<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LS1046A Secure Boot Issue error 0x341 in Layerscape</title>
    <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1635561#M12282</link>
    <description>&lt;P&gt;So another datapoint that hopefully will help. I went ahead and followed the steps for flashing from here&amp;nbsp;&lt;A href="https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-853E743B-D814-4DBF-BBA8-AE15AADE536A.html" target="_blank" rel="noopener"&gt;https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-853E743B-D814-4DBF-BBA8-AE15AADE536A.html&lt;/A&gt;&amp;nbsp;using&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;firmware_ls1046ardb_qspiboot_secure.img&lt;/PRE&gt;&lt;P&gt;instead of the non secure like the docs suggest. I reboot to the alt flash bank and attach and set my srkh mirror registers and still end up with the 0x341 error code and non-secure. So seems this isn't an issue with my build since its happening with a build directly from nxp as well? Thoughts?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 17:02:51 GMT</pubDate>
    <dc:creator>dmerrill</dc:creator>
    <dc:date>2023-04-18T17:02:51Z</dc:date>
    <item>
      <title>LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1626292#M12132</link>
      <description>&lt;P&gt;Hoping to get some insight into why I might be getting this error.&lt;/P&gt;&lt;P&gt;The Following is the output from the build of the header:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;/home/dmerrill/projects/hardware/bsp/build/tmp-glibc/work/ls1046ardb-oe-linux/atf/git-r0/recipe-sysroot-native/usr/bin/cst/create_hdr_isbc --in /home/dmerrill/devtool-workspace/atf/build/ls1046ardb/debug/bl2.bin --out /home/dmerrill/devtool-workspace/atf/build/ls1046ardb/debug/hdr_bl2 drivers/nxp/auth/csf_hdr_parser/input_bl2_ch2 --verbose&lt;BR /&gt;EL3 Runtime Firmware BL31: offset=0x88, size=0xF63D, cmdline="--soc-fw"&lt;BR /&gt;Non-Trusted Firmware BL33: offset=0xF6C5, size=0xD1436, cmdline="--nt-fw"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#----------------------------------------------------#&lt;BR /&gt;#------- -------- -------- -------#&lt;BR /&gt;#------- CST (Code Signing Tool) Version 2.0 -------#&lt;BR /&gt;#------- -------- -------- -------#&lt;BR /&gt;#----------------------------------------------------#&lt;BR /&gt;file name is /home/dmerrill/devtool-workspace/atf/build/ls1046ardb/debug/bl2.bin&lt;BR /&gt;file name is /home/dmerrill/devtool-workspace/atf/build/ls1046ardb/debug/hdr_bl2&lt;BR /&gt;?? getopt returned character code 00 ??&lt;/P&gt;&lt;P&gt;==========================================================&lt;BR /&gt;This tool includes software developed by OpenSSL Project&lt;BR /&gt;for use in the OpenSSL Toolkit (&lt;A href="http://www.openssl.org/" target="_blank"&gt;http://www.openssl.org/&lt;/A&gt;)&lt;BR /&gt;This product includes cryptographic software written by&lt;BR /&gt;Eric Young (eay@cryptsoft.com)&lt;BR /&gt;==========================================================&lt;/P&gt;&lt;P&gt;Input File is drivers/nxp/auth/csf_hdr_parser/input_bl2_ch2&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;BR /&gt;- Dumping the Header Fields&lt;BR /&gt;-----------------------------------------------&lt;BR /&gt;- SRK Information&lt;BR /&gt;- SRK Offset : 200&lt;BR /&gt;- SRK Flag = 1&lt;BR /&gt;- Number of Keys : 1&lt;BR /&gt;- Key Select : 1&lt;BR /&gt;- Key List :&lt;BR /&gt;- Key1 srk.pub(100)&lt;BR /&gt;- UID Information&lt;BR /&gt;- UID Flags = 00&lt;BR /&gt;- FSL UID = 00000000_00000000&lt;BR /&gt;- OEM UID = 00000000_00000000&lt;BR /&gt;- FLAGS Information&lt;BR /&gt;- Secondary Image = 0&lt;BR /&gt;- Manufacturing Protection = 1&lt;BR /&gt;- Image Information&lt;BR /&gt;- SG Table Offset : 800&lt;BR /&gt;- Number of entries : 1&lt;BR /&gt;- Entry Point : 10000000&lt;BR /&gt;- Entry 1 : /home/dmerrill/devtool-workspace/atf/build/ls1046ardb/debug/bl2.bin (Size = 000102ea src=10000000 DST = ffffffff)&lt;BR /&gt;- RSA Signature Information&lt;BR /&gt;- RSA Offset : a00&lt;BR /&gt;- RSA Size : 80&lt;BR /&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;Image Hash:&lt;BR /&gt;71b7fe65ee12a5da6555048a48871ad81c5a0b9d1e93a0421a6245d7a32886cb&lt;/P&gt;&lt;P&gt;************************************************&lt;BR /&gt;* Header File is with Signature appended&lt;BR /&gt;************************************************&lt;/P&gt;&lt;P&gt;Header File Created: /home/dmerrill/devtool-workspace/atf/build/ls1046ardb/debug/hdr_bl2&lt;/P&gt;&lt;P&gt;SRK (Public Key) Hash:&lt;BR /&gt;948b3f42396e770df696c178f5fff0f315d678052ceed215d38a94780360f66f&lt;BR /&gt;SFP SRKHR0 = 948b3f42&lt;BR /&gt;SFP SRKHR1 = 396e770d&lt;BR /&gt;SFP SRKHR2 = f696c178&lt;BR /&gt;SFP SRKHR3 = f5fff0f3&lt;BR /&gt;SFP SRKHR4 = 15d67805&lt;BR /&gt;SFP SRKHR5 = 2ceed215&lt;BR /&gt;SFP SRKHR6 = d38a9478&lt;BR /&gt;SFP SRKHR7 = 0360f66f&lt;/P&gt;&lt;P&gt;The bl2 is programmed into qspi and the srkh registers are programmed during boot hold off with the values as show in the attached image:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="srkh_regs.PNG" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/217383iFA7D6995104198F4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="srkh_regs.PNG" alt="srkh_regs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Boot is released, however once boot reaches BL2 it is set to non secure and SRATCHRW2 is set to 0x341. I can't figure out what about the signature is invalid. Any help would be appreciated. Thanks.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 20:20:20 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1626292#M12132</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-03-31T20:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627096#M12144</link>
      <description>&lt;P&gt;Any ideas on what to look at here or more information that could point out what is wrong would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 20:51:15 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627096#M12144</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-03T20:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627472#M12157</link>
      <description>&lt;P&gt;ISBC validation error codes&lt;/P&gt;
&lt;P style="font-family: Arial, sans-serif;"&gt;0x341 ERROR_HASH_COMPARE_EM RSA&lt;/P&gt;
&lt;P style="font-family: Arial, sans-serif;"&gt;signature check failure. Signature provided by you in&lt;BR /&gt;the header doesn’t match with the signature of the ESBC&lt;BR /&gt;image generated by ISBC. The ESBC image loaded by you&lt;BR /&gt;may be different than the image used while generating the&lt;BR /&gt;signature(using CST)&lt;/P&gt;
&lt;P style="font-family: Arial, sans-serif;"&gt;I notice in your build log image hash is printed as the following.&lt;/P&gt;
&lt;P style="font-family: Arial, sans-serif;"&gt;Image Hash:&lt;BR /&gt;71b7fe65ee12a5da6555048a48871ad81c5a0b9d1e93a0421a6245d7a32886cb&lt;/P&gt;
&lt;P style="font-family: Arial, sans-serif;"&gt;However SRK is as the following.&lt;/P&gt;
&lt;P style="font-family: Arial, sans-serif;"&gt;SRK (Public Key) Hash:&lt;BR /&gt;948b3f42396e770df696c178f5fff0f315d678052ceed215d38a94780360f66f&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please refer to the following command to build secure ATF image.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;make -s -j2 fip pbl PLAT=ls1046ardb BOOT_MODE=qspi RCW=/home/nxa22585/data/flexbuild_lsdk2108_bak/build/firmware/rcw/ls1046ardb/RR_FFSSPPPH_1133_5559/rcw_1600_qspiboot_sben.bin BL33=/home/nxa22585/data/flexbuild_lsdk2108_bak/build/firmware/u-boot/ls1046ardb/uboot_ls1046ardb_tfa_SECURE_BOOT.bin TRUSTED_BOARD_BOOT=1 CST_DIR=/home/nxa22585/data/flexbuild_lsdk2108_bak/components/apps/security/cst&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 08:10:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627472#M12157</guid>
      <dc:creator>yipingwang</dc:creator>
      <dc:date>2023-04-04T08:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627804#M12171</link>
      <description>&lt;P&gt;Thank you for the information. Yes I understand the Signature check is failing. Maybe you can correct my understand if it is wrong. I thought the SRK (Public Key) Hash is the hash of the public key used to generate the signature which is a hash of the image hash? The SRK Hash is the written into the SRK Mirror registers. So I'm confused what is wrong with the image hash being different than the SRK hash.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 16:21:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627804#M12171</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-04T16:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627938#M12175</link>
      <description>Also your make command is essentially what is being executed though its being done through yocto. Eventually it calls create_hdr_isbc. I did not post the entire build log, so if there is another part that we should look at I'm happy to pull that up.</description>
      <pubDate>Tue, 04 Apr 2023 21:37:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1627938#M12175</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-04T21:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629244#M12192</link>
      <description>&lt;P&gt;Maybe I can ask my question in a better way that would help me gain some understanding. I am struggling to figure out why I'm getting the 0x341 ERROR_HASH_COMPARE_EM signature check failure. As far as I can tell I am loading the correct SRK hash as I would expect (and do see if I have the wrong hash) 0x340. I also believe the image I am loading is correct, though in the process of validating there are no erroneous bits. At least cursory glance seems to validate that the BL2 I loaded as well as the header and signature match what was produced by the build. In other words I'm wondering what would be the next step in figuring out where this is going wrong? Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 15:48:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629244#M12192</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-06T15:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629426#M12198</link>
      <description>&lt;P&gt;Please refer to the following update from the AE team.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can customer confirm they only have one set of srk.pub and srk.pri in the build server to sign all the different images. If they have different set of srk.pub and srk.pri to sign different images, it will cause the 0x341 error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Which version of LSDK customer is using?&lt;BR /&gt;Here is my buid log, which I don't have the "?? getopt returned character code 00 ??" issue.&lt;BR /&gt;#####&lt;BR /&gt;...&lt;BR /&gt;Built /home/r01360/flexbuild_lsdk2108/components/firmware/atf/build/ls1046ardb/release/bl2.bin successfully&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;#----------------------------------------------------#&lt;BR /&gt;#------- -------- -------- -------#&lt;BR /&gt;#------- CST (Code Signing Tool) Version 2.0 -------#&lt;BR /&gt;#------- -------- -------- -------#&lt;BR /&gt;#----------------------------------------------------#&lt;BR /&gt;file name is /home/r01360/flexbuild_lsdk2108/components/firmware/atf/build/ls1046ardb/release/bl2.bin&lt;BR /&gt;file name is /home/r01360/flexbuild_lsdk2108/components/firmware/atf/build/ls1046ardb/release/hdr_bl2&lt;BR /&gt;&lt;BR /&gt;==========================================================&lt;BR /&gt;This tool includes software developed by OpenSSL Project&lt;BR /&gt;for use in the OpenSSL Toolkit (&lt;A href="http://www.openssl.org/" target="_blank"&gt;http://www.openssl.org/&lt;/A&gt;)&lt;BR /&gt;This product includes cryptographic software written by&lt;BR /&gt;Eric Young (eay@cryptsoft.com)&lt;BR /&gt;==========================================================&lt;BR /&gt;&lt;BR /&gt;Input File is drivers/nxp/auth/csf_hdr_parser/input_bl2_ch2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;************************************************&lt;BR /&gt;* Header File is with Signature appended&lt;BR /&gt;************************************************&lt;BR /&gt;&lt;BR /&gt;Header File Created: /home/r01360/flexbuild_lsdk2108/components/firmware/atf/build/ls1046ardb/release/hdr_bl2&lt;BR /&gt;&lt;BR /&gt;SRK (Public Key) Hash:&lt;BR /&gt;a74ad3f58c3dd9a5b715480c2f6108949500fe08e54fe2a989e85710cbc1e300&lt;BR /&gt;SFP SRKHR0 = a74ad3f5&lt;BR /&gt;SFP SRKHR1 = 8c3dd9a5&lt;BR /&gt;SFP SRKHR2 = b715480c&lt;BR /&gt;SFP SRKHR3 = 2f610894&lt;BR /&gt;SFP SRKHR4 = 9500fe08&lt;BR /&gt;SFP SRKHR5 = e54fe2a9&lt;BR /&gt;SFP SRKHR6 = 89e85710&lt;BR /&gt;SFP SRKHR7 = cbc1e300&lt;BR /&gt;&lt;BR /&gt;LD byte_swap&lt;BR /&gt;&lt;BR /&gt;Built byte_swap successfully&lt;BR /&gt;&lt;BR /&gt;LD create_pbl&lt;BR /&gt;&lt;BR /&gt;Built create_pbl successfully&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Input Boot Source: SD_BOOT&lt;BR /&gt;Input RCW File: /home/r01360/flexbuild_lsdk2108/build/firmware/rcw/ls1046ardb/RR_FFSSPPPH_1133_5559/rcw_1800_sdboot_sben.bin&lt;BR /&gt;Input BL2 Binary File: /home/r01360/flexbuild_lsdk2108/components/firmware/atf/build/ls1046ardb/release/bl2.bin&lt;BR /&gt;Input load address for BL2 Binary File: 0x10000000&lt;BR /&gt;Chassis Type: 1&lt;BR /&gt;...&lt;BR /&gt;#####&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 01:56:15 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629426#M12198</guid>
      <dc:creator>yipingwang</dc:creator>
      <dc:date>2023-04-07T01:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629858#M12205</link>
      <description>&lt;P&gt;Yes I did confirm that I only have one set of keys. It was a little difficult as it gets copied around a bunch. I also went as far as validating how the signature is actually getting built. I was also able to&amp;nbsp; dump the values that the hardware should be reading during the boot hold off. After dumping I calculated the sha256 hash and signature and was able to get a match.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as version I'm building from&amp;nbsp;&lt;A href="https://github.com/nxp-qoriq/cst" target="_blank"&gt;https://github.com/nxp-qoriq/cst&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;af56e6c5c66dd2bc86a83b0bee8cb61b88d2120c I'm not sure what version that corresponds to, but it looks like its later than 21.08.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It does look like in your log you're building for the SD card and I'm building for qspi though not sure that should make a difference in how the signature is created. Would it be helpful to post up the built pbl for you to review and see if you can identify the issue there?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 17:06:52 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629858#M12205</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-07T17:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629921#M12206</link>
      <description>&lt;P&gt;Interestingly I just downloaded the 21.08 sdk from nxp and built the firmware and I get this in srk_hash.txt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#----------------------------------------------------#&lt;BR /&gt;#------- -------- -------- -------#&lt;BR /&gt;#------- CST (Code Signing Tool) Version 2.0 -------#&lt;BR /&gt;#------- -------- -------- -------#&lt;BR /&gt;#----------------------------------------------------#&lt;BR /&gt;?? getopt returned character code 00 ??&lt;/P&gt;&lt;P&gt;==========================================================&lt;BR /&gt;This tool includes software developed by OpenSSL Project&lt;BR /&gt;for use in the OpenSSL Toolkit (&lt;A href="http://www.openssl.org/" target="_blank"&gt;http://www.openssl.org/&lt;/A&gt;)&lt;BR /&gt;This product includes cryptographic software written by&lt;BR /&gt;Eric Young (eay@cryptsoft.com)&lt;BR /&gt;==========================================================&lt;/P&gt;&lt;P&gt;Input File is input_files/uni_sign/ls104x_1012/input_bootscript_secure&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SRK (Public Key) Hash:&lt;BR /&gt;caa8738d62fb29b9d671a8f8c51f01bd8f1f12bb9b778fd5c9f010b176057a77&lt;BR /&gt;SFP SRKHR0 = caa8738d&lt;BR /&gt;SFP SRKHR1 = 62fb29b9&lt;BR /&gt;SFP SRKHR2 = d671a8f8&lt;BR /&gt;SFP SRKHR3 = c51f01bd&lt;BR /&gt;SFP SRKHR4 = 8f1f12bb&lt;BR /&gt;SFP SRKHR5 = 9b778fd5&lt;BR /&gt;SFP SRKHR6 = c9f010b1&lt;BR /&gt;SFP SRKHR7 = 76057a77&lt;/P&gt;&lt;P&gt;so thinking the getopt return code thing is a red herring.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 19:08:47 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1629921#M12206</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-07T19:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1630656#M12216</link>
      <description>&lt;P&gt;Additionally I installed the qspi_boot_sec.pbl that was generated by the lsdk using&amp;nbsp;flex-builder -i mkfw -m ls1046ardb -b qspi -s and inputing the hash into the srkh registers and I still get 0x341 signature error.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 17:52:44 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1630656#M12216</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-10T17:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1630818#M12218</link>
      <description>&lt;P&gt;&lt;SPAN&gt;As in the LSDK UG, error code 0x341 has the following ISBC error definition:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;RSA signature check failure. Signature provided by you in the header doesn’t match with the signature of the ESBC image generated by ISBC. The ESBC image loaded by you may be different than the image used while generating the signature(using CST)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What it is complain about is the "signature" of your signed image in flash media, does not match the run time calculation of the image you are trying to boot. As you can see in &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-4D5D0916-29CC-4E11-BF82-477C40F31585.html" target="_blank"&gt;https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-4D5D0916-29CC-4E11-BF82-477C40F31585.html&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The CSF header contains:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;0x0c RSA signature offset &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This field contains an offset (in bytes) of the RSA signature from the start of the CSF header. Using this offset and the signature length, the RSA signature is read. The RSA signature is calculated over CSF header, SG table, and ESBC images.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;0x10 RSA signature length in bytes.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The RSA signature does not match the run time calculation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;i.e.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-0D3D0BD8-45E2-4D2D-BD79-E5591C34225D.html" target="_blank"&gt;https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-0D3D0BD8-45E2-4D2D-BD79-E5591C34225D.html&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#####&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Assuming that the device is configured to perform secure boot, the digital signature validation routine performs following steps (as shown at the right side of the figure).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The routine locates and parses the CSF header to determine the size and location of the image, public keys, and digital signature.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It hashes the public key and compares it to the hash of the public key or key list stored in the SRKH register in SFP. If the hash comparison fails, secure boot fails.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It uses the validated public key to decrypt the digital signature, recovering the hash of the header + image + public keys.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The routine then calculates hash over the header + image (ESBC/Trusted Firmware) + public keys and compares the decrypted hash to the calculated hash. If the hash comparison fails, the secure boot fails.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#####&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The ISBC uses the validated public key to decrypt the digital signature, recovering the hash of the header + image + public keys. The ISBC then calculates a hash over the header + image (ESBC/Trusted Firmware) + public keys and compares the decrypted hash to the calculated hash. If the hash comparison fails, secure boot fails.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The ISBC is using a SHA256 to calculate the signature. Can you check your CSF header (or provide the CSF to us to investigation)0x0C and 0x10 pointer has the correct information in the LS1046A? Also the CSF header "0x04 Public key offset" points to a corrected public key?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Lastly, what flash media you are using for secure boot (i.e. NOR, NAND, SD)? How you build the signed image?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Have you tried LSDK2108, "bld -m ls1046ardb -b sd -s" to build? i.e. "-s" option for secure boot.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 01:55:14 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1630818#M12218</guid>
      <dc:creator>yipingwang</dc:creator>
      <dc:date>2023-04-11T01:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1631438#M12229</link>
      <description>&lt;P&gt;So we're booting off qspi on an ls1046ardb, so my understanding is that is a nor flash chip hooked up to that but i'm not 100% sure on that.&amp;nbsp; I'm building with the following:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[root@fbubuntu flexbuild_lsdk2108_github]$ flex-builder -i mkfw -m ls1046ardb -b qspi -s&lt;BR /&gt;MACHINE: ls1046ardb&lt;BR /&gt;BOOTTYPE: qspi&lt;BR /&gt;SECURE: y&lt;BR /&gt;Writing 0x00000000 &amp;lt;---&amp;gt; firmware/atf/ls1046ardb/bl2_qspi.pbl&lt;BR /&gt;Writing 0x00900000 &amp;lt;---&amp;gt; firmware/fm_ucode/fsl_fman_ucode_ls1046_r1.0_106_4_18.bin&lt;BR /&gt;Writing 0x00940000 &amp;lt;---&amp;gt; firmware/qe_ucode/iram_Type_A_LS1021a_r1.0.bin&lt;BR /&gt;Writing 0x00980000 &amp;lt;---&amp;gt; firmware/phy_cortina/cs4315-cs4340-PHY-ucode.txt&lt;BR /&gt;Writing 0x009C0000 &amp;lt;---&amp;gt; images/flash_images.scr&lt;BR /&gt;Writing 0x00F00000 &amp;lt;---&amp;gt; linux/kernel/arm64/LS/fsl-ls1046a-rdb-sdk.dtb&lt;BR /&gt;Writing 0x01000000 &amp;lt;---&amp;gt; images/lsdk2108_yocto_tiny_LS_arm64.itb&lt;BR /&gt;/home/dmerrill/flexbuild_lsdk2108_github/build/images/firmware_ls1046ardb_qspiboot.img [Done]&lt;/P&gt;&lt;P&gt;Writing 0x00000000 &amp;lt;---&amp;gt; firmware/atf/ls1046ardb/bl2_qspi_sec.pbl&lt;BR /&gt;Writing 0x00100000 &amp;lt;---&amp;gt; firmware/atf/ls1046ardb/fip_uboot_sec.bin&lt;BR /&gt;Writing 0x00600000 &amp;lt;---&amp;gt; firmware/secboot_hdrs/ls1046ardb/secboot_hdrs_qspiboot.bin&lt;BR /&gt;Writing 0x00900000 &amp;lt;---&amp;gt; firmware/fm_ucode/fsl_fman_ucode_ls1046_r1.0_106_4_18.bin&lt;BR /&gt;Writing 0x00940000 &amp;lt;---&amp;gt; firmware/qe_ucode/iram_Type_A_LS1021a_r1.0.bin&lt;BR /&gt;Writing 0x00980000 &amp;lt;---&amp;gt; firmware/phy_cortina/cs4315-cs4340-PHY-ucode.txt&lt;BR /&gt;Writing 0x009C0000 &amp;lt;---&amp;gt; images/flash_images.scr&lt;BR /&gt;Writing 0x00F00000 &amp;lt;---&amp;gt; linux/kernel/arm64/LS/fsl-ls1046a-rdb-sdk.dtb&lt;BR /&gt;Writing 0x01000000 &amp;lt;---&amp;gt; images/lsdk2108_yocto_tiny_LS_arm64.itb&lt;BR /&gt;/home/dmerrill/flexbuild_lsdk2108_github/build/images/firmware_ls1046ardb_qspiboot_secure.img [Done]&lt;/P&gt;&lt;P&gt;Writing 0x00000000 &amp;lt;---&amp;gt; firmware/atf/ls1046ardb/bl2_qspi.pbl&lt;BR /&gt;Writing 0x00100000 &amp;lt;---&amp;gt; firmware/atf/ls1046ardb/fip_uefi.bin&lt;BR /&gt;Writing 0x00500000 &amp;lt;---&amp;gt; firmware/uefi/ls1046ardb/LS1046ARDBNV_EFI_QSPIBOOT.fd&lt;BR /&gt;Writing 0x00900000 &amp;lt;---&amp;gt; firmware/fm_ucode/fsl_fman_ucode_ls1046_r1.0_106_4_18.bin&lt;BR /&gt;Writing 0x00940000 &amp;lt;---&amp;gt; firmware/qe_ucode/iram_Type_A_LS1021a_r1.0.bin&lt;BR /&gt;Writing 0x00980000 &amp;lt;---&amp;gt; firmware/phy_cortina/cs4315-cs4340-PHY-ucode.txt&lt;BR /&gt;Writing 0x009C0000 &amp;lt;---&amp;gt; images/flash_images.scr&lt;BR /&gt;Writing 0x00F00000 &amp;lt;---&amp;gt; linux/kernel/arm64/LS/fsl-ls1046a-rdb-sdk.dtb&lt;BR /&gt;Writing 0x01000000 &amp;lt;---&amp;gt; images/lsdk2108_yocto_tiny_LS_arm64.itb&lt;BR /&gt;/home/dmerrill/flexbuild_lsdk2108_github/build/images/firmware_ls1046ardb_qspiboot_uefi.img [Done]&lt;/P&gt;&lt;P&gt;This ends up with the same 0x341 error. Please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 15:54:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1631438#M12229</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-11T15:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1633701#M12261</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Can you try &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;flex-builder -m ls1046ardb -b qspi -s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;bld -m ls1046ardb -b qspi -s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;and load the into QSPI and boot again? The "mkfw" option may have use different key to sign the image. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If this does not resolve the issue, please provide the build log so we can check the CST signing log for the name and location of the srk.pub and srk.pri that sign the software images.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;One more note. &lt;BR /&gt;Please refers to&lt;BR /&gt;&lt;A href="https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-D9A90107-3335-4BDB-861C-1613044EC6FD.html" target="_blank"&gt;https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-D9A90107-3335-4BDB-861C-1613044EC6FD.html&lt;/A&gt;&lt;BR /&gt;Note that customer also needs to put the correct "secure boot header" in 0x00600000 for QSPI&lt;BR /&gt;Secure boot headers 128KiB 0x00600000 0x60600000 0x64600000 0x580600000 0x584600000 0x03000&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 07:21:36 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1633701#M12261</guid>
      <dc:creator>yipingwang</dc:creator>
      <dc:date>2023-04-14T07:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1634796#M12274</link>
      <description>&lt;P&gt;Interesting about the secure boot headers? Can you help me understand what that is referring to?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 16:56:12 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1634796#M12274</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-17T16:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1635561#M12282</link>
      <description>&lt;P&gt;So another datapoint that hopefully will help. I went ahead and followed the steps for flashing from here&amp;nbsp;&lt;A href="https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-853E743B-D814-4DBF-BBA8-AE15AADE536A.html" target="_blank" rel="noopener"&gt;https://docs.nxp.com/bundle/GUID-487B2E69-BB19-42CB-AC38-7EF18C0FE3AE/page/GUID-853E743B-D814-4DBF-BBA8-AE15AADE536A.html&lt;/A&gt;&amp;nbsp;using&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;firmware_ls1046ardb_qspiboot_secure.img&lt;/PRE&gt;&lt;P&gt;instead of the non secure like the docs suggest. I reboot to the alt flash bank and attach and set my srkh mirror registers and still end up with the 0x341 error code and non-secure. So seems this isn't an issue with my build since its happening with a build directly from nxp as well? Thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 17:02:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1635561#M12282</guid>
      <dc:creator>dmerrill</dc:creator>
      <dc:date>2023-04-18T17:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: LS1046A Secure Boot Issue error 0x341</title>
      <link>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1641896#M12357</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If you are using a pre-built image from us. you have to use our SRKH value. how do you program that? Can you share your CCS console log?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;additional info using pre-build image.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In the pre-build image, there should be a srk_hash.txt.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;For example:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; #----------------------------------------------------#&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; #------- -------- -------- -------#&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; #------- CST (Code Signing Tool) Version 2.0 -------#&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; #------- -------- -------- -------#&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; #----------------------------------------------------#&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;?? getopt returned character code 00 ??&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;==========================================================&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This tool includes software developed by OpenSSL Project&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;for use in the OpenSSL Toolkit (&lt;A href="http://www.openssl.org/" target="_blank"&gt;http://www.openssl.org/&lt;/A&gt;)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This product includes cryptographic software written by&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Eric Young (eay@cryptsoft.com)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;==========================================================&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Input File is input_files/uni_sign/lx2160/input_bootscript_secure&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;SRK (Public Key) Hash:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2ff8750dee453269d43bfc6ca38ec315468e2fad73f157f21b383707a8c48e0e&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR0 = 2ff8750d&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR1 = ee453269&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR2 = d43bfc6c&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR3 = a38ec315&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR4 = 468e2fad&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR5 = 73f157f2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR6 = 1b383707&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; SFP SRKHR7 = a8c48e0e&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If they are using CWTap to write to the SRKH mirror register, there is no need to do endianess swap for the above value.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 02:28:40 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/LS1046A-Secure-Boot-Issue-error-0x341/m-p/1641896#M12357</guid>
      <dc:creator>yipingwang</dc:creator>
      <dc:date>2023-04-28T02:28:40Z</dc:date>
    </item>
  </channel>
</rss>

