<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: NXP's Secure boot variant for i.MX8M</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995373#M147713</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/igorpadykov"&gt;igorpadykov&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Can you please respond to my question#3 above?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 May 2020 06:00:35 GMT</pubDate>
    <dc:creator>saikumarmails</dc:creator>
    <dc:date>2020-05-14T06:00:35Z</dc:date>
    <item>
      <title>NXP's Secure boot variant for i.MX8M</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995370#M147710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All, it is going to be a bit long question as I'm putting the questions and observations I had.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using i.MX8M EVK and trying to enable the secure boot feature on the same. After doing some study &amp;amp; searching I didn't find specific details on which variant of secure boot the i.MX8M EVK supports? (is it HAB version 4? or AHAB?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason for this question is none the application notes I'm referring (AN4581,&amp;nbsp;AN12263 &amp;amp;&amp;nbsp;AN12312) have details about i.MX8M (specifically). When one of my teammate reached out to the NXP support they replied&amp;nbsp;&lt;SPAN&gt;AN12312 applies to i.MX8M but no where does that document list i.MX8M.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, when referring the u-boot code base &lt;A class="link-titled" href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/introduction_ahab.txt?h=imx_v2019.04_4.19.35_1.1.0" title="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/introduction_ahab.txt?h=imx_v2019.04_4.19.35_1.1.0"&gt;introduction_ahab.txt\ahab\imx\doc - uboot-imx - i.MX U-Boot&lt;/A&gt;&amp;nbsp;&amp;nbsp;- the&amp;nbsp;introduction&amp;nbsp;text file under AHAB only lists&amp;nbsp;i.MX8/8x and&amp;nbsp;&lt;A class="link-titled" href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4/introduction_habv4.txt?h=imx_v2019.04_4.19.35_1.1.0" title="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4/introduction_habv4.txt?h=imx_v2019.04_4.19.35_1.1.0"&gt;introduction_habv4.txt\habv4\imx\doc - uboot-imx - i.MX U-Boot&lt;/A&gt;&amp;nbsp;&amp;nbsp;- the introduction text file under HAB4 refers to&amp;nbsp;i.MX 8M&amp;nbsp;&amp;amp; i.MX 8MM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The above reasons caused confusion to my understanding about the variant of secure boot supported for i.MX8M.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below are the questions I had&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. What does the boot ROM of i.MX8M (i.MX8M EVK) gets programmed/shipped with? (Is it HAB4 or AHAB?)&amp;nbsp;Is there a chance that i.MX8M supports both? If yes,&amp;nbsp;how to check the variant of the secure boot for an i.MX processor?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. When we enable secure boot in u-boot configuration file for i.MX8M in yocto,&amp;nbsp;which APIs they try to access from boot ROM?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Lastly and importantly, is there a way to verify signed Linux Image from u-boot's command line without programming the fuses (using the shadow registers etc.,)? as I am a first time fuse programmer and don't want to brick the board with out verifying the functionality first. Any work around or help is highly appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for the patience to make it to the end.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i.mx 8m u-boot‌ &amp;nbsp;secureboot‌ imx8m‌&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2020 13:42:07 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995370#M147710</guid>
      <dc:creator>saikumarmails</dc:creator>
      <dc:date>2020-01-23T13:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: NXP's Secure boot variant for i.MX8M</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995371#M147711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venkatasai&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN&gt;1. What does the boot ROM of i.MX8M (i.MX8M EVK) gets programmed/shipped with? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;(Is it HAB4 or AHAB?)&amp;nbsp;Is there a chance that i.MX8M supports both?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;for i.MX8M supported only HAB4, so old app notes are applicable to it. Also one can check &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A class="link-titled" href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4?h=imx_v2019.04_4.19.35_1.1.0" title="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4?h=imx_v2019.04_4.19.35_1.1.0"&gt;habv4\imx\doc - uboot-imx - i.MX U-Boot&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For other questions one can refer to &lt;A href="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=IMX8MDQLQSRM&amp;amp;appType=moderated" target="_blank"&gt;&lt;STRONG&gt;Security Reference Manual for i.MX 8M Dual/8M QuadLite/8M Quad&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2020 23:17:15 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995371#M147711</guid>
      <dc:creator>igorpadykov</dc:creator>
      <dc:date>2020-01-23T23:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: NXP's Secure boot variant for i.MX8M</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995372#M147712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/igorpadykov"&gt;igorpadykov&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Thanks for the confirmation and references, they were helpful and using them I could get the u-boot's sign verified by boot ROM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp;also&amp;nbsp;did some searching for the question#3 in the SRM and couldn't find any. could you help me with some more info? I think this way we could be confident before programming the fuses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;3. Lastly and importantly, is there a way to verify signed Linux Image from u-boot's command line without programming the fuses (using the shadow registers etc.,)? as I am a first time fuse programmer and don't want to brick the board with out verifying the functionality first. Any work around or help is highly appreciated.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2020 03:53:29 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995372#M147712</guid>
      <dc:creator>saikumarmails</dc:creator>
      <dc:date>2020-03-02T03:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: NXP's Secure boot variant for i.MX8M</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995373#M147713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/igorpadykov"&gt;igorpadykov&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Can you please respond to my question#3 above?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 May 2020 06:00:35 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995373#M147713</guid>
      <dc:creator>saikumarmails</dc:creator>
      <dc:date>2020-05-14T06:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: NXP's Secure boot variant for i.MX8M</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995374#M147714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venkatasai&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Can you please respond to my question#3 above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;old app notes are applicable to it:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A data-content-finding="Community" href="https://community.nxp.com/external-link.jspa?url=https%3A%2F%2Fsource.codeaurora.org%2Fexternal%2Fimx%2Fuboot-imx%2Ftree%2Fdoc%2Fimx%2Fhabv4%3Fh%3Dimx_v2019.04_4.19.35_1.1.0" rel="nofollow" target="_blank"&gt;habv4\imx\doc - uboot-imx - i.MX U-Boot&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.nxp.com/docs/en/application-note/AN12056.pdf" target="_blank"&gt;&lt;STRONG&gt;Encrypted Boot on HABv4 and CAAM Enabled Devices &lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://boundarydevices.com/high-assurance-boot-hab-dummies/" title="https://boundarydevices.com/high-assurance-boot-hab-dummies/"&gt;https://boundarydevices.com/high-assurance-boot-hab-dummies/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 May 2020 06:18:31 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/NXP-s-Secure-boot-variant-for-i-MX8M/m-p/995374#M147714</guid>
      <dc:creator>igorpadykov</dc:creator>
      <dc:date>2020-05-14T06:18:31Z</dc:date>
    </item>
  </channel>
</rss>

