<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: uboot 加入Secure boot功能，且加入的CST生成的签名文件，烧写进去后仍然提示错误 in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775637#M120428</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Yuri,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;我在不是virtual box到机器上试了一下，不会出现 random state错误。（可能是virtualbox的问题？）&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;谢谢！&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;luoyonghe@luoyonghe-Latitude-5480:~/cst/release/keys$ ./hab4_pki_tree.sh&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt; This script is a part of the Code signing tools for Freescale's&lt;BR /&gt; High Assurance Boot. It generates a basic PKI tree. The PKI&lt;BR /&gt; tree consists of one or more Super Root Keys (SRK), with each&lt;BR /&gt; SRK having two subordinate keys: &lt;BR /&gt; + a Command Sequence File (CSF) key &lt;BR /&gt; + Image key. &lt;BR /&gt; Additional keys can be added to the PKI tree but a separate &lt;BR /&gt; script is available for this. This this script assumes openssl&lt;BR /&gt; is installed on your system and is included in your search &lt;BR /&gt; path. Finally, the private keys generated are password &lt;BR /&gt; protectedwith the password provided by the file key_pass.txt.&lt;BR /&gt; The format of the file is the password repeated twice:&lt;BR /&gt; my_password&lt;BR /&gt; my_password&lt;BR /&gt; All private keys in the PKI tree are in PKCS #8 format will be&lt;BR /&gt; protected by the same password.&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;Do you want to use an existing CA key (y/n)?: n&lt;BR /&gt;Enter key length in bits for PKI tree: 2048&lt;BR /&gt;Enter PKI tree duration (years): 10&lt;BR /&gt;How many Super Root Keys should be generated? 4&lt;BR /&gt;Do you want the SRK certificates to have the CA flag set? (y/n)?: y&lt;BR /&gt;A default 'serial' file was created!&lt;BR /&gt;A default file 'key_pass.txt' was created with password = test!&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CA key and certificate +&lt;BR /&gt;+++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating a 2048 bit RSA private key&lt;BR /&gt;................................................................................................................................................+++&lt;BR /&gt;.......................+++&lt;BR /&gt;writing new private key to 'temp_ca.pem'&lt;BR /&gt;-----&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;......................................+++&lt;BR /&gt;.....................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK1_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:50 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.............................................................+++&lt;BR /&gt;..............................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF1_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.............................+++&lt;BR /&gt;..+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG1_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.......+++&lt;BR /&gt;..............................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK2_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.......................................+++&lt;BR /&gt;....................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF2_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.................................................+++&lt;BR /&gt;...........+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG2_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;..............................................+++&lt;BR /&gt;..............................................................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK3_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;................................+++&lt;BR /&gt;............................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF3_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.........................................+++&lt;BR /&gt;..........................................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG3_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.........................+++&lt;BR /&gt;...................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK4_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;................................................................+++&lt;BR /&gt;...................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF4_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:52 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.............................................................................................+++&lt;BR /&gt;......................................................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG4_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:52 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;luoyonghe@luoyonghe-Latitude-5480:~/cst/release/keys$ &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jun 2018 16:10:36 GMT</pubDate>
    <dc:creator>yongheluo_hotma</dc:creator>
    <dc:date>2018-06-06T16:10:36Z</dc:date>
    <item>
      <title>uboot 加入Secure boot功能，且加入的CST生成的签名文件，烧写进去后仍然提示错误</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775633#M120424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir，&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 我的平台是：i.mx6 solo&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;uboot软件版本是：U-Boot 2013.04&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;按照CST文档写入了SRK，并制作了CST文件，但是在uboot启动时仍然显示如下，请帮忙分析一下原因。谢谢！&lt;/P&gt;&lt;P&gt;====================================================&lt;/P&gt;&lt;P&gt;HAB Configuration: 0xf0, HAB State: 0x66&lt;/P&gt;&lt;P&gt;--------- HAB Event 1 -----------------&lt;BR /&gt; event data:&lt;BR /&gt; 0xdb 0x00 0x08 0x41 0x33 0x22 0x0a 0x00&lt;/P&gt;&lt;P&gt;--------- HAB Event 2 -----------------&lt;BR /&gt; event data:&lt;BR /&gt; 0xdb 0x00 0x14 0x41 0x33 0x0c 0xa0 0x00&lt;BR /&gt; 0x00 0x00 0x00 0x00 0x17 0x7f 0xb0 0x00&lt;BR /&gt; 0x00 0x00 0x00 0x20&lt;/P&gt;&lt;P&gt;--------- HAB Event 3 -----------------&lt;BR /&gt; event data:&lt;BR /&gt; 0xdb 0x00 0x14 0x41 0x33 0x0c 0xa0 0x00&lt;BR /&gt; 0x00 0x00 0x00 0x00 0x17 0x7f 0xb0 0x2c&lt;BR /&gt; 0x00 0x00 0x02 0x38&lt;/P&gt;&lt;P&gt;--------- HAB Event 4 -----------------&lt;BR /&gt; event data:&lt;BR /&gt; 0xdb 0x00 0x14 0x41 0x33 0x0c 0xa0 0x00&lt;BR /&gt; 0x00 0x00 0x00 0x00 0x17 0x7f 0xb0 0x20&lt;BR /&gt; 0x00 0x00 0x00 0x01&lt;/P&gt;&lt;P&gt;--------- HAB Event 5 -----------------&lt;BR /&gt; event data:&lt;BR /&gt; 0xdb 0x00 0x14 0x41 0x33 0x0c 0xa0 0x00&lt;BR /&gt; 0x00 0x00 0x00 0x00 0x17 0x80 0x00 0x00&lt;BR /&gt; 0x00 0x00 0x00 0x04&lt;BR /&gt; MXC_ARM_CLK = 792000000Hz&lt;BR /&gt; MXC_DDR_CLK= 400000000Hz&lt;/P&gt;&lt;P&gt;==============================&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;谢谢！&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Yonghe.Luo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 06:56:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775633#M120424</guid>
      <dc:creator>yongheluo_hotma</dc:creator>
      <dc:date>2018-05-23T06:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: uboot 加入Secure boot功能，且加入的CST生成的签名文件，烧写进去后仍然提示错误</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775634#M120425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 昨天看了nxp论坛上的一下讨论，目前问题已经解决了。&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Yonghe.Luo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 02:54:32 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775634#M120425</guid>
      <dc:creator>yongheluo_hotma</dc:creator>
      <dc:date>2018-05-24T02:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: uboot 加入Secure boot功能，且加入的CST生成的签名文件，烧写进去后仍然提示错误</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775635#M120426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp; Appendix A (Interpreting HAB Event Data from Report_Event() API) of the “HAB4_API.pdf” &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;in the CST package should be used to analyze HAB Events.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;A href="https://www.nxp.com/webapp/Download?colCode=IMX_CST_TOOL&amp;amp;amp;appType=license&amp;amp;amp;location=null&amp;amp;fsrch=1&amp;amp;sr=1&amp;amp;pageNum=1&amp;amp;Parent_nodeId=&amp;amp;Parent_pageType"&gt;https://www.nxp.com/webapp/Download?colCode=IMX_CST_TOOL&amp;amp;amp;appType=license&amp;amp;amp;location=null&amp;amp;fsrch=1&amp;amp;sr=1&amp;amp;pageNum=1&amp;amp;Parent_nodeId=&amp;amp;Parent_pageType&lt;/A&gt;=&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp; HAB event 1 in Your case has "HAB_INV_ADDRESS (0x22) reason, that is -&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;Invalid address: access denied", please check if initialization via DCD table meet allowed addresses. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;&amp;nbsp; Please take a look at Table 8-29 (Valid DCD Address Ranges) in i.MX 6Solo/6DualLite Reference Manual, &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="color: black; font-size: 12.0pt; font-family: 'Arial',sans-serif;"&gt;Rev. 3, 09/2017&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note: If this post answers your question, please click the Correct Answer &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 06:29:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775635#M120426</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2018-05-24T06:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: uboot 加入Secure boot功能，且加入的CST生成的签名文件，烧写进去后仍然提示错误</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775636#M120427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Yuri,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 我们在用CST3.0.1，运行hab4_pki_tree.sh时，得到如下结果，不知是否正常？&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;unable to write 'random state'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;（运行环境： ubuntu 14.04 64Bit）&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 完整的log如下，谢谢！&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yonghe@yonghe-VirtualBox:~/cst/cst3.0.1-release/keys$ ./hab4_pki_tree.sh&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt; This script is a part of the Code signing tools for Freescale's&lt;BR /&gt; High Assurance Boot. It generates a basic PKI tree. The PKI&lt;BR /&gt; tree consists of one or more Super Root Keys (SRK), with each&lt;BR /&gt; SRK having two subordinate keys: &lt;BR /&gt; + a Command Sequence File (CSF) key &lt;BR /&gt; + Image key. &lt;BR /&gt; Additional keys can be added to the PKI tree but a separate &lt;BR /&gt; script is available for this. This this script assumes openssl&lt;BR /&gt; is installed on your system and is included in your search &lt;BR /&gt; path. Finally, the private keys generated are password &lt;BR /&gt; protectedwith the password provided by the file key_pass.txt.&lt;BR /&gt; The format of the file is the password repeated twice:&lt;BR /&gt; my_password&lt;BR /&gt; my_password&lt;BR /&gt; All private keys in the PKI tree are in PKCS #8 format will be&lt;BR /&gt; protected by the same password.&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;Do you want to use an existing CA key (y/n)?: n&lt;BR /&gt;Enter key length in bits for PKI tree: 2048&lt;BR /&gt;Enter PKI tree duration (years): 10&lt;BR /&gt;How many Super Root Keys should be generated? 4&lt;BR /&gt;Do you want the SRK certificates to have the CA flag set? (y/n)?: y&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CA key and certificate +&lt;BR /&gt;+++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating a 2048 bit RSA private key&lt;BR /&gt;..................................+++&lt;BR /&gt;..............+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;writing new private key to 'temp_ca.pem'&lt;BR /&gt;-----&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;..................+++&lt;BR /&gt;..................................................................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK1_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:16 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.......+++&lt;BR /&gt;.........................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF1_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:16 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.....+++&lt;BR /&gt;..............................................................................................................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG1_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:16 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.....................+++&lt;BR /&gt;.........................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK2_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:16 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;..............+++&lt;BR /&gt;.......+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF2_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:17 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;....+++&lt;BR /&gt;.........................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG2_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:17 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;............+++&lt;BR /&gt;............................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK3_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:17 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;...............................................................................+++&lt;BR /&gt;...............................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF3_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:17 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;................................................................+++&lt;BR /&gt;.......................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG3_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:18 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;............................................................+++&lt;BR /&gt;....................................................................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK4_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:18 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.....................................+++&lt;BR /&gt;..............................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF4_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:18 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;..............+++&lt;BR /&gt;................................................................+++&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG4_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 14:25:19 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;BR /&gt;unable to write 'random state'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 14:38:25 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775636#M120427</guid>
      <dc:creator>yongheluo_hotma</dc:creator>
      <dc:date>2018-06-06T14:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: uboot 加入Secure boot功能，且加入的CST生成的签名文件，烧写进去后仍然提示错误</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775637#M120428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Yuri,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;我在不是virtual box到机器上试了一下，不会出现 random state错误。（可能是virtualbox的问题？）&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;谢谢！&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;luoyonghe@luoyonghe-Latitude-5480:~/cst/release/keys$ ./hab4_pki_tree.sh&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt; This script is a part of the Code signing tools for Freescale's&lt;BR /&gt; High Assurance Boot. It generates a basic PKI tree. The PKI&lt;BR /&gt; tree consists of one or more Super Root Keys (SRK), with each&lt;BR /&gt; SRK having two subordinate keys: &lt;BR /&gt; + a Command Sequence File (CSF) key &lt;BR /&gt; + Image key. &lt;BR /&gt; Additional keys can be added to the PKI tree but a separate &lt;BR /&gt; script is available for this. This this script assumes openssl&lt;BR /&gt; is installed on your system and is included in your search &lt;BR /&gt; path. Finally, the private keys generated are password &lt;BR /&gt; protectedwith the password provided by the file key_pass.txt.&lt;BR /&gt; The format of the file is the password repeated twice:&lt;BR /&gt; my_password&lt;BR /&gt; my_password&lt;BR /&gt; All private keys in the PKI tree are in PKCS #8 format will be&lt;BR /&gt; protected by the same password.&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;Do you want to use an existing CA key (y/n)?: n&lt;BR /&gt;Enter key length in bits for PKI tree: 2048&lt;BR /&gt;Enter PKI tree duration (years): 10&lt;BR /&gt;How many Super Root Keys should be generated? 4&lt;BR /&gt;Do you want the SRK certificates to have the CA flag set? (y/n)?: y&lt;BR /&gt;A default 'serial' file was created!&lt;BR /&gt;A default file 'key_pass.txt' was created with password = test!&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CA key and certificate +&lt;BR /&gt;+++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating a 2048 bit RSA private key&lt;BR /&gt;................................................................................................................................................+++&lt;BR /&gt;.......................+++&lt;BR /&gt;writing new private key to 'temp_ca.pem'&lt;BR /&gt;-----&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;......................................+++&lt;BR /&gt;.....................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK1_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:50 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.............................................................+++&lt;BR /&gt;..............................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF1_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 1 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.............................+++&lt;BR /&gt;..+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG1_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.......+++&lt;BR /&gt;..............................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK2_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.......................................+++&lt;BR /&gt;....................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF2_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 2 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.................................................+++&lt;BR /&gt;...........+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG2_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;..............................................+++&lt;BR /&gt;..............................................................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK3_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;................................+++&lt;BR /&gt;............................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF3_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 3 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.........................................+++&lt;BR /&gt;..........................................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG3_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating SRK key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.........................+++&lt;BR /&gt;...................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'SRK4_sha256_2048_65537_v3_ca'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:51 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating CSF key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;................................................................+++&lt;BR /&gt;...................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'CSF4_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:52 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++&lt;BR /&gt;+ Generating IMG key and certificate 4 +&lt;BR /&gt;++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;Generating RSA private key, 2048 bit long modulus&lt;BR /&gt;.............................................................................................+++&lt;BR /&gt;......................................................................................................+++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Using configuration from ../ca/openssl.cnf&lt;BR /&gt;Check that the request matches the signature&lt;BR /&gt;Signature ok&lt;BR /&gt;The Subject's Distinguished Name is as follows&lt;BR /&gt;commonName :ASN.1 12:'IMG4_1_sha256_2048_65537_v3_usr'&lt;BR /&gt;Certificate is to be certified until Jun 3 16:03:52 2028 GMT (3650 days)&lt;/P&gt;&lt;P&gt;Write out database with 1 new entries&lt;BR /&gt;Data Base Updated&lt;BR /&gt;luoyonghe@luoyonghe-Latitude-5480:~/cst/release/keys$ &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 16:10:36 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/uboot-%E5%8A%A0%E5%85%A5Secure-boot%E5%8A%9F%E8%83%BD-%E4%B8%94%E5%8A%A0%E5%85%A5%E7%9A%84CST%E7%94%9F%E6%88%90%E7%9A%84%E7%AD%BE%E5%90%8D%E6%96%87%E4%BB%B6-%E7%83%A7%E5%86%99%E8%BF%9B%E5%8E%BB%E5%90%8E%E4%BB%8D%E7%84%B6%E6%8F%90%E7%A4%BA%E9%94%99%E8%AF%AF/m-p/775637#M120428</guid>
      <dc:creator>yongheluo_hotma</dc:creator>
      <dc:date>2018-06-06T16:10:36Z</dc:date>
    </item>
  </channel>
</rss>

