuration Skill ## Purpose This skill reports the current UEFI Secure Boot configuration on the target system. ## What to Report - Secure Boot status (Enabled/Disabled) - Setup Mode status (Enabled/Disabled) - Platform Key (PK) presence - Key Exchange Keys (KEK) enrolled - Signature database (db) entries ## Commands ### Check Secure Boot Status ```bash # Check if Secure Boot is enabled mokutil --sb-state # Alternative: Check EFI variable directly. # The first 4 bytes are the EFI attributes header, so skip them and read 1 data byte. cat /sys/firmware/efi/efivars/SecureBoot-* 2>/dev/null | od -An -t u1 -j 4 -N 1 | tr -d ' ' ``` **Interpreting Output:** - `SecureBoot enabled` → Secure Boot is active - Data byte value `1` → Enabled, `0` → Disabled ### Check Setup Mode ```bash mokutil --sb-state | grep -i "setup mode" # Alternative: Check EFI variable directly. # The first 4 bytes are the EFI attributes header, so skip them and read 1 data byte. cat /sys/firmware/efi/efivars/SetupMode-* 2>/dev/null | od -An -t u1 -j 4 -N 1 | tr -d ' ' ``` **Interpreting Output:** - Value `0` → Setup Mode disabled (normal operation) - Value `1` → Setup Mode enabled (keys can be modified) ### Check Secure Boot Keys ```bash # Platform Key (PK) mokutil --pk # Key Exchange Keys (KEK) mokutil --kek # Signature database (db) mokutil --db # List all enrolled keys mokutil --list-enrolled ``` ## Output Format ``` SECURE BOOT Status: Enabled/Disabled Setup Mode: Enabled/Disabled Platform Key (PK): Present/Not Found Key Exchange Keys (KEK): X enrolled Signature Database (db): X entries ``` ## Dependencies - `mokutil` package - EFI boot mode (not legacy BIOS) - Access to `/sys/firmware/efi/` filesystem
GitHub에서 보기