<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Layerscape中的主题 Code Signing Tool with a Hardware Security Module</title>
    <link>https://community.nxp.com/t5/Layerscape/Code-Signing-Tool-with-a-Hardware-Security-Module/m-p/2358847#M16664</link>
    <description>&lt;P&gt;I am aware that there are multiple versions of the code signing tool from different locations.&lt;/P&gt;&lt;P&gt;I currently am using the CST located at github.com/nxp-qoriq/cst. This appears to be version 2.0 and matches what documentation I seem to come across. I have also seen versions in the 3.* range as well as a 4.* version. From postings on the forums it seems these version 3 and 4 versions of CST can support a HSM through some configuration changes.&lt;/P&gt;&lt;P&gt;However, I can't seem to find an equivalent for CST 2.0? Can CST 2.0 utilize a HSM? If yes what steps would be required, if no, then can other versions of CST be used as drop in replacements?&lt;/P&gt;&lt;P&gt;I also noticed that the latest CST 4 doesn't appear to have actual source code available, or am I just looking in the wrong place? The precompiled binaries are only available for x86_64, but I'm developing natively on the LS1043A aarch64, so the precompiled binaries are obviously not an option. I don't mind building a different version, I just need to know where the source is and if there are any compatibility issues to be aware of?&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2026 22:22:17 GMT</pubDate>
    <dc:creator>endrunner_smw</dc:creator>
    <dc:date>2026-04-29T22:22:17Z</dc:date>
    <item>
      <title>Code Signing Tool with a Hardware Security Module</title>
      <link>https://community.nxp.com/t5/Layerscape/Code-Signing-Tool-with-a-Hardware-Security-Module/m-p/2358847#M16664</link>
      <description>&lt;P&gt;I am aware that there are multiple versions of the code signing tool from different locations.&lt;/P&gt;&lt;P&gt;I currently am using the CST located at github.com/nxp-qoriq/cst. This appears to be version 2.0 and matches what documentation I seem to come across. I have also seen versions in the 3.* range as well as a 4.* version. From postings on the forums it seems these version 3 and 4 versions of CST can support a HSM through some configuration changes.&lt;/P&gt;&lt;P&gt;However, I can't seem to find an equivalent for CST 2.0? Can CST 2.0 utilize a HSM? If yes what steps would be required, if no, then can other versions of CST be used as drop in replacements?&lt;/P&gt;&lt;P&gt;I also noticed that the latest CST 4 doesn't appear to have actual source code available, or am I just looking in the wrong place? The precompiled binaries are only available for x86_64, but I'm developing natively on the LS1043A aarch64, so the precompiled binaries are obviously not an option. I don't mind building a different version, I just need to know where the source is and if there are any compatibility issues to be aware of?&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 22:22:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/Code-Signing-Tool-with-a-Hardware-Security-Module/m-p/2358847#M16664</guid>
      <dc:creator>endrunner_smw</dc:creator>
      <dc:date>2026-04-29T22:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Code Signing Tool with a Hardware Security Module</title>
      <link>https://community.nxp.com/t5/Layerscape/Code-Signing-Tool-with-a-Hardware-Security-Module/m-p/2359491#M16666</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;CST 2.0 does not have documented native HSM/PKCSsupport; for Layerscape the supported path is detached external signing with &lt;CODE class=""&gt;--img_hash&lt;/CODE&gt; plus &lt;CODE class=""&gt;sign_embedding&lt;/CODE&gt; , while i.MX CST 3.x/newer adds HSM features but is not verified as a drop-in replacement for QorIQ CST 2.0.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 22:55:24 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Layerscape/Code-Signing-Tool-with-a-Hardware-Security-Module/m-p/2359491#M16666</guid>
      <dc:creator>Bio_TICFSL</dc:creator>
      <dc:date>2026-04-30T22:55:24Z</dc:date>
    </item>
  </channel>
</rss>

