跳至主要内容

syslock 指令

使用此指令可顯示和配置系統鎖定設定。

語法:
syslock [-options]
表 1. syslock 選項
選項說明
-en啟用或停用系統配置鎖定功能。
透過 -e 選項啟用可將目前清單升級為受信任快照。
enabled, disabled
-e啟用系統配置鎖定設定,但不一定強制將目前清單作為受信任快照。
如果沒有 -e 選項,則會設定預設值。
enabled, disabled
-l [x]列出索引 x 處特定快照的清單。在指令選項中,索引編號 x 指定為整數。
-m拍攝手動快照。 
-d手動快照的說明。最多 32 個字元的字串。
-c列出與受信任快照的清單差異。 
-po設定鎖定原則。
如果系統防護處於不符合標準的狀態,此動作將防止伺服器啟動。
none, osboot, pperm
-cpu設定 CPU 鎖定。on, off
-dimm設定 DIMM 鎖定。on, off
-pci設定 PCI 鎖定。on, off
-drive設定硬碟鎖定。on, off
-riser設定擴充卡鎖定。on, off
-bp設定背板鎖定。on, off
To show current status and snapshot list (trusted and history)
system> syslock
Current status: disabled
Policy: none
cpu: off
dXCC: off
pci: off
drive: off
riser: off
bp: off

No snapshot.

System changes have been detected!
Index In Use Date Description
----- -------- ------------------- ----------------
1 Yes 28/01/2022 15:32:59 Enforced by XCCroot.
2 No 28/01/2022 15:28:16 Boot by BMC.

system> syslock
Current status: disabled
Policy: none
cpu: off
dXCC: off
pci: off
drive: off
riser: off
bp: off

To list inventory of specific snapshot
system> syslock -l 1
Location Component ID Description
--------- -------------- ----------------
To enable/disable function.(enable with passphrase, and/or promote current inventory as trusted snapshot):
system> syslock -en enabled
ok
system> syslock -en disabled
ok
system> syslock -en disabled -p Passw0rd12 -e disabled
ok
To take manual snapshot:
system> syslock -m -d xyz
ok
To list inventory difference from trusted snapshot
System>syslock -c
system configuration changes have been detected:

Difference Location ID Description
-------------- ---------- --------------- ----------------------------------------------------------------
New device Drive 13 S0K2QRYC Drive 13, IBM-ESXS, 300GB 10K 6Gbps SAS 2.5"

To set lockdown policy:
system> syslock -po none/pperm/osboot

To set lockdown components:
system>syslock -cpu <on | off>
system>syslock -dXCC <on | off>
system>syslock -pci <on | off>
system>syslock -drive <on | off>
system>syslock -tpm <on | off>
system>syslock -riser <on | off>
system>syslock -bp <on | off>
system>syslock -board <on | off>
system>syslock -psu <on | off>
system>syslock -fan <on | off>
system>syslock -xccfw <on | off>
system>syslock -uefifw <on | off>