<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43 in S32G</title>
    <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039753#M12561</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/135277"&gt;@hittzt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your confirmation.&lt;/P&gt;
&lt;P&gt;I tested it without m7boot added to the local.conf, and seems there are no issues, the possible reason for the issue you met seems to be secure boot verification fail.&lt;/P&gt;
&lt;P&gt;While you added m7boot to the local.conf, then a small m7 bootloader would be appended, the boot image could be changed to the&amp;nbsp;bl2_w_dtb.s32-sdcard.m7 instead of the original one, but when booted to Linux, while enabling secure boot, the command is like:&lt;/P&gt;
&lt;P&gt;hse-secboot -s -d /dev/mmcblk0 --bl2_key /etc/keys/secboot/bl2_rsa2048_public.pem --bl31_key -:0x010700 --bl33_key -:0x010700 --bl2_sign /etc/keys/secboot/bl2-signature.bin-sdcard --bl2_bin /etc/keys/secboot/bl2_w_dtb.bin-sdcard&lt;/P&gt;
&lt;P&gt;Which does not match the boot image specified.&lt;/P&gt;
&lt;P&gt;From my understanding, the default secboot operation steps are only reference for default settings, if there are some additional configurations added, there may be issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;</description>
    <pubDate>Fri, 07 Feb 2025 07:11:21 GMT</pubDate>
    <dc:creator>chenyin_h</dc:creator>
    <dc:date>2025-02-07T07:11:21Z</dc:date>
    <item>
      <title>M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2038435#M12520</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed that SDK BSP43 has been released, and I am testing M7 boot with secure boot enabled on RDB3 v1.1 silicon, but the board boot failed after excuting hse-secboot command and rebooting, command is following:&lt;/P&gt;&lt;P&gt;hse-secboot -s -d /dev/mmcblk0 -b sd --bl2_bin bl2_w_dtb.bin --bl2_key /etc/keys/secboot/bl2_rsa2048_public.pem /etc/keys/secboot/bl2_rsa2048_public.pem --bl31_key -:0x010700 --bl33_key -:0x010700 --bl2_sign bl2-signature.bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The HSE firmware version is 0.2.51.0 for Gen3 v1.1 SOC, so would you please help to tell how to test this case, is there any other settings or configures?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zhantao&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 09:04:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2038435#M12520</guid>
      <dc:creator>hittzt</dc:creator>
      <dc:date>2025-02-05T09:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039001#M12524</link>
      <description>&lt;P&gt;Hello, &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/135277"&gt;@hittzt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your post.&lt;/P&gt;
&lt;P&gt;Would you mind testing it with the following command on your board to check if it is correct?&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;/etc/keys/secboot/secboot_script.sh sd /dev/mmcblk0&amp;nbsp; /etc/keys/secboot/bl2_w_dtb.bin-sdcard /etc/keys/secboot/bl2-signature.bin-sdcard"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 04:20:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039001#M12524</guid>
      <dc:creator>chenyin_h</dc:creator>
      <dc:date>2025-02-06T04:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039075#M12527</link>
      <description>&lt;P&gt;Yes, I tested it using the command in reference manual:&lt;/P&gt;&lt;P&gt;/etc/keys/secboot/secboot_script.sh sd /dev/mmcblk0 \&lt;BR /&gt;&amp;gt; /etc/keys/secboot/bl2_w_dtb.bin-sdcard \&lt;BR /&gt;&amp;gt; /etc/keys/secboot/bl2-signature.bin-sdcard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the whole test log is attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zhantao&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 07:01:14 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039075#M12527</guid>
      <dc:creator>hittzt</dc:creator>
      <dc:date>2025-02-06T07:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039134#M12529</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/135277"&gt;@hittzt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have checked the log, and do not see M7 bootloader information, which version M7 bootloader is used? any applications running on M7 side?&lt;/P&gt;
&lt;P&gt;And, may I know if you have tested it with A53 standalone boot without M7 involved? I just tested it only with BSP, and found no issues on my local RDB3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 08:10:01 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039134#M12529</guid>
      <dc:creator>chenyin_h</dc:creator>
      <dc:date>2025-02-06T08:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039643#M12556</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/24163"&gt;@chenyin_h&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed the steps in SDK BSP43 user manual section "3.1.6 Building Images with M7 as Boot Target" to test the m7 boot, and there seems no other commands or settings when booting the board with the output image.&lt;/P&gt;&lt;P&gt;For this test, I just add the following lines in project conf/local.conf:&lt;/P&gt;&lt;P&gt;DISTRO_FEATURES:append = " m7boot secboot"&lt;BR /&gt;NXP_FIRMWARE_LOCAL_DIR = "&amp;lt;0.2.51.0 hse firmware path&amp;gt;"&lt;/P&gt;&lt;P&gt;And then I used the output image "fsl-image-auto-s32g399ardb3.sdcard" to boot up the board and test as the log shows.&lt;/P&gt;&lt;P&gt;If I missed something please tell me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zhantao&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 01:46:06 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039643#M12556</guid>
      <dc:creator>hittzt</dc:creator>
      <dc:date>2025-02-07T01:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039753#M12561</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/135277"&gt;@hittzt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your confirmation.&lt;/P&gt;
&lt;P&gt;I tested it without m7boot added to the local.conf, and seems there are no issues, the possible reason for the issue you met seems to be secure boot verification fail.&lt;/P&gt;
&lt;P&gt;While you added m7boot to the local.conf, then a small m7 bootloader would be appended, the boot image could be changed to the&amp;nbsp;bl2_w_dtb.s32-sdcard.m7 instead of the original one, but when booted to Linux, while enabling secure boot, the command is like:&lt;/P&gt;
&lt;P&gt;hse-secboot -s -d /dev/mmcblk0 --bl2_key /etc/keys/secboot/bl2_rsa2048_public.pem --bl31_key -:0x010700 --bl33_key -:0x010700 --bl2_sign /etc/keys/secboot/bl2-signature.bin-sdcard --bl2_bin /etc/keys/secboot/bl2_w_dtb.bin-sdcard&lt;/P&gt;
&lt;P&gt;Which does not match the boot image specified.&lt;/P&gt;
&lt;P&gt;From my understanding, the default secboot operation steps are only reference for default settings, if there are some additional configurations added, there may be issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 07:11:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039753#M12561</guid>
      <dc:creator>chenyin_h</dc:creator>
      <dc:date>2025-02-07T07:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039980#M12564</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/24163"&gt;@chenyin_h&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;It is reasonable that the default command: “&lt;SPAN&gt;hse-secboot -s -d /dev/mmcblk0 --bl2_key /etc/keys/secboot/bl2_rsa2048_public.pem --bl31_key -:0x010700 --bl33_key -:0x010700 --bl2_sign /etc/keys/secboot/bl2-signature.bin-sdcard --bl2_bin /etc/keys/secboot/bl2_w_dtb.bin-sdcard&lt;/SPAN&gt;” is only for normal secure boot, not for m7 case.&lt;/P&gt;&lt;P&gt;So it is to say that we can not enable m7 and secure boot at same time currently, or else, the issue will show, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zhantao&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 13:01:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2039980#M12564</guid>
      <dc:creator>hittzt</dc:creator>
      <dc:date>2025-02-07T13:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: M7 boot with secure boot feature enabled on RDB3 SDK BSP43</title>
      <link>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2040257#M12573</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/135277"&gt;@hittzt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;Yes, from my understanding, the secure boot example shown in BSP UM is for default settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2025 01:59:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/M7-boot-with-secure-boot-feature-enabled-on-RDB3-SDK-BSP43/m-p/2040257#M12573</guid>
      <dc:creator>chenyin_h</dc:creator>
      <dc:date>2025-02-08T01:59:17Z</dc:date>
    </item>
  </channel>
</rss>

