<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S32K3 Secure Boot activation timing question in S32K</title>
    <link>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2248069#M54788</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/242600"&gt;@minjaekang99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. This is described in section "7.10.4 Sanctions" in HSE firmware reference manual. If the secure boot fails, alternate image can be executed (if configured). If it fails too, the device enters recovery mode. Or you can only disable usage of individual keys (based on smrFlags) or all keys. Or the device can be reset and it can enter a recovery mode after 8 resets... See mentioned section in the manual for more details and also check HSE Service API reference manual.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Yes, common way is to finalize your application and then start with configuration of secure boot.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lukas&lt;/P&gt;</description>
    <pubDate>Tue, 25 Nov 2025 06:29:27 GMT</pubDate>
    <dc:creator>lukaszadrapa</dc:creator>
    <dc:date>2025-11-25T06:29:27Z</dc:date>
    <item>
      <title>S32K3 Secure Boot activation timing question</title>
      <link>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2232752#M54715</link>
      <description>&lt;P&gt;Hello, I am working with Secure Boot on the S32K324 (HSE firmware), and I want to confirm whether my understanding is correct.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Once Secure Boot is activated and the SMR/CR entries are provisioned, will the device refuse to boot if the application firmware changes even by one byte (e.g., code modification, rebuild, RTD version change, etc.) because the hash/signature no longer matches?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Given this behavior, is the recommended workflow to &lt;STRONG&gt;complete all firmware development first&lt;/STRONG&gt;, finalize the application image, and &lt;STRONG&gt;activate Secure Boot only at the very end&lt;/STRONG&gt; of the project (since any further code changes would cause Secure Boot verification to fail)?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thank you in advance for your clarification.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 10:29:10 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2232752#M54715</guid>
      <dc:creator>minjaekang99</dc:creator>
      <dc:date>2025-11-21T10:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: S32K3 Secure Boot activation timing question</title>
      <link>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2246832#M54756</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Can anyone answer this question?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 08:03:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2246832#M54756</guid>
      <dc:creator>minjaekang99</dc:creator>
      <dc:date>2025-11-24T08:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: S32K3 Secure Boot activation timing question</title>
      <link>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2248069#M54788</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/242600"&gt;@minjaekang99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. This is described in section "7.10.4 Sanctions" in HSE firmware reference manual. If the secure boot fails, alternate image can be executed (if configured). If it fails too, the device enters recovery mode. Or you can only disable usage of individual keys (based on smrFlags) or all keys. Or the device can be reset and it can enter a recovery mode after 8 resets... See mentioned section in the manual for more details and also check HSE Service API reference manual.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Yes, common way is to finalize your application and then start with configuration of secure boot.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lukas&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 06:29:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K3-Secure-Boot-activation-timing-question/m-p/2248069#M54788</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2025-11-25T06:29:27Z</dc:date>
    </item>
  </channel>
</rss>

