Nvidia Mellanox ConnectX-6 Lx handleiding

56 pagina's
PDF beschikbaar

Handleiding

Je bekijkt pagina 33 van 56
33
Mellanox Technologies
1.
2.
3.
1.
Please note, this feature is disabled by default. To enable the automatic firmware update upon system boot, set the following
parameter to “yes” “RUN_FW_UPDATER_ONBOOT=yes” in the openibd service configuration file “/etc/infiniband/openib.conf.
You can opt to exclude a list of devices from the automatic firmware update procedure. To do so, edit the configurations file “/opt/
mellanox/mlnx-fw-updater/mlnx-fw-updater.conf” and provide a comma separated list of PCI devices to exclude from the firmware
update.
Example:
MLNX_EXCLUDE_DEVICES="00:05.0,00:07.0"
4.1.7 UEFI Secure Boot
All kernel modules included in MLNX_OFED for RHEL7 and SLES12 are signed with x.509 key to support loading the modules when
Secure Boot is enabled.
4.1.7.1 Enrolling Mellanox's x.509 Public Key on Your Systems
In order to support loading MLNX_OFED drivers when an OS supporting Secure Boot boots on a UEFI-based system with Secure Boot
enabled, the Mellanox x.509 public key should be added to the UEFI Secure Boot key database and loaded onto the system key ring
by the kernel.
Follow these steps below to add the Mellanox's x.509 public key to your system:
Download the x.509 public key.
# wget http://www.mellanox.com/downloads/ofed/mlnx_signing_key_pub.der
Add the public key to the MOK list using the mokutil utility.
# mokutil --import mlnx_signing_key_pub.der
Reboot the system.
The pending MOK key enrollment request will be noticed by shim.efi and it will launch MokManager.efi to allow you to complete the
enrollment from the UEFI console. You will need to enter the password you previously associated with this request and confirm the
enrollment. Once done, the public key is added to the MOK list, which is persistent. Once a key is in the MOK list, it will be
automatically propagated to the system key ring and subsequent will be booted when the UEFI Secure Boot is enabled.
4.1.7.2 Removing Signature from kernel Modules
The signature can be removed from a signed kernel module using the 'strip' utility which is provided by the 'binutils' package. The
strip utility will change the given file without saving a backup. The operation can be undo only by resigning the kernel module.
Hence, we recommend backing up a copy prior to removing the signature.
To remove the signature from the MLNX_OFED kernel modules:
Remove the signature.
Prior to adding the Mellanox's x.509 public key to your system, please make sure that (1) The 'mokutil' package is installed
on your system, and (2) The system is booted in UEFI mode.
To see what keys have been added to the system key ring on the current boot, install the 'keyutils' package and run: #keyctl
list %:.system_keyring#

Bekijk gratis de handleiding van Nvidia Mellanox ConnectX-6 Lx, stel vragen en lees de antwoorden op veelvoorkomende problemen, of gebruik onze assistent om sneller informatie in de handleiding te vinden of uitleg te krijgen over specifieke functies.

Productinformatie

MerkNvidia
ModelMellanox ConnectX-6 Lx
CategorieNiet gecategoriseerd
TaalNederlands
Grootte10621 MB