<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981609#M145840</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;it looks like I ran into the same issue. Could you please provide the information for me as well ?&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Cajus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Jun 2020 13:04:05 GMT</pubDate>
    <dc:creator>c_hahn</dc:creator>
    <dc:date>2020-06-02T13:04:05Z</dc:date>
    <item>
      <title>Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981607#M145838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm trying to used the code signing tool (CST) with a HSM. I'm following instructions from "Code-Signing&amp;nbsp;Tool – HSM&amp;nbsp;User’s Guide&amp;nbsp;Rev. 3.0.1&amp;nbsp;May 2018".&lt;/P&gt;&lt;P&gt;When I try running "make all" after copying 'libfrontend.a' to current working directory I get a curious error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ubuntu@GHFL71X2E:~/cst/release_3_3_0/code/back_end-hsm/src$ make all&lt;BR /&gt;$ARCH is []&lt;BR /&gt;gcc -std=c99 -D_POSIX_C_SOURCE=200809L -Wall -Werror -g -Wall -o cst libfrontend.a libbackend.a -L./lib -I/../openssl/include -mno-ms-bitfields -L/../openssl/lib -lssl -lcrypto -ldl -lpthread -lconfig -fno-builtin -fno-strict-aliasing -fno-common -DREMOVE_ENCRYPTION -Wl,--allow-multiple-definition&lt;BR /&gt;libfrontend.a(openssl_helper.o): In function `EVP_MD_CTX_free':&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:115: undefined reference to `EVP_MD_CTX_cleanup'&lt;BR /&gt;libfrontend.a(openssl_helper.o): In function `openssl_initialize':&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:182: undefined reference to `ERR_load_crypto_strings'&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:183: undefined reference to `OPENSSL_add_all_algorithms_noconf'&lt;BR /&gt;libfrontend.a(openssl_helper.o): In function `sign_data':&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:251: undefined reference to `EVP_MD_CTX_create'&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:275: undefined reference to `EVP_MD_CTX_destroy'&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:286: undefined reference to `EVP_MD_CTX_destroy'&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:303: undefined reference to `EVP_MD_CTX_destroy'&lt;BR /&gt;collect2: error: ld returned 1 exit status&lt;BR /&gt;Makefile:77: recipe for target 'all' failed&lt;BR /&gt;make: *** [all] Error 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is curious because openssl_helper.c is a file common to the backend as well, but it isn't flagged there&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Feb 2020 14:51:02 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981607#M145838</guid>
      <dc:creator>WILBURCOLACO</dc:creator>
      <dc:date>2020-02-04T14:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981608#M145839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp; I've sent You directly some information. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;-------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2020 07:14:09 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981608#M145839</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-02-10T07:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981609#M145840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;it looks like I ran into the same issue. Could you please provide the information for me as well ?&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Cajus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2020 13:04:05 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981609#M145840</guid>
      <dc:creator>c_hahn</dc:creator>
      <dc:date>2020-06-02T13:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981610#M145841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/c.hahn"&gt;c.hahn&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; To build the backend for CST 3.3.0 you need OpenSSL 1.0.2 as stated in the&lt;/P&gt;&lt;P&gt;release/code/back_end-hsm/README.md file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CST-HSM backend depends on:&lt;/P&gt;&lt;P&gt;- OpenSSL 1.0.2x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2020 05:30:12 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981610#M145841</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-06-03T05:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981611#M145842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;yes, I saw that, but the "normal" CST seems to work with openSSL 1.1.1 as well.&lt;/P&gt;&lt;P&gt;The 64bit Linux version does, the 32 bit Linux version does not!&lt;/P&gt;&lt;P&gt;The linux32/bin/cst depends explicitly on libcrypto-1.0, which belongs to openSSL 1.0x.&lt;/P&gt;&lt;P&gt;This is not the case for linux64/bin/cst. Confusing.&lt;/P&gt;&lt;P&gt;openSSL 1.0.2 is depreciated and outdated. Every newer Linux distribution uses 1.1.1x.&lt;/P&gt;&lt;P&gt;It is not possible to have 1.0 and 1.1 on the same host at the same time (at least not the development files)&lt;/P&gt;&lt;P&gt;I am even more confused about the fact that my linker error comes form libfrontend.a(openssl_helper.o) and not from libbackend.a (which I built from code/back-end-hsm)! The libfrontend.a is from the linux64/lib directory (as described in the documentation) and I would expect runtime issues if this library was used for building the linux64/bin/cst.&lt;/P&gt;&lt;P&gt;Is there really no way to make it working under openSSL 1.1.1x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cajus@linux:~/cst-3.3.0/code/back_end-hsm/src&amp;gt; make all&lt;BR /&gt;$ARCH is []&lt;BR /&gt;gcc&amp;nbsp;&amp;nbsp; -std=c99&amp;nbsp; -D_POSIX_C_SOURCE=200809L -Wall -Werror -g -Wall -o cst&amp;nbsp; libfrontend.a libbackend.a -L./lib&amp;nbsp; -I/../openssl/include -mno-ms-bitfields -L/../openssl/lib -lssl -lcrypto -ldl -lpthread -lconfig -fno-builtin -fno-strict-aliasing -fno-common -DREMOVE_ENCRYPTION -Wl,--allow-multiple-definition&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: libfrontend.a(openssl_helper.o): in function `EVP_MD_CTX_free':&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:115: undefined reference to `EVP_MD_CTX_cleanup'&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: libfrontend.a(openssl_helper.o): in function `openssl_initialize':&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:182: undefined reference to `ERR_load_crypto_strings'&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: /opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:183: undefined reference to `OPENSSL_add_all_algorithms_noconf'&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: libfrontend.a(openssl_helper.o): in function `sign_data':&lt;BR /&gt;/opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:251: undefined reference to `EVP_MD_CTX_create'&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: /opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:275: undefined reference to `EVP_MD_CTX_destroy'&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: /opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:286: undefined reference to `EVP_MD_CTX_destroy'&lt;BR /&gt;/usr/lib64/gcc/x86_64-suse-linux/8/../../../../x86_64-suse-linux/bin/ld: /opt/cst-repo/cst/cst-build/code/obj.linux64/../../code/common/src/openssl_helper.c:303: undefined reference to `EVP_MD_CTX_destroy'&lt;BR /&gt;collect2: error: ld returned 1 exit status&lt;BR /&gt;make: *** [Makefile:77: all] Error 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Cajus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. I just saw that you can also compile the frontend!&lt;/P&gt;&lt;P&gt;cajus@linux:~/cst-3.3.0/code/cst&amp;gt; OSTYPE=linux64 make&lt;/P&gt;&lt;P&gt;This will build a new libfrontend.a. With this lib my backend compiles without errors, but I'll need to check if it runs as expected......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edit: 9th June:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The back_end-hsm code does not run as expected :-(&lt;/P&gt;&lt;P&gt;It stuck in the backend in some ENGINE_ call, no error message, nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides that I found out, that the back_end-hsm code requires a HSM that has the capability of writing and &lt;STRONG&gt;downloading&lt;/STRONG&gt; private keys from the HSM stick.&lt;/P&gt;&lt;P&gt;Downloading a private key from a HSM is a secutiry issue and not supported by many HSMs.&lt;/P&gt;&lt;P&gt;The normal way would be to to create a private/public key pair &lt;STRONG&gt;inside&lt;/STRONG&gt; the HSM and download the public key.&lt;/P&gt;&lt;P&gt;The private key will &lt;STRONG&gt;never&lt;/STRONG&gt; leave the HSM, thats what makes it safe.&lt;/P&gt;&lt;P&gt;To certify your data you need to push the data through the HSM and get the certificate out.&lt;/P&gt;&lt;P&gt;This is not supported by the current back_end-hsm implementation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2020 05:55:59 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/981611#M145842</guid>
      <dc:creator>c_hahn</dc:creator>
      <dc:date>2020-06-03T05:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/1157820#M162391</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/55026"&gt;@c_hahn&lt;/a&gt;&amp;nbsp;&amp;nbsp;Did you have any luck working around this? It's upsetting that I have poured hours into implementation just to get to this same point. When I was running the CST-3.1.0, it appeared I was getting stuck in some ENGINE call as well. I did not run the hab4pki scripts; I generated the full PKI on my Nitrokey HSM and was trying to use that. I have all the certs locally, but did not want to expose the private keys (nor do I think there is an ability to). I have no idea how NXP is actually testing this; maybe they are only using HSMs capable of exporting private keys?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 14:41:02 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/1157820#M162391</guid>
      <dc:creator>cheuschkel</dc:creator>
      <dc:date>2020-09-23T14:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Code-Signing Tool – HSM. Has anyone built it successfully?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/1203660#M166903</link>
      <description>&lt;P&gt;&lt;FONT face="arial" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Below are&amp;nbsp;&lt;FONT style="font-family: Arial;"&gt;a few points that might come useful for others:&lt;BR /&gt;- In AN12812, section 3.3, back_end-engine compilation does not work until you build the libfrontend static &lt;BR /&gt;&amp;nbsp;&amp;nbsp; library and copy it to $OSTYPE/lib/ folder, since it is not pre-compiled in latest release of the cst.&lt;BR /&gt;&amp;nbsp;- In AN12812, item 6 of section 3.4.1.2 (Using in systems without p11-kit) should also be done in systems with p11-kit available.&lt;BR /&gt;&amp;nbsp;- On Ubuntu 16.04, packages opensc &amp;amp; opensc-pkcs11 are available in outdated versions that do not work with the SmartCard HSM.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up to date releases are available for download here: &lt;A href="https://github.com/Nitrokey/opensc-build" target="_blank"&gt;https://github.com/Nitrokey/opensc-build&lt;/A&gt;&lt;/FONT&gt; &lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 12:11:59 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Code-Signing-Tool-HSM-Has-anyone-built-it-successfully/m-p/1203660#M166903</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-12-23T12:11:59Z</dc:date>
    </item>
  </channel>
</rss>

