<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure boot i.mx7D in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815156#M125587</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already boot up the board in a secure manner using a closed device + a signed u-boot =&amp;gt; so this is secure!&lt;/P&gt;&lt;P&gt;The feature is called secure boot :smileyhappy:&amp;nbsp;not "secure every app in every stage".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you already boot up, you can use any other app to play with, even a non-signed u-boot.&lt;/P&gt;&lt;P&gt;How you started the 2nd u-boot?&amp;nbsp;&lt;/P&gt;&lt;P&gt;In theory, if the device is closed the u-boot terminal is no longer&amp;nbsp;available&amp;nbsp;for the user. If still available, you can set boot_delay to 0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To stop loading a 2nd u-boot via jtag, you can disable the JTAG programming a dedicated fuse for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw, for full a full secure chain of trust u-boot - Linux, please take a look also to this AN [1]. But again, even in Linux you can load a custom application. After the device is booting up in a secure manner, it's up to you to maintain the system in a secure state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Marius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[1]&amp;nbsp;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN4581.pdf" title="https://www.nxp.com/docs/en/application-note/AN4581.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN4581.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jul 2018 15:40:37 GMT</pubDate>
    <dc:creator>marius_grigoras</dc:creator>
    <dc:date>2018-07-16T15:40:37Z</dc:date>
    <item>
      <title>Secure boot i.mx7D</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815155#M125586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;I have closed my device and secured my device ,hab_status shows that&amp;nbsp;Secure boot enabled.I have downloaded a signed u-boot.imx ,but why I can download a no signed boot.img .It's not secure.I think a signed u-boot.imx can't load a no signed boot.img.Can you help me.Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 09:23:35 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815155#M125586</guid>
      <dc:creator>llliu</dc:creator>
      <dc:date>2018-07-16T09:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Secure boot i.mx7D</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815156#M125587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already boot up the board in a secure manner using a closed device + a signed u-boot =&amp;gt; so this is secure!&lt;/P&gt;&lt;P&gt;The feature is called secure boot :smileyhappy:&amp;nbsp;not "secure every app in every stage".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you already boot up, you can use any other app to play with, even a non-signed u-boot.&lt;/P&gt;&lt;P&gt;How you started the 2nd u-boot?&amp;nbsp;&lt;/P&gt;&lt;P&gt;In theory, if the device is closed the u-boot terminal is no longer&amp;nbsp;available&amp;nbsp;for the user. If still available, you can set boot_delay to 0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To stop loading a 2nd u-boot via jtag, you can disable the JTAG programming a dedicated fuse for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw, for full a full secure chain of trust u-boot - Linux, please take a look also to this AN [1]. But again, even in Linux you can load a custom application. After the device is booting up in a secure manner, it's up to you to maintain the system in a secure state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Marius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[1]&amp;nbsp;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN4581.pdf" title="https://www.nxp.com/docs/en/application-note/AN4581.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN4581.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 15:40:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815156#M125587</guid>
      <dc:creator>marius_grigoras</dc:creator>
      <dc:date>2018-07-16T15:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Secure boot i.mx7D</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815157#M125588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Boot ROM does not allow to run unsigned U-boot; further responsibility for verifying and running applications&lt;/P&gt;&lt;P&gt;under U-boot belongs to the U-boot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 02:55:54 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-boot-i-mx7D/m-p/815157#M125588</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2018-07-19T02:55:54Z</dc:date>
    </item>
  </channel>
</rss>

