<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Boot fail with secure OS in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991848#M147206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;I am enabling secure boot with iMX8XQ platform.&lt;BR /&gt;My platform boots with SD card.&lt;BR /&gt;It can boot up with secure u-boot, but boot fail with secure OS.&lt;BR /&gt;Below is boot log:&lt;BR /&gt;=====&amp;gt;&lt;BR /&gt;mmc1 is current device&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;** Unable to read file boot.scr **&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;** Unable to read file os_cntr_signed.bin **&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Booting from net ...&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;ethernet@5b040000 Waiting for PHY auto negotiation to complete.........TIMEOUT !&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Could not initialize PHY &lt;A href="mailto:ethernet@5b040000"&gt;ethernet@5b040000 &lt;/A&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 1&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 2&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 3&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 4&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 5&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 6&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 7&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 8&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 9&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 10&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 11&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 12&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 13&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 14&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 15&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 16&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 17 &amp;nbsp;&lt;BR /&gt;Retry time exceeded; starting again&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Authenticate OS container at 0x88000000&amp;nbsp;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Wrong container header&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;ERR: failed to authenticate &amp;nbsp;&lt;BR /&gt;&amp;lt;====&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;From boot log, system can't find signed OS file.&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;I used below command to copy OS container to system.&lt;BR /&gt;$ sudo cp os_cntr_signed.bin /media/root/Boot/imx8qx&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;The command to copy OS container to system in mx8_mx8x_secure_boot.txt is:&lt;BR /&gt;&amp;nbsp; $ sudo cp os_cntr_signed.bin /media/UserID/Boot\ imx8qx&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;What is wrong with my command?&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Owen Chiu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Nov 2019 07:22:04 GMT</pubDate>
    <dc:creator>owenchiu</dc:creator>
    <dc:date>2019-11-01T07:22:04Z</dc:date>
    <item>
      <title>Boot fail with secure OS</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991848#M147206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;I am enabling secure boot with iMX8XQ platform.&lt;BR /&gt;My platform boots with SD card.&lt;BR /&gt;It can boot up with secure u-boot, but boot fail with secure OS.&lt;BR /&gt;Below is boot log:&lt;BR /&gt;=====&amp;gt;&lt;BR /&gt;mmc1 is current device&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;** Unable to read file boot.scr **&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;** Unable to read file os_cntr_signed.bin **&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Booting from net ...&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;ethernet@5b040000 Waiting for PHY auto negotiation to complete.........TIMEOUT !&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Could not initialize PHY &lt;A href="mailto:ethernet@5b040000"&gt;ethernet@5b040000 &lt;/A&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 1&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 2&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 3&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 4&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 5&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 6&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 7&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 8&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 9&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 10&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 11&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 12&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 13&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 14&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 15&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 16&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;BOOTP broadcast 17 &amp;nbsp;&lt;BR /&gt;Retry time exceeded; starting again&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Authenticate OS container at 0x88000000&amp;nbsp;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Wrong container header&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;ERR: failed to authenticate &amp;nbsp;&lt;BR /&gt;&amp;lt;====&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;From boot log, system can't find signed OS file.&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;I used below command to copy OS container to system.&lt;BR /&gt;$ sudo cp os_cntr_signed.bin /media/root/Boot/imx8qx&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;The command to copy OS container to system in mx8_mx8x_secure_boot.txt is:&lt;BR /&gt;&amp;nbsp; $ sudo cp os_cntr_signed.bin /media/UserID/Boot\ imx8qx&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;What is wrong with my command?&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Owen Chiu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2019 07:22:04 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991848#M147206</guid>
      <dc:creator>owenchiu</dc:creator>
      <dc:date>2019-11-01T07:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Boot fail with secure OS</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991849#M147207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Owen,&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;In the boot mode you can find that the commands used for sending the kernel, device tree&amp;nbsp;and rootfs here are missing. This is because you don´t have configuration of the Ethernet or you have not connected to ethernet, as well os_cntr_signed.bin you must copy before uboot.&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;regards&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2019 15:20:05 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991849#M147207</guid>
      <dc:creator>Bio_TICFSL</dc:creator>
      <dc:date>2019-11-01T15:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Boot fail with secure OS</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991850#M147208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bio_TICFSL&amp;nbsp;&amp;nbsp;&amp;nbsp;,&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Thanks for your reply.&lt;BR /&gt;I connected ethernet and retested again.&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;System still can't read&amp;nbsp;&lt;SPAN&gt;os_cntr_signed.bin.&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;The new test log is as below.&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;I did copy&amp;nbsp;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;os_cntr_signed.bin before uboot.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;I sent&amp;nbsp;&lt;SPAN&gt;os_cntr_signed.bin to SD card with "&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;sudo cp os_cntr_signed.bin /media/root/Boot/imx8qx" command on PC.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #51626f; "&gt;Then I used this SD card&lt;SPAN style="color: #3d3d3d;"&gt;&amp;nbsp; as boot device to boot my target board.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #3d3d3d; "&gt;If the location of&amp;nbsp;os_cntr_signed.bin is correct, system shall read os_cntr_signed.bin without problem.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #3d3d3d; "&gt;That's not the case.&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #3d3d3d; "&gt;I am not sure the path of "sudo cp os_cntr_signed.bin /media/UserID/Boot\ imx8qx" in mx8_mx8x_secure_boot.txt is correct or not.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #3d3d3d; "&gt;If &lt;SPAN style="background-color: #ffffff;"&gt;boot device is SD card,&amp;nbsp;&lt;/SPAN&gt;the UserID is root and the platform is&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;imx8qx, do you think what is the exact path?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #3d3d3d; "&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;New test log :&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;===&amp;gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;U-Boot 2018.03-g0d267d5-dirty (Nov 01 2019 - 11:56:27 +0800)&lt;BR /&gt; CPU: Freescale i.MX8QXP revB A35 at 1200 MHz at 31C&lt;BR /&gt;Model: DFI.Inc i.MX8QXP F8700&lt;BR /&gt;Board: iMX8QXP MEK&lt;BR /&gt;Boot: SD1&lt;BR /&gt;DRAM: 4 GiB&lt;BR /&gt;setup_typec lookup gpio@1a_7 failed ret = -22&lt;BR /&gt;MMC: FSL_SDHC: 0, FSL_SDHC: 1&lt;BR /&gt;Loading Environment from MMC... *** Warning - bad CRC, using default environment&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Failed (-5)&lt;BR /&gt;TX PLL is not locked.&lt;BR /&gt;[board_video_skip] 17&lt;BR /&gt;[enable_lvds] 632&lt;BR /&gt;lvds2hdmi_setup: Can't find device id=0x4c, on bus 13&lt;BR /&gt;Display: M101NWWB_R3 (1280x800)&lt;BR /&gt;In: serial&lt;BR /&gt;Out: serial&lt;BR /&gt;Err: serial&lt;BR /&gt; &lt;BR /&gt; BuildInfo: &lt;BR /&gt; - SCFW f0226b37, SECO-FW 9d71fd5b, IMX-MKIMAGE 2cf091c0, ATF d6451cc&lt;BR /&gt; - U-Boot 2018.03-g0d267d5-dirty&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;switch to partitions #0, OK&lt;BR /&gt;mmc1 is current device&lt;BR /&gt;flash target is MMC:1&lt;BR /&gt;Net: &lt;BR /&gt;Warning: ethernet@5b040000 (eth0) using random MAC address - 8a:de:be:a1:a3:0f&lt;BR /&gt;eth0: ethernet@5b040000 [PRIME]&lt;BR /&gt;Warning: ethernet@5b050000 (eth1) using random MAC address - 06:d2:93:d7:1b:64&lt;BR /&gt;, eth1: ethernet@5b050000&lt;BR /&gt;Fastboot: Normal&lt;BR /&gt;Normal Boot&lt;BR /&gt;Hit any key to stop autoboot: 3     2     1     0 &lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc1 is current device&lt;BR /&gt;** Unable to read file boot.scr **&lt;BR /&gt;** Unable to read file os_cntr_signed.bin **&lt;BR /&gt; Booting from net ...&lt;BR /&gt;BOOTP broadcast 1&lt;BR /&gt;DHCP client bound to address 172.18.8.45 (18 ms)&lt;BR /&gt;Using ethernet@5b040000 device&lt;BR /&gt;TFTP from server 172.18.0.32; our IP address is 172.18.8.45&lt;BR /&gt;Filename 'SMSBoot\x64\wdsnbp.com'.&lt;BR /&gt;Load address: 0x88000000&lt;BR /&gt;Loading: * ## Warning: gatewayip needed but not set&lt;BR /&gt;###&lt;BR /&gt; 2.7 MiB/s&lt;BR /&gt;done&lt;BR /&gt;Bytes transferred = 30832 (7870 hex)&lt;BR /&gt;Authenticate OS container at 0x88000000 &lt;BR /&gt;Wrong container header&lt;BR /&gt;ERR: failed to authenticate&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&amp;lt;=====&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;P&gt;Owen Chiu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2019 02:27:22 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-fail-with-secure-OS/m-p/991850#M147208</guid>
      <dc:creator>owenchiu</dc:creator>
      <dc:date>2019-11-04T02:27:22Z</dc:date>
    </item>
  </channel>
</rss>

