<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hardware token support by HAB/CST in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687438#M106419</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The best approach to fulfill your request would be creating an OpenSSL engine which talks to your HSM.&lt;/P&gt;&lt;P&gt;In your CST backend, you create the CMS signature using OpenSSL's public accessors. OpenSSL in his turn will offload any cryprohraphic operation involved during signing to the HSM.&lt;/P&gt;&lt;P&gt;Detailed answer can be found here&amp;nbsp;&lt;A href="https://community.nxp.com/message/1021666"&gt;https://community.nxp.com/message/1021666&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 May 2018 14:11:51 GMT</pubDate>
    <dc:creator>marouene_boubakri</dc:creator>
    <dc:date>2018-05-23T14:11:51Z</dc:date>
    <item>
      <title>Hardware token support by HAB/CST</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687435#M106416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to sign U-Boot and other binaries that are later verified by HAB using a&amp;nbsp;hardware token? The disadvantage of using Code Signing Tool as described in tutorial(s) is that private keys are stored in the file system so it's not as secure as it might be in theory.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jul 2017 16:15:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687435#M106416</guid>
      <dc:creator>ivandrobyshevs1</dc:creator>
      <dc:date>2017-07-07T16:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware token support by HAB/CST</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687436#M106417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You may look at Appendix B (Replacing the CST Backend Implementation)&lt;/P&gt;&lt;P class=""&gt;of &lt;SPAN class=""&gt;HAB Code-Signing Tool User’s Guide, Rev. 2.3.2, 3/2016.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 03:32:54 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687436#M106417</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-07-10T03:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware token support by HAB/CST</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687437#M106418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The back-end code included with the CST needs to be ported to support certificate and key storage other than OpenSSL.&amp;nbsp; For the most part, it is not difficult.&amp;nbsp; The only difficult portion is constructing the CSM signing portion, which requires unraveling the OpenSSL code.&amp;nbsp; You'll need to link directly to the OpenSSL libcrypto.a file.&amp;nbsp; Once you are able to produce the same signature that OpenSSL does, everything works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Nov 2017 21:56:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687437#M106418</guid>
      <dc:creator>brianmiller</dc:creator>
      <dc:date>2017-11-06T21:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware token support by HAB/CST</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687438#M106419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The best approach to fulfill your request would be creating an OpenSSL engine which talks to your HSM.&lt;/P&gt;&lt;P&gt;In your CST backend, you create the CMS signature using OpenSSL's public accessors. OpenSSL in his turn will offload any cryprohraphic operation involved during signing to the HSM.&lt;/P&gt;&lt;P&gt;Detailed answer can be found here&amp;nbsp;&lt;A href="https://community.nxp.com/message/1021666"&gt;https://community.nxp.com/message/1021666&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 14:11:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Hardware-token-support-by-HAB-CST/m-p/687438#M106419</guid>
      <dc:creator>marouene_boubakri</dc:creator>
      <dc:date>2018-05-23T14:11:51Z</dc:date>
    </item>
  </channel>
</rss>

