<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ls1043a is it possible to prototype secure boot without blowing any fuses? in Layerscape</title>
    <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2344112#M16607</link>
    <description>&lt;P&gt;Between documentation and even cross referencing with some Ai agents I can't get a definitive answer on this.&lt;/P&gt;&lt;P&gt;Can secure boot be setup on LS1043A without blowing any fuses? If yes, how? If no, what are the minimum fuses I have to blow in order to step the process along for secure boot.&lt;/P&gt;&lt;P&gt;I seem to be stuck where I setup secure boot in the RCW for SB_EN = 1 and BOOT_HO = 1, but when connecting to CCS when I try to write in the SRK registers those registers are locked and I can't write to them. And obviously secure boot isn't working.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Apr 2026 08:22:50 GMT</pubDate>
    <dc:creator>endrunner_smw</dc:creator>
    <dc:date>2026-04-02T08:22:50Z</dc:date>
    <item>
      <title>ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2344112#M16607</link>
      <description>&lt;P&gt;Between documentation and even cross referencing with some Ai agents I can't get a definitive answer on this.&lt;/P&gt;&lt;P&gt;Can secure boot be setup on LS1043A without blowing any fuses? If yes, how? If no, what are the minimum fuses I have to blow in order to step the process along for secure boot.&lt;/P&gt;&lt;P&gt;I seem to be stuck where I setup secure boot in the RCW for SB_EN = 1 and BOOT_HO = 1, but when connecting to CCS when I try to write in the SRK registers those registers are locked and I can't write to them. And obviously secure boot isn't working.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 08:22:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2344112#M16607</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-02T08:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2345075#M16608</link>
      <description>&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 10.5pt;"&gt;Secure boot requires the fuse to be blown.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 10.5pt;"&gt;Some secure boot–related documents are not publicly available. Please kindly create a support case at&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 10.5pt;"&gt;&lt;A href="https://support.nxp.com/s/?language=en_US" target="_blank"&gt;https://support.nxp.com/s/?language=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 10.5pt;"&gt;to request access to the Trust Architecture documents.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 10.5pt;"&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 11:43:43 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2345075#M16608</guid>
      <dc:creator>June_Lu</dc:creator>
      <dc:date>2026-04-03T11:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2345590#M16610</link>
      <description>&lt;P&gt;Was reviewing the Secure Boot.pptx by Yiping Wang from August 2024,&lt;/P&gt;&lt;P&gt;In the secure boot troubleshooting section it lists to check the SecMon_HP Status Register (0x1e90014) bits OTPMK_ZERO should be 0. Which I have (0x81D0AB00 is value returned). And to check SFP_SVHESR(0x1e80024) should be 0, mine however returns 0x00068400.&lt;/P&gt;&lt;P&gt;The powerpoint says if this is the case then there was an error in the way I tried to blow the OTPMK fuse. Is this the case? Is this recoverable? I read a document that said as long as the parity bit was 0 then it should be ok, but after seeing this presentation is that not the case?&lt;/P&gt;&lt;P&gt;Should the jump be attached to the board before power on? From documentation it sounds like it should not be, but rather put the jumper on while the system is running, burn the fuses, then remove the jumper while the system is still running before removing power and power cycling.&lt;/P&gt;&lt;P&gt;When I attempt to use CCS to put the SRK hashes in it appears that the registers are locked, because they don't take the values I'm entering. I try to put in the values and then set the board to release the CPU to boot, but I get no activity on the console (minicom).&lt;/P&gt;&lt;P&gt;For my attempt at secure boot on the LS1043A-RDB is my attempt with this board is this board done? It will still boot with a non-secure image as I didn't try setting the ITS fuse.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2026 06:55:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2345590#M16610</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-06T06:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2350376#M16621</link>
      <description>&lt;P&gt;My manager has access to the Qoriq Trust Architecture 2.x document, I'm still waiting on my approval from NXP (already got the secure rights access, but that document hasn't been included).&lt;/P&gt;&lt;P&gt;Can you please provide confirmation of the OTPMK and SRKHR offsets?&lt;/P&gt;&lt;P&gt;I see a couple different values between multiple documents.&lt;/P&gt;&lt;P&gt;For OTPMK I see both offsets between 0x21C-0x238, and 0x234-0x250&lt;/P&gt;&lt;P&gt;For SRKHR I see both offsets between 0x23C-0x258, and 0x254-0x270&lt;/P&gt;&lt;P&gt;As you can see there between the two sets they overlap on a couple of registers.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 00:26:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2350376#M16621</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-14T00:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2350397#M16622</link>
      <description>&lt;P&gt;Memory Map for SFP in Qoriq Trust Architecture 2.x has incorrect register range. Tried with other values from LSDUK_Rev21.08 and document 'Setting up Secure Boot on PBL Based Platforms in Prototype Stage', and Secure_boot.pptx. And after entering SRK hash values into registers and releasing the CPU finally got life on the console. I still have errors, but its a step in the right direction&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 01:48:05 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2350397#M16622</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-14T01:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2351031#M16624</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="endrunner_smw_0-1776212372703.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/382364iACD16E5A672B5CBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="endrunner_smw_0-1776212372703.png" alt="endrunner_smw_0-1776212372703.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If anyone is curious these are the errors I am receiving after putting the SRK hash in and releasing the cpu&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 00:20:33 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2351031#M16624</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-15T00:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2351061#M16625</link>
      <description>Did you eventually use CodeWarrior or U-Boot to fuse the OTPMK? This is mandatory. Later, if you need to verify the SRKH effects, you can skip the actual fusing and just use the mirror registers instead. You'll need CodeWarrior to assist with this—halt the main CPU, configure the mirror registers properly, then release the CPU. Refer to the corresponding sections in the LSDK documentation for detailed descriptions.</description>
      <pubDate>Wed, 15 Apr 2026 02:14:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2351061#M16625</guid>
      <dc:creator>kenli</dc:creator>
      <dc:date>2026-04-15T02:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2351769#M16626</link>
      <description>&lt;P&gt;Yes, I used CCS to fuse the OTPMK. Then with BOOT_HO = 1 and SB_EN = 1 in RCW I booted and in CCS set the SRKH mirror registers and released the cpu. That is the screenshot I posted above. Though apparently I still have an issue of SEC/CAAM not initializing?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 21:26:01 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2351769#M16626</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-15T21:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: ls1043a is it possible to prototype secure boot without blowing any fuses?</title>
      <link>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2353151#M16628</link>
      <description>&lt;P&gt;Marked as solved since I was able to get output on the console, will open a new issue for the SEC/CAAM not initializing&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 19:52:38 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/ls1043a-is-it-possible-to-prototype-secure-boot-without-blowing/m-p/2353151#M16628</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-17T19:52:38Z</dc:date>
    </item>
  </channel>
</rss>

