<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe:  i.MX7D NAND secure boot</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894905#M135249</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Please look at my comments below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I.MX7 NAND boot (both secure and usual) is supported.&lt;/P&gt;&lt;P&gt;Note, in open mode any image (signed or unsigned) can be executed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In close mode only signed images will executed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt; Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Apr 2019 08:12:26 GMT</pubDate>
    <dc:creator>Yuri</dc:creator>
    <dc:date>2019-04-15T08:12:26Z</dc:date>
    <item>
      <title>i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894904#M135248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Thanks for this link.&lt;/P&gt;&lt;P&gt;Do you know whether secure boot supports on NAND flash too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Our FAE donwload the same BSP (&lt;SPAN style="background-color: #ffffff;"&gt;L4.9.11_1.0.0&lt;/SPAN&gt;) without any patch and just enabled SECURE_BOOT flag as mentioned in&amp;nbsp;AN4581.pdf, it can boot up from SD card or SPI flash no matter this boot image is signed or not.&lt;/P&gt;&lt;P&gt;PS. our EVK is a open device (We don't blow fuse to close it.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; But it's failed to boot up from flash (SECURE_BOOT is enabled and UBOOT_CONFIG = "nand") no matter this boot image is signed or not. (This EVK is reworked to boot from NAND flash. It can boot up if SECURE_BOOT is disabled.)&lt;/P&gt;&lt;P&gt;Do you have any advice for this symptom or is there any patch for this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jordan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2019 10:14:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894904#M135248</guid>
      <dc:creator>jordan_chen</dc:creator>
      <dc:date>2019-04-12T10:14:30Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894905#M135249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Please look at my comments below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I.MX7 NAND boot (both secure and usual) is supported.&lt;/P&gt;&lt;P&gt;Note, in open mode any image (signed or unsigned) can be executed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In close mode only signed images will executed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt; Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2019 08:12:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894905#M135249</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2019-04-15T08:12:26Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894906#M135250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jordan &lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/jordan_chen@sercomm.com"&gt;jordan_chen@sercomm.com&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So have you finally managed to get it working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently playing&amp;nbsp;on iMX7D NAND&amp;nbsp;with mainline U-boot (U-Boot 2019.10-rc2) with CONFIG_SECURE_BOOT=y and&amp;nbsp;facing the same issue, althought it's working when I try to boot it from eMMC (also&amp;nbsp;&lt;SPAN&gt;CONFIG_SECURE_BOOT=y&lt;/SPAN&gt;).&lt;BR /&gt;&lt;BR /&gt;SRK values aren't fused and obviously the device isn't "closed", and I haven't&amp;nbsp;concatenated&amp;nbsp;CSF to the U-boot image (althought booting from eMMC works without any issues).&lt;BR /&gt;After going throught all details&amp;nbsp;AN4581 doc I understood that BootROM&amp;nbsp;should also boot U-boot image even if the image isn't properly signed if SRK&amp;nbsp;isn't fused and device is in open state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After disabling&amp;nbsp;&lt;SPAN&gt;CONFIG_SECURE_BOOT (or even just removing CSF command from imximage.cfg) the image&amp;nbsp;boots.&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:52:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894906#M135250</guid>
      <dc:creator>igor_opaniuk</dc:creator>
      <dc:date>2019-09-11T16:52:03Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894907#M135251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Igor,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;It's not workable for me too. But you can refer to following link for&amp;nbsp;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;iMX7D NAND Secure Boot. Maybe you have to take care for the image start address which mentioned in "NOTE" of F.1. "Signing code downloadable with the manufacturing tool" in AN4581 if your device is Rev D.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://community.nxp.com/docs/DOC-332725"&gt;iMX7D Plugin mode HAB (High Assurance Boot)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jordan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2019 10:11:39 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894907#M135251</guid>
      <dc:creator>jordan_chen</dc:creator>
      <dc:date>2019-09-12T10:11:39Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894908#M135252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;A _jive_internal="true" data-content-finding="Community" data-userid="11235" data-username="Yuri" href="https://community.nxp.com/people/Yuri" style="color: #3d9ce7; background-color: #ffffff; border: 0px; font-weight: 200; text-decoration: none; font-size: 1.286rem;"&gt;&lt;BR /&gt;Yuri Muhin&lt;/A&gt;&lt;SPAN style="color: #3d9ce7; background-color: #ffffff; font-weight: 500;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;&amp;nbsp;I.MX7 NAND boot (both secure and usual) is supported.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to cross check this by someone from NXP (just to confirm that U-boot boots from NAND built with &lt;SPAN&gt;CONFIG_IMX_HAB=y&lt;/SPAN&gt;)?&lt;BR /&gt;Both mainline and downstream&amp;nbsp;U-boot (from NXP) are acting in the same on iMX7D + NAND based setups:&lt;BR /&gt;If&amp;nbsp;CSF region is embedded (when CONFIG_IMX_HAB=y ) into the final U-boot imx binary, BootROM never boots it and goes to recovery mode.&amp;nbsp;When `CSF` CMD is removed from imximage.cfg before creating final U-boot binary, the image starts booting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is already discussion about this in U-boot ML, but without any final conclusion&amp;nbsp;&lt;A class="link-titled" href="http://u-boot.10912.n7.nabble.com/nxp-HABv4-secure-boot-on-iMX7-NAND-broken-td379251.html#a383822" title="http://u-boot.10912.n7.nabble.com/nxp-HABv4-secure-boot-on-iMX7-NAND-broken-td379251.html#a383822"&gt;U-Boot - nxp: HABv4 secure boot on iMX7 NAND broken&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2019 16:45:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894908#M135252</guid>
      <dc:creator>igor_opaniuk</dc:creator>
      <dc:date>2019-12-09T16:45:50Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894909#M135253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; What is exact part number of the i.MX7?&lt;/P&gt;&lt;P&gt;In particular, the following erratum may take place:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e11166: OCRAM: The first 4K of OCRAM (0x910000 - 0x910fff) is not available during boot time&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Dec 2019 03:40:38 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894909#M135253</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2019-12-11T03:40:38Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894910#M135254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;What is exact part number of the i.MX7?&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #252526; background-color: #ffffff; font-size: 16px;"&gt;MCIMX7D5EVM10SD&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P style="color: #51626f; border: 0px; font-size: 15px;"&gt;In particular, the following erratum may take place:&amp;nbsp;&lt;/P&gt;&lt;P style="color: #51626f; border: 0px; font-size: 15px;"&gt;e11166: OCRAM: The first 4K of OCRAM (0x910000 - 0x910fff) is not available during boot time&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;There was a reply in ML from Breno Matheus Lima from NXP, who has been working on this (in &lt;A class="link-titled" href="https://community.nxp.com/external-link.jspa?url=http%3A%2F%2Fu-boot.10912.n7.nabble.com%2Fnxp-HABv4-secure-boot-on-iMX7-NAND-broken-td379251.html%23a383822" title="https://community.nxp.com/external-link.jspa?url=http%3A%2F%2Fu-boot.10912.n7.nabble.com%2Fnxp-HABv4-secure-boot-on-iMX7-NAND-broken-td379251.html%23a383822"&gt;https://community.nxp.com/external-link.jspa?url=http%3A%2F%2Fu-boot.10912.n7.nabble.com%2Fnxp-HABv4-secure-boot-on-iMX7…&lt;/A&gt;&amp;nbsp; thread), that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 13.44px;"&gt;When booting from NAND the DCD table is not loaded in OCRAM so that&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 13.44px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 13.44px;"&gt;shouldn't be a problem. The DCD is loaded in OCRAM when booting via&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 13.44px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 13.44px;"&gt;USB OTG using the serial download protocol, you can have more details&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 13.44px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 13.44px;"&gt;in link below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/NXPmicro/mfgtools/wiki/UUU-default-support-protocol-list#habv4-closed-chip-support" rel="nofollow" style="color: #551a8b; background-color: #ffffff; font-size: 13.44px;" target="_top"&gt;https://github.com/NXPmicro/mfgtools/wiki/UUU-default-support-protocol-list#habv4-closed-chip-support&lt;/A&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2019 10:15:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894910#M135254</guid>
      <dc:creator>igor_opaniuk</dc:creator>
      <dc:date>2019-12-19T10:15:46Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894911#M135255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally, why it's hapenning and the fix is here (check the reply from Breno Matheus Lima from NXP):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://lists.denx.de/pipermail/u-boot/2019-December/394443.html" title="https://lists.denx.de/pipermail/u-boot/2019-December/394443.html"&gt;[PATCH v1] colibri_imx7: disable HAB and CAAM support&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Dec 2019 09:58:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894911#M135255</guid>
      <dc:creator>igor_opaniuk</dc:creator>
      <dc:date>2019-12-27T09:58:08Z</dc:date>
    </item>
    <item>
      <title>Re:  i.MX7D NAND secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894912#M135256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check this thread:&amp;nbsp;&lt;A class="jivelink12" href="https://lists.denx.de/pipermail/u-boot/2019-December/394443.html" title="https://lists.denx.de/pipermail/u-boot/2019-December/394443.html"&gt;https://lists.denx.de/pipermail/u-boot/2019-December/394443.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Dec 2019 09:59:28 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX7D-NAND-secure-boot/m-p/894912#M135256</guid>
      <dc:creator>igor_opaniuk</dc:creator>
      <dc:date>2019-12-27T09:59:28Z</dc:date>
    </item>
  </channel>
</rss>

