<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Signing RFS, Configuration and Application with AHAB possible? in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995030#M147676</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yuri, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the fast answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am pretty new to this - but according to my understanding dm-crypts is used to encrypt my disk which protects the confidentiality of the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about signing the RFS Kernel configuration and Application to ensure the security goal "integrity" and "authenticity"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there other tools for that?&lt;/P&gt;&lt;P&gt;May it be possible with AHAB or&amp;nbsp;is there no API for that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quang&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Mar 2020 08:48:15 GMT</pubDate>
    <dc:creator>quang_bui</dc:creator>
    <dc:date>2020-03-06T08:48:15Z</dc:date>
    <item>
      <title>Signing RFS, Configuration and Application with AHAB possible?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995028#M147674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to implement secure boot on the new i.MX8X processor and having some question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the documenation of AN12312 it is possible to secure the bootloader and the OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This leads me to the question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it also possible with AHAB to sign and verify the Root File System and all Applications offered by the OEM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes - how does it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quang&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2020 15:12:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995028#M147674</guid>
      <dc:creator>quang_bui</dc:creator>
      <dc:date>2020-03-05T15:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Signing RFS, Configuration and Application with AHAB possible?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995029#M147675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Hello,&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; It may be recommended to use the DM-Crypt in Your case.&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;"i.MX Encrypted Storage Using CAAM Secure Keys"&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN12714.pdf" title="https://www.nxp.com/docs/en/application-note/AN12714.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN12714.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;BR /&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/P&gt;&lt;P class=""&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2020 02:30:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995029#M147675</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-03-06T02:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Signing RFS, Configuration and Application with AHAB possible?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995030#M147676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yuri, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the fast answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am pretty new to this - but according to my understanding dm-crypts is used to encrypt my disk which protects the confidentiality of the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about signing the RFS Kernel configuration and Application to ensure the security goal "integrity" and "authenticity"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there other tools for that?&lt;/P&gt;&lt;P&gt;May it be possible with AHAB or&amp;nbsp;is there no API for that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quang&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2020 08:48:15 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995030#M147676</guid>
      <dc:creator>quang_bui</dc:creator>
      <dc:date>2020-03-06T08:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Signing RFS, Configuration and Application with AHAB possible?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995031#M147677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;U-boot can be signed and checked by i.MX boot ROM; Linux kernel can be signed&amp;nbsp;&lt;/P&gt;&lt;P&gt;and checked by U-boot, using boot ROM HAB API, mentioned in&amp;nbsp; AN12263 (HABv4 RVT&lt;/P&gt;&lt;P&gt;Guidelines and Recommendations).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN12263.pdf" title="https://www.nxp.com/docs/en/application-note/AN12263.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN12263.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; But for Linux we do not have proper HAB API, therefore such general approach as using&amp;nbsp;&lt;/P&gt;&lt;P&gt;DM-Crypt is recommended for Linux file system and applications.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2020 08:01:14 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-RFS-Configuration-and-Application-with-AHAB-possible/m-p/995031#M147677</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-03-10T08:01:14Z</dc:date>
    </item>
  </channel>
</rss>

