<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>S32KのトピックRe: S32K312 HSE secureboot SMR installation failed</title>
    <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2158776#M52177</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/226377"&gt;@Yiming2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested secure boot with RSA key two or three weeks ago and I can see that your SMR configuration is almost exactly the same. Just different addresses and sizes but there's no functional difference. Everything seems to be correct.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Was the import of RSA key successful?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is data cache turned off?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lukas&lt;/P&gt;</description>
    <pubDate>Wed, 27 Aug 2025 05:22:18 GMT</pubDate>
    <dc:creator>lukaszadrapa</dc:creator>
    <dc:date>2025-08-27T05:22:18Z</dc:date>
    <item>
      <title>S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2155823#M52034</link>
      <description>&lt;P&gt;hello all&amp;nbsp;&lt;/P&gt;&lt;P&gt;we met a question when we implement the secure boot. We tried to install the defined SMR table into the HSE using the HSELIB API. But it always return the 0x55A5A399 which means&amp;nbsp;HSE_SRV_RSP_INVALID_PARAM. But we checked several times for the parameters we input the&amp;nbsp;HSELIB Install API. but we didn't find any uncorrect parameters.&lt;/P&gt;&lt;P&gt;Detailed information:&lt;/P&gt;&lt;P&gt;MCU: S32K312 publickey has been provioned into HSE.&lt;/P&gt;&lt;P&gt;for smrenty is shown as below:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; smrEntry_Test[4].configFlags                  &amp;nbsp;= HSE_SMR_CFG_FLAG_INSTALL_AUTH;   &amp;nbsp;/* Indicate that verification should be done on provided signature*/&lt;BR /&gt;    smrEntry_Test[4].pSmrDest                   &amp;nbsp;= 0U;                &amp;nbsp;/* Destination address shall be NULL for flashed based devices*/&lt;BR /&gt;    smrEntry_Test[4].checkPeriod                  &amp;nbsp;= 0U;                &amp;nbsp;/* If not 0, SMR will be automatically and periodically verified at run-time regardless of&amp;nbsp; verifMethod*/&lt;BR /&gt;    smrEntry_Test[4].pSmrSrc                    &amp;nbsp;= 0x00520000ul;            &amp;nbsp;/* Start of APP code*/&lt;BR /&gt;    smrEntry_Test[4].smrSize                    &amp;nbsp;= 0x124;     &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Length of APP code (test use value like 0x00010000U)*/&lt;BR /&gt;    smrEntry_Test[4].authKeyHandle                 &amp;nbsp;= NVM_CUST_RSA2048_BOOT_PUB_KEY;   &amp;nbsp;/* HANDLE0 -&amp;gt; HANDLE1(The actual import key slot of RSA keys)*/&lt;BR /&gt;    smrEntry_Test[4].authScheme.sigScheme.signSch         &amp;nbsp;= HSE_SIGN_RSASSA_PSS;&lt;BR /&gt;    smrEntry_Test[4].authScheme.sigScheme.sch.rsaPss.hashAlgo   &amp;nbsp;= HSE_HASH_ALGO_SHA2_256;&lt;BR /&gt;    smrEntry_Test[4].authScheme.sigScheme.sch.rsaPss.saltLength   &amp;nbsp;= 32UL;&lt;BR /&gt;#if 1&lt;BR /&gt;    smrEntry_Test[4].pInstAuthTag[0]                &amp;nbsp;= 0x00510000UL;  /* Signature tag address*/&lt;BR /&gt;#else&lt;BR /&gt;    smrEntry_Test[4].pInstAuthTag[0]                &amp;nbsp;= (uint32_t)NULL; ;  /* Signature tag address*/&lt;BR /&gt;#endif&lt;BR /&gt;    smrEntry_Test[4].pInstAuthTag[1]                &amp;nbsp;= (uint32_t)NULL;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;below is the install the smr API details:&lt;/P&gt;&lt;P&gt;hseSrvResponse_t HSE_InstallSmrEntry&lt;BR /&gt;(&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint8_t entryIndex,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const hseSmrEntry_t *pSmrEntry,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint8_t *pData,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint32_t dataLen,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint8_t *pSign0,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint8_t *pSign1,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint32_t SignLen0,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; const uint32_t SignLen1&lt;BR /&gt;)&lt;BR /&gt;{&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uint8_t u8MuChannel = 1U;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; /*hseSrvDescriptor_t *pHseSrvDesc;*/&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; /*hseSmrEntryInstallSrv_t *pSmrEntryInstall;*/&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hseSrvResponse_t srvResponse = HSE_SRV_RSP_GENERAL_ERROR;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Clear the service descriptor placed in shared memory */&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pHseSrvDesc = &amp;amp;gHseSrvDesc[MU0][u8MuChannel];&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall = &amp;amp;(pHseSrvDesc-&amp;gt;hseSrv.smrEntryInstallReq);&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; memset(pHseSrvDesc, 0, sizeof(hseSrvDescriptor_t));&lt;BR /&gt;&lt;BR /&gt;  pSmrEntryInstallTemp = pSmrEntryInstall;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;  pSign0_Temp = PTR_TO_HOST_ADDR(pSign0);;&lt;BR /&gt;  pSign1_Temp = PTR_TO_HOST_ADDR(pSign1);&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;  SignLen0Temp = SignLen0;&lt;BR /&gt;  SignLen1Temp = SignLen1;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;  srvId_Temp = HSE_SRV_ID_SMR_ENTRY_INSTALL;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Fill the service descriptor */&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pHseSrvDesc-&amp;gt;srvId = HSE_SRV_ID_SMR_ENTRY_INSTALL;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;accessMode = HSE_ACCESS_MODE_ONE_PASS;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;entryIndex = entryIndex;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;pSmrEntry = PTR_TO_HOST_ADDR(pSmrEntry);&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;pSmrData = PTR_TO_HOST_ADDR(pData);&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;smrDataLength = dataLen;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;pAuthTag[0] = PTR_TO_HOST_ADDR(pSign0);&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;pAuthTag[1] = PTR_TO_HOST_ADDR(pSign1);&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;authTagLength[0] = SignLen0;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; #if 1&lt;BR /&gt;  pSmrEntryInstall-&amp;gt;authTagLength[1] = 0;&lt;BR /&gt;  #else&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pSmrEntryInstall-&amp;gt;authTagLength[1] = SignLen1;&lt;BR /&gt;  #endif&lt;BR /&gt;  pHseSrvDescTemp = pHseSrvDesc;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Send the request synchronously */&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; srvResponse = HSE_Send(MU0, u8MuChannel, gSyncTxOption, pHseSrvDesc);&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; return srvResponse;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;below is the key information:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;  /****************************** NVM&amp;nbsp; RSA-PUB *****************************/&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; /* Import RSA keys for secure boot.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; */&lt;BR /&gt;  srvResponse = ImportPlainRsaKeyReq(&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NVM_CUST_RSA2048_BOOT_PUB_KEY,&amp;nbsp;&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HSE_KEY_TYPE_RSA_PUB,&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (HSE_KF_USAGE_VERIFY),&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (HOST_ADDR)rsa2048CustAuthKeyModulus,&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rsa2048CustAuthKeyModulusLength,&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (HOST_ADDR)rsa2048CustAuthKeyPubExp,&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rsa2048CustAuthKeyPubExpLength,&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (HOST_ADDR) NULL,&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0UL&lt;BR /&gt;       &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; );&lt;BR /&gt;  ASSERT(HSE_SRV_RSP_OK == srvResponse);&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 07:32:58 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2155823#M52034</guid>
      <dc:creator>Yiming2</dc:creator>
      <dc:date>2025-08-21T07:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2156627#M52081</link>
      <description>&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Could you describe what is your configuration based on? Which is used FW and SBAF version, its configuration (FULL_MEM, AB_SWAP) and other information we should know. Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 08:33:44 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2156627#M52081</guid>
      <dc:creator>davidtosenovjan</dc:creator>
      <dc:date>2025-08-22T08:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2157244#M52114</link>
      <description>hello thanks for your reply.&lt;BR /&gt;the code is created based on HSELIB.&lt;BR /&gt;The FW version is 0_2_40_0.&lt;BR /&gt;And SBAF is 00 0D 00 00 00 08 00 00.&lt;BR /&gt;Configuration is FULL_MEM.&lt;BR /&gt;if you need more information ,please let me know. Thank you very much.</description>
      <pubDate>Mon, 25 Aug 2025 03:13:25 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2157244#M52114</guid>
      <dc:creator>Yiming2</dc:creator>
      <dc:date>2025-08-25T03:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2158776#M52177</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/226377"&gt;@Yiming2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested secure boot with RSA key two or three weeks ago and I can see that your SMR configuration is almost exactly the same. Just different addresses and sizes but there's no functional difference. Everything seems to be correct.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Was the import of RSA key successful?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is data cache turned off?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lukas&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 05:22:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2158776#M52177</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2025-08-27T05:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2158841#M52179</link>
      <description>&lt;P&gt;Could you try align the size to 128 bytes? I didn't notice that first time. You use value 0x124.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lukaszadrapa_0-1756277621484.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/354253i8670E3DCF75D81B9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lukaszadrapa_0-1756277621484.png" alt="lukaszadrapa_0-1756277621484.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 06:54:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2158841#M52179</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2025-08-27T06:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2164063#M52437</link>
      <description>hello , I am sorry for the misstake. We have found the rootcourse that we used the wrong HSELIB. In that HSELIB the SMRENTRY struct is not correct. And we update the new one, then the SMR successfully installed.</description>
      <pubDate>Fri, 05 Sep 2025 05:22:04 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2164063#M52437</guid>
      <dc:creator>Yiming2</dc:creator>
      <dc:date>2025-09-05T05:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: S32K312 HSE secureboot SMR installation failed</title>
      <link>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2170101#M52693</link>
      <description>&lt;P&gt;I also encountered the same problem.I also received an invalid parameter return code 0x55A5A399.&lt;/P&gt;&lt;P&gt;I want to know where the SMRENTRY struct has a problem.&lt;/P&gt;&lt;P&gt;You have used The FW version is 0_2_40_0 , I want to know What version of HSELIB is the problem found in?&lt;/P&gt;&lt;P&gt;I hope you can reply, thank you very much.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 03:08:31 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K312-HSE-secureboot-SMR-installation-failed/m-p/2170101#M52693</guid>
      <dc:creator>luhaiou</dc:creator>
      <dc:date>2025-09-16T03:08:31Z</dc:date>
    </item>
  </channel>
</rss>

