<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HAB PKI in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1186233#M165232</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a question about the PKI used for the HAB authentication. The CST comes with a script which generates the full PKI: CA -&amp;gt; SRK -&amp;gt; IMG/CSF. The self-signed CA sign the SRK, which in turn sign the IMG/CSF - everything clear.&lt;/P&gt;&lt;P&gt;However, we are fusing the SRK onto the board. Thus, my question: Why do we need the CA ie. why arent the SRK self-signed?&lt;/P&gt;&lt;P&gt;Thanks, cheers,&lt;/P&gt;&lt;P&gt;Aleksandar&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2020 20:58:34 GMT</pubDate>
    <dc:creator>aleksandar_niko</dc:creator>
    <dc:date>2020-11-19T20:58:34Z</dc:date>
    <item>
      <title>HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1186233#M165232</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a question about the PKI used for the HAB authentication. The CST comes with a script which generates the full PKI: CA -&amp;gt; SRK -&amp;gt; IMG/CSF. The self-signed CA sign the SRK, which in turn sign the IMG/CSF - everything clear.&lt;/P&gt;&lt;P&gt;However, we are fusing the SRK onto the board. Thus, my question: Why do we need the CA ie. why arent the SRK self-signed?&lt;/P&gt;&lt;P&gt;Thanks, cheers,&lt;/P&gt;&lt;P&gt;Aleksandar&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 20:58:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1186233#M165232</guid>
      <dc:creator>aleksandar_niko</dc:creator>
      <dc:date>2020-11-19T20:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1186399#M165254</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/153013"&gt;@aleksandar_niko&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; The issue has been already discussed in &lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.nxp.com/t5/i-MX-Processors/Confused-about-SRK/m-p/1184334#M164997" target="_blank"&gt;https://community.nxp.com/t5/i-MX-Processors/Confused-about-SRK/m-p/1184334&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 04:08:36 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1186399#M165254</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-11-20T04:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1190848#M165708</link>
      <description>&lt;P&gt;Hello Yuri,&lt;/P&gt;&lt;P&gt;some things are still unclear for me. Let me ask this way. I modified the script that creates the hab4 PKI in a way that I use &lt;STRONG&gt;my own SRK&lt;/STRONG&gt; keys/crts, but the CA and the CST/IMG keys &lt;STRONG&gt;are generated by the script every time&lt;/STRONG&gt;. The SRK hashes that are supposed to be fused on the board remained the &lt;STRONG&gt;same&lt;/STRONG&gt;. Does this make sense?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 10:00:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1190848#M165708</guid>
      <dc:creator>aleksandar_niko</dc:creator>
      <dc:date>2020-11-30T10:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191249#M165746</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/153013"&gt;@aleksandar_niko&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; SRK is used to check CST/IMG keys. It is possible to revoke one SRK in order to use&amp;nbsp;&lt;BR /&gt;another.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 03:56:20 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191249#M165746</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-12-01T03:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191399#M165759</link>
      <description>&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;I dont think you understand me, it has nothing to do with the target. If I use my own SRK keys every time I create the PKI (basically I create the CA and the IMG/CST keys, but the SRK always remain the same), is such PKI valid?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 08:07:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191399#M165759</guid>
      <dc:creator>aleksandar_niko</dc:creator>
      <dc:date>2020-12-01T08:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191406#M165760</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; ...&amp;nbsp;&lt;SPAN&gt;create the CA and the IMG/CST keys, but the SRK always remain the same), is such PKI valid?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Yes - why not?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 08:16:41 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191406#M165760</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-12-01T08:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191410#M165761</link>
      <description>&lt;P&gt;Would in that case the HAB authentication work? (The SRK hashes remain the same).&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 08:20:07 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191410#M165761</guid>
      <dc:creator>aleksandar_niko</dc:creator>
      <dc:date>2020-12-01T08:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191441#M165765</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/153013"&gt;@aleksandar_niko&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; if I correctly understand the problem - the SRK (once burned) must not be changed.&lt;/P&gt;
&lt;P&gt;~Yuri.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 08:51:33 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191441#M165765</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-12-01T08:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191539#M165771</link>
      <description>&lt;P&gt;Heres a bit longer explanation so we would be on the same page.&lt;/P&gt;&lt;P&gt;Step1:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We generate the whole PKI (CA, SRK, IMG/CST)&lt;/LI&gt;&lt;LI&gt;SRKs are burned (cannot be changed anymore)&lt;/LI&gt;&lt;LI&gt;HAB authentication works&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Step2:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We generate a new PKI, but with SRK keys from the previous step. This means CA and IMG/CST keys are generated, but SRK are just integrated into the PKI&lt;/LI&gt;&lt;LI&gt;This means&lt;UL&gt;&lt;LI&gt;SRK are the same as in Step1 but are signed by different CA&lt;/LI&gt;&lt;LI&gt;IMG/CST keys are different than in Step1 but are signed by the same SRK&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is the PKI from the Step2 valid and could you tell whether the authentication would work?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 10:31:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191539#M165771</guid>
      <dc:creator>aleksandar_niko</dc:creator>
      <dc:date>2020-12-01T10:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: HAB PKI</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191587#M165774</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/153013"&gt;@aleksandar_niko&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; CA is not involved in target verifications;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;the PKI from the Step2 is valid and&amp;nbsp; the authentication will work.&lt;BR /&gt;SRK hash is checked.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;~Yuri.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 11:31:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/HAB-PKI/m-p/1191587#M165774</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-12-01T11:31:34Z</dc:date>
    </item>
  </channel>
</rss>

