<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: HABv4 CST size of encripted data</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023790#M151302</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; the following Community discussion may help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.nxp.com/message/1086197"&gt;https://community.nxp.com/message/1086197&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Mar 2020 13:43:43 GMT</pubDate>
    <dc:creator>Yuri</dc:creator>
    <dc:date>2020-03-27T13:43:43Z</dc:date>
    <item>
      <title>HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023786#M151298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I am trying to sign and encrypt imx6`s linux + initramfs image by cst. cst crashes during data encryption.&lt;/P&gt;&lt;P&gt;I also tried to play with len of encrypted data, it worked till some kind of limit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cfs script which does not work:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;# The syntax for this file is documented in the HAB Code-Signing Tool&lt;BR /&gt;# User's Guide which is included in the CST package distributed by NXP&lt;BR /&gt;[Header]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version = 4.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hash Algorithm = sha256&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine Configuration = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate Format = X509&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Format = CMS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine = CAAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "./SRK_table.bin"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source index = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "./security/crts/CSF1_1_sha256_4096_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Key]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "./security/crts/IMG1_1_sha256_4096_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 312844288 10854400 0x20 "zImage.initramfs.signed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 301990144 0x100 0x20 "zImage.initramfs.signed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000000 0x0 0x40 "zImage.initramfs.signed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Secret Key]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key = "./security/dek.bin"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Length = 256&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blob address = 301989632&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Decrypt Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 301989952 0x40 192 "zImage.initramfs.signed", \&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 301990176 288 10854112 "zImage.initramfs.signed"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;csf script which still works:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;# The syntax for this file is documented in the HAB Code-Signing Tool&lt;BR /&gt;# User's Guide which is included in the CST package distributed by NXP&lt;BR /&gt;[Header]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version = 4.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hash Algorithm = sha256&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine Configuration = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate Format = X509&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Format = CMS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine = CAAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "./SRK_table.bin"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source index = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "./security/crts/CSF1_1_sha256_4096_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Key]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "./security/crts/IMG1_1_sha256_4096_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 312844288 10854400 0x20 "zImage.initramfs.signed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 301990144 0x100 0x20 "zImage.initramfs.signed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000000 0x0 0x40 "zImage.initramfs.signed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Secret Key]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key = "./security/dek.bin"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Length = 256&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blob address = 301989632&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Decrypt Data]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 301989952 0x40 192 "zImage.initramfs.signed", \&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 301990176 288 8300000 "zImage.initramfs.signed"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cst version is :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~/work/mel11-imx6/workspace/build/tmp/work/nitrogen6x_mel-mel-linux-gnueabi/linux-mel/4.14.78-nitrogen6x-mel+gitAUTOINC+b87a171d5c-r0/recipe-sysroot-native/usr/bin/cst -v&lt;BR /&gt;Code Signing Tool release version 3.1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please guide how to fix the issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Mar 2020 13:04:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023786#M151298</guid>
      <dc:creator>valentinsitdiko</dc:creator>
      <dc:date>2020-03-26T13:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023787#M151299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Hello,&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; It is recommended to use DM-Crypt for filesystem:&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;"AN12714 i.MX Encrypted Storage Using CAAM Secure Keys"&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN12714.pdf" title="https://www.nxp.com/docs/en/application-note/AN12714.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN12714.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;BR /&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/P&gt;&lt;P class=""&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2020 03:50:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023787#M151299</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-03-27T03:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023788#M151300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot, you are right but we have requirements from our customer:&lt;/P&gt;&lt;P&gt;1 Linux image should be signed and encrypted.&lt;/P&gt;&lt;P&gt;2 Rootfs should be encrypted and IMA/EVM should be used to check integrity&lt;/P&gt;&lt;P&gt;To satisfy 2 we need have small initramfs which setups DM-crypt/Luks and IMA/EVM.&lt;/P&gt;&lt;P&gt;More over it seems like issue depending on size of encrypted data. So nobody say that kernel image should be less than some limit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway have you ever tried encrypted rootfs with CAAM and CAAM`s secure key ? It would be nice if you can share your experience. From our current project it looks like not such straight forward&amp;nbsp; as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2020 09:39:56 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023788#M151300</guid>
      <dc:creator>valentinsitdiko</dc:creator>
      <dc:date>2020-03-27T09:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023789#M151301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yuri.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your comment regarding DM-Crypt. However Valentin was asking about signing and encrypting the kernel and initramfs, rather than rootfs.&amp;nbsp;According to our tests, Code Signing Tool starts crashing depending on the size of zImage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding an application note you've linked. I have checked the source code. Two obvious problems from the&amp;nbsp;first glance. It seems the 5 year old bug with DM-Crypt and CAAM still is not fixed. Instead DM-crypt is changed to be broken for all other crypto drivers. Next, the&amp;nbsp;0001-full-disk-encryption-using-caam-secure-key.patch patch&amp;nbsp;makes dm-crypt accept keys with different key types,&amp;nbsp;however later the code assumes that it can use user_key_payload for each and every key it got (which is far from being true). It works for a demo, but I would not&amp;nbsp;use this code in the production software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp;&lt;/P&gt;&lt;P&gt;With best wishes&lt;/P&gt;&lt;P&gt;Dmtiry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2020 11:09:49 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023789#M151301</guid>
      <dc:creator>dmitry_eremin-s</dc:creator>
      <dc:date>2020-03-27T11:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023790#M151302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; the following Community discussion may help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.nxp.com/message/1086197"&gt;https://community.nxp.com/message/1086197&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2020 13:43:43 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023790#M151302</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-03-27T13:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023791#M151303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is ulimit -S -s the only solution or there is fixed version of CST?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2020 11:18:39 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023791#M151303</guid>
      <dc:creator>valentinsitdiko</dc:creator>
      <dc:date>2020-03-30T11:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023792#M151304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; CST sources are provided in the package. Customers can recompile it as needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2020 12:50:55 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023792#M151304</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-03-30T12:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: HABv4 CST size of encripted data</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023793#M151305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/dmitry_eremin-solenikov@mentor.com"&gt;dmitry_eremin-solenikov@mentor.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Customers can apply to the Proservice to adapt DM-crypt for their&amp;nbsp; requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2020 12:53:09 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HABv4-CST-size-of-encripted-data/m-p/1023793#M151305</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-03-30T12:53:09Z</dc:date>
    </item>
  </channel>
</rss>

