You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ELF格式的.exe后缀二进制文件签名与验证方法咨询

ELF格式的.exe后缀二进制文件签名与验证方法咨询

Hey there! Great question—let’s break this down clearly. First off: yes, you absolutely can sign an ELF binary even if it has a .exe file extension—the file suffix doesn’t matter here; what counts is the underlying ELF format, which fully supports digital signing using standard Linux tools. Below are practical methods to sign and verify your testFile.exe (ELF) binary:

签名方法

方法1:使用OpenSSL(通用、轻量)

This is the most straightforward approach for standalone file signing:

  1. 生成密钥对(如果还没有的话):
    # 创建2048位私钥(提示时设置强密码)
    openssl genrsa -out private_key.pem 2048
    # 从私钥导出公钥
    openssl rsa -in private_key.pem -pubout -out public_key.pem
    
  2. 对ELF二进制文件签名:
    我们会先计算文件的SHA256哈希,再用私钥对哈希签名:
    openssl dgst -sha256 -sign private_key.pem -out testFile.exe.sig testFile.exe
    
    执行后会生成一个testFile.exe.sig签名文件,请将它和原ELF文件放在一起保管。

方法2:使用IMA/EVM(系统级内核验证)

如果你需要让Linux内核原生信任该二进制文件的完整性,可以使用完整性测量架构(IMA)和扩展验证模块(EVM):

  1. 确保你的内核已启用IMA/EVM相关配置(通常需要通过发行版工具进行内核配置和系统设置)。
  2. 使用evmctl工具签名(需要系统信任的密钥对):
    evmctl sign --key private_key.pem testFile.exe
    
    这种方式会将签名元数据嵌入到文件的扩展属性中,内核在执行文件时会自动验证签名。

验证方法

验证OpenSSL签名

使用公钥确认文件未被篡改且签名有效:

openssl dgst -sha256 -verify public_key.pem -signature testFile.exe.sig testFile.exe
  • 验证通过时,会输出Verified OK
  • 文件被篡改或签名无效时,会输出Verification Failure

验证IMA/EVM签名

查看嵌入的签名元数据并验证:

# 查看EVM签名扩展属性
getfattr -m security.evm -d testFile.exe
# 验证签名
evmctl verify --key public_key.pem testFile.exe

最后提个小细节:.exe后缀只是个标识,Linux是通过ELF文件头识别可执行文件的,和后缀无关。你把文件重命名为testFile.elf或者其他任意名称,签名和验证流程都不会受影响。

备注:内容来源于stack exchange,提问作者Aniket

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 09:14:32