<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processorsのトピックcst different hashes from same input binary</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046091#M154065</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, can someone help me in understanding why cst is generating 2 different hashes for the same input binary?&lt;/P&gt;&lt;P&gt;I'm using this input csf:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Header]&lt;BR /&gt; Version = 4.2&lt;BR /&gt; Engine = DCP&lt;BR /&gt; Engine Configuration = 0&lt;BR /&gt; Certificate Format = x509&lt;BR /&gt; Signature Format = CMS&lt;BR /&gt; Hash Algorithm = sha256&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;BR /&gt; File = "keys/SRK_1_2_3_4_table.bin"&lt;BR /&gt; Source Index = 0&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;BR /&gt; File = "crts/CSF1_1_sha256_2048_65537_v3_usr_crt.pem"&lt;BR /&gt; Certificate Format = x509&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;[Install Key]&lt;BR /&gt; File = "crts/IMG1_1_sha256_2048_65537_v3_usr_crt.pem"&lt;BR /&gt; Verification Index = 0&lt;BR /&gt; Target Index = 2&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt; Verification Index = 2&lt;BR /&gt; Engine = DCP&lt;BR /&gt; Engine Configuration = 0&lt;BR /&gt; Blocks = 0x60001000 0x1000 0x40 "test.bin",\&lt;BR /&gt; 0x60002000 0x2000 0x40090 "test.bin"&lt;/P&gt;&lt;P&gt;[Set Engine]&lt;BR /&gt; Hash Algorithm = sha256&lt;BR /&gt; Engine = DCP&lt;BR /&gt; Engine Configuration = 0&lt;/P&gt;&lt;P&gt;[Unlock]&lt;BR /&gt; Engine = SNVS&lt;BR /&gt; Features = ZMK WRITE&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;with this command line invocation:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;cst.exe -o out_csf.bin -i input.csf&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;the result from cst seems ok:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;CSF Processed successfully and signed data available in out_csf.bin&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;But if I&amp;nbsp;execute this process twice, the content of&amp;nbsp;&amp;nbsp;out_csf.bin is different.&lt;/P&gt;&lt;P&gt;I tried to debug this thing by using the program&amp;nbsp;hab_csf_parser part of the cst package and analyzing the 2 generated out_csf.bin but the only different part is what follows the&amp;nbsp;HAB_TAG_SIG 0xD8 which from my understanding is the signature itself. Am I doing something wrong here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Aug 2020 08:10:22 GMT</pubDate>
    <dc:creator>paride_russo</dc:creator>
    <dc:date>2020-08-19T08:10:22Z</dc:date>
    <item>
      <title>cst different hashes from same input binary</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046091#M154065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, can someone help me in understanding why cst is generating 2 different hashes for the same input binary?&lt;/P&gt;&lt;P&gt;I'm using this input csf:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Header]&lt;BR /&gt; Version = 4.2&lt;BR /&gt; Engine = DCP&lt;BR /&gt; Engine Configuration = 0&lt;BR /&gt; Certificate Format = x509&lt;BR /&gt; Signature Format = CMS&lt;BR /&gt; Hash Algorithm = sha256&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;BR /&gt; File = "keys/SRK_1_2_3_4_table.bin"&lt;BR /&gt; Source Index = 0&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;BR /&gt; File = "crts/CSF1_1_sha256_2048_65537_v3_usr_crt.pem"&lt;BR /&gt; Certificate Format = x509&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;[Install Key]&lt;BR /&gt; File = "crts/IMG1_1_sha256_2048_65537_v3_usr_crt.pem"&lt;BR /&gt; Verification Index = 0&lt;BR /&gt; Target Index = 2&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt; Verification Index = 2&lt;BR /&gt; Engine = DCP&lt;BR /&gt; Engine Configuration = 0&lt;BR /&gt; Blocks = 0x60001000 0x1000 0x40 "test.bin",\&lt;BR /&gt; 0x60002000 0x2000 0x40090 "test.bin"&lt;/P&gt;&lt;P&gt;[Set Engine]&lt;BR /&gt; Hash Algorithm = sha256&lt;BR /&gt; Engine = DCP&lt;BR /&gt; Engine Configuration = 0&lt;/P&gt;&lt;P&gt;[Unlock]&lt;BR /&gt; Engine = SNVS&lt;BR /&gt; Features = ZMK WRITE&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;with this command line invocation:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;cst.exe -o out_csf.bin -i input.csf&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;the result from cst seems ok:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;CSF Processed successfully and signed data available in out_csf.bin&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;But if I&amp;nbsp;execute this process twice, the content of&amp;nbsp;&amp;nbsp;out_csf.bin is different.&lt;/P&gt;&lt;P&gt;I tried to debug this thing by using the program&amp;nbsp;hab_csf_parser part of the cst package and analyzing the 2 generated out_csf.bin but the only different part is what follows the&amp;nbsp;HAB_TAG_SIG 0xD8 which from my understanding is the signature itself. Am I doing something wrong here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Aug 2020 08:10:22 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046091#M154065</guid>
      <dc:creator>paride_russo</dc:creator>
      <dc:date>2020-08-19T08:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: cst different hashes from same input binary</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046092#M154066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/paride.russo@orbotech.com"&gt;paride.russo@orbotech.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Please use the following resources for i.MX RT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&lt;/P&gt;&lt;P&gt;"&lt;A href="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated" style="box-sizing: border-box; background-color: #ffffff; color: #215bd6; text-decoration: underline; cursor: pointer; outline: -webkit-focus-ring-color auto 5px; outline-offset: -2px; font-family: Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;" target="_blank"&gt;&lt;SPAN style="box-sizing: border-box; font-weight: bold;"&gt;&lt;STRONG&gt;Security Application Note AN12079&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated" title="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated"&gt;https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.nxp.com/docs/DOC-340904"&gt;i.MX RT Secure Boot Lab Guide.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.nxp.com/design/software/development-software/mcuxpresso-software-and-tools-/mcuxpresso-secure-provisioning-tool:MCUXPRESSO-SECURE-PROVISIONING" title="https://www.nxp.com/design/software/development-software/mcuxpresso-software-and-tools-/mcuxpresso-secure-provisioning-tool:MCUXPRESSO-SECURE-PROVISIONING"&gt;MCUXpresso Secure Provisioning Tool | Software Development for NXP Microcontrollers (MCUs) | NXP | NXP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2020 05:44:45 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046092#M154066</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-08-24T05:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: cst different hashes from same input binary</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046093#M154067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've already&amp;nbsp;read that documents but I need to drive "the low level" of the code signing tool because I'm bypassing elftosb and the flashloader; I'm loading the fw signed and encrypted via ethernet via a custom bootloader and some custom hardware that I did. It is working though, I&amp;nbsp;generated multiple times the binary signed with cst&amp;nbsp;and the i.mx is&amp;nbsp;starting every time in closed mode so the signature makes sense and is valid. I just don't understand why the signature keeps changing value every time I generated even if the source binary is always the same. I was expecting the signature to be the same...are you including some random/time number/info in the signature?&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2020 06:31:44 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046093#M154067</guid>
      <dc:creator>paride_russo</dc:creator>
      <dc:date>2020-08-24T06:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: cst different hashes from same input binary</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046094#M154068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jx-jive-macro-user" href="https://community.nxp.com/people/paride.russo@orbotech.com"&gt;paride.russo@orbotech.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; It is expected behavior - that the signature is changed.&lt;/P&gt;&lt;P&gt;Details of signature data are not provided - sorry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2020 11:09:47 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/cst-different-hashes-from-same-input-binary/m-p/1046094#M154068</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-08-24T11:09:47Z</dc:date>
    </item>
  </channel>
</rss>

