<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: Why not use only fast authentication?</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769811#M119541</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using CST&amp;nbsp;Rev. 2.3.1 so sorry if my questions are already answered in the updated document.&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;Why would someone want to use&amp;nbsp;one key for CST signing and a different key for&amp;nbsp;&lt;SPAN&gt;IMG signing when both&amp;nbsp;keys are used by the same tool? I cannot see any advantage&amp;nbsp;in it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) Certificates generated by the add_key.sh script have&amp;nbsp;a validity interval based on user's input. Is HAB&amp;nbsp;checking certificate validity during boot time?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Michal&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Dec 2017 10:13:51 GMT</pubDate>
    <dc:creator>michalhojsik</dc:creator>
    <dc:date>2017-12-07T10:13:51Z</dc:date>
    <item>
      <title>Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769807#M119537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using the authenticated boot feature of i.MX6ul and I would like to ask:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the advantage of using dedicated CSF and IMG signing keys compared to using directly the SRKs for signing (so-called "fast authentication")?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2017 16:53:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769807#M119537</guid>
      <dc:creator>michalhojsik</dc:creator>
      <dc:date>2017-12-06T16:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769808#M119538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Classical&amp;nbsp;&amp;nbsp;Public Key Infrastructure (PKI) approach allows to use multiple CSF and IMG keys,&lt;/P&gt;&lt;P&gt;say for different design teams.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 05:26:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769808#M119538</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-12-07T05:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769809#M119539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri.&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;If the goal was to allow different teams to have different keys, why there are different keys for CSF signing and for image signing? Both CSF and image signatures are generated by the CST in one step.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 09:10:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769809#M119539</guid>
      <dc:creator>michalhojsik</dc:creator>
      <dc:date>2017-12-07T09:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769810#M119540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; "Additional keys may be added to the tree later using a separate script."&lt;/P&gt;&lt;P&gt;&amp;nbsp;You may look at section&amp;nbsp;3.2.5 (Adding a Key to a HAB4 PKI Tree) of the recent CST (2.3.3) documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Also, customers may use own CST (Appendix B Replacing the CST Backend Implementation)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 09:38:24 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769810#M119540</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-12-07T09:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769811#M119541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using CST&amp;nbsp;Rev. 2.3.1 so sorry if my questions are already answered in the updated document.&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;Why would someone want to use&amp;nbsp;one key for CST signing and a different key for&amp;nbsp;&lt;SPAN&gt;IMG signing when both&amp;nbsp;keys are used by the same tool? I cannot see any advantage&amp;nbsp;in it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) Certificates generated by the add_key.sh script have&amp;nbsp;a validity interval based on user's input. Is HAB&amp;nbsp;checking certificate validity during boot time?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Michal&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 10:13:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769811#M119541</guid>
      <dc:creator>michalhojsik</dc:creator>
      <dc:date>2017-12-07T10:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769812#M119542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;1.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; IMX boot ROM HAB implementation does not allow to&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;use&amp;nbsp;one key for CST signing and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;a different key for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff; border: 0px;"&gt;IMG signing.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; color: #51626f;"&gt;2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; color: #51626f;"&gt;&amp;nbsp; Details of&amp;nbsp;&lt;SPAN style="color: #3d3d3d;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;boot ROM HAB implementation are not provided publically.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Please create request / ticket.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;A class="link-titled" href="https://www.nxp.com/support/support:SUPPORTHOME?tid=sbmenu" title="https://www.nxp.com/support/support:SUPPORTHOME?tid=sbmenu"&gt;Support|NXP&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note: If this post answers your question, please click the Correct Answer &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 02:16:25 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769812#M119542</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-12-08T02:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769813#M119543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri.&lt;/P&gt;&lt;P&gt;Sorry, there was a typo in the first question - should be CSF signing and not CST signing. The question is:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;1)&amp;nbsp;Why would someone want to use&amp;nbsp;one key for &lt;STRONG&gt;CSF&lt;/STRONG&gt; signing and a different key for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff; border: 0px;"&gt;IMG signing when both&amp;nbsp;keys are used by the same tool? I cannot see any advantage&amp;nbsp;in it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff; border: 0px;"&gt;CSF key is installed by the CSF command&amp;nbsp;[Install CSFK], IMG key by the&amp;nbsp;[Install Key] command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff; border: 0px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff; border: 0px;"&gt;Michal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 11:53:10 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769813#M119543</guid>
      <dc:creator>michalhojsik</dc:creator>
      <dc:date>2017-12-08T11:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why not use only fast authentication?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769814#M119544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The IMG also may be encrypted, CSF should be only signed.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 08:39:15 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-not-use-only-fast-authentication/m-p/769814#M119544</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-12-11T08:39:15Z</dc:date>
    </item>
  </channel>
</rss>

