<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックClarification of Boot Order when using HAB with a DCD present</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Clarification-of-Boot-Order-when-using-HAB-with-a-DCD-present/m-p/882044#M133734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking to develop a secure boot app on the I.MX8MMini EVK and have a question regarding the Boot ROM processing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that to enable Code Signing I need generate the certificate chain and set the hash in the SRK_HASH OTP area. The HAB code will then authenticate against my certs. I can use the hab_status to verify a clean, authenticated boot. This is covered in AN4581.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now - I would like to avoid blowing fuses at all costs, so ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the OTP area is covered by writable shadow registers, I'm thinking that i can use the DCD block to program the shadow SRK_HASH using registers&amp;nbsp;OCOTP_HW_OCOTP_SRK[0-7] which would &lt;EM&gt;simulate&lt;/EM&gt; me having programmed the real OTP value. However this will only work if the Boot ROM applies the DCD before it verifies the image signature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you please clarify if the ROM boot order, does it ...&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Apply the DCD configuration then HAB checks image signature and jumps to code or&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;HAB Verifies the image and THEN applies the DCD, then jumps to the entry point.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Apr 2019 16:24:16 GMT</pubDate>
    <dc:creator>philiph</dc:creator>
    <dc:date>2019-04-05T16:24:16Z</dc:date>
    <item>
      <title>Clarification of Boot Order when using HAB with a DCD present</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Clarification-of-Boot-Order-when-using-HAB-with-a-DCD-present/m-p/882044#M133734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking to develop a secure boot app on the I.MX8MMini EVK and have a question regarding the Boot ROM processing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that to enable Code Signing I need generate the certificate chain and set the hash in the SRK_HASH OTP area. The HAB code will then authenticate against my certs. I can use the hab_status to verify a clean, authenticated boot. This is covered in AN4581.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now - I would like to avoid blowing fuses at all costs, so ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the OTP area is covered by writable shadow registers, I'm thinking that i can use the DCD block to program the shadow SRK_HASH using registers&amp;nbsp;OCOTP_HW_OCOTP_SRK[0-7] which would &lt;EM&gt;simulate&lt;/EM&gt; me having programmed the real OTP value. However this will only work if the Boot ROM applies the DCD before it verifies the image signature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you please clarify if the ROM boot order, does it ...&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Apply the DCD configuration then HAB checks image signature and jumps to code or&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;HAB Verifies the image and THEN applies the DCD, then jumps to the entry point.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2019 16:24:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Clarification-of-Boot-Order-when-using-HAB-with-a-DCD-present/m-p/882044#M133734</guid>
      <dc:creator>philiph</dc:creator>
      <dc:date>2019-04-05T16:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification of Boot Order when using HAB with a DCD present</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Clarification-of-Boot-Order-when-using-HAB-with-a-DCD-present/m-p/882045#M133735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; I've sent Your some comments directly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;-------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Apr 2019 06:17:13 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Clarification-of-Boot-Order-when-using-HAB-with-a-DCD-present/m-p/882045#M133735</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2019-04-08T06:17:13Z</dc:date>
    </item>
  </channel>
</rss>

