<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iMX6 ull encrypted boot in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227420#M169058</link>
    <description>&lt;P&gt;Hi CarlosFG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unfortunately i.MX6ULL does not support &lt;SPAN style="color: #333f48; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;encrypted boot&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;/P&gt;</description>
    <pubDate>Sat, 06 Feb 2021 11:59:55 GMT</pubDate>
    <dc:creator>igorpadykov</dc:creator>
    <dc:date>2021-02-06T11:59:55Z</dc:date>
    <item>
      <title>iMX6 ull encrypted boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227000#M169003</link>
      <description>&lt;P&gt;I'm trying to enable encrypted boot in iMX6 ULL EVK. According to IMX6ULLRM and IMX6ULLSRM this should be possible. One of the steps to get encrypted boot work is generate a "dek blob" [1][2] inside the processor. In order to do that, there is a u-boot command named "dek_blob" that uses the CAAM [1][3][4]. I couldn't get his command work, It fails at &lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/drivers/crypto/fsl/jobdesc.c?h=imx_v2020.04_5.4.24_2.1.0#n105" target="_self"&gt;this point&lt;/A&gt;&amp;nbsp;in a function named caam_page_alloc() which is always called with the same parameters: caam_page_alloc(1, 1), this means it fails regardless of how I use the dek_blob command. I also tried to use the CAAM Linux drivers unsuccessfully. Later I found in a couple of sites the CAAM is not available in iMX6ULL [5][6]&lt;/P&gt;&lt;P&gt;So my question is ¿How can I encapsulate a DEK and obtain a dek blob in the iMX6ULL?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Code-signing Tool User's Guide&lt;/LI&gt;&lt;LI&gt;AN12056&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4/introduction_habv4.txt?h=imx_v2020.04_5.4.24_2.1.0" target="_self"&gt;U-boot introduction to HABv4&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4/guides/encrypted_boot.txt?h=imx_v2020.04_5.4.24_2.1.0" target="_self"&gt;U-boot encrypted boot&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.nxp.com/t5/i-MX-Processors/Signed-and-encrypted-boot-in-i-MX6UL/m-p/466447/highlight/true#M73521" target="_self"&gt;https://community.nxp.com/t5/i-MX-Processors/Signed-and-encrypted-boot-in-i-MX6UL/m-p/466447/highlight/true#M73521&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://patchwork.kernel.org/project/linux-arm-kernel/patch/1523739330-27363-1-git-send-email-festevam@gmail.com/" target="_self"&gt;https://patchwork.kernel.org/project/linux-arm-kernel/patch/1523739330-27363-1-git-send-email-festevam@gmail.com/&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:12:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227000#M169003</guid>
      <dc:creator>CarlosFG</dc:creator>
      <dc:date>2021-02-05T09:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: iMX6 ull encrypted boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227420#M169058</link>
      <description>&lt;P&gt;Hi CarlosFG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unfortunately i.MX6ULL does not support &lt;SPAN style="color: #333f48; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;encrypted boot&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 11:59:55 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227420#M169058</guid>
      <dc:creator>igorpadykov</dc:creator>
      <dc:date>2021-02-06T11:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: iMX6 ull encrypted boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227781#M169119</link>
      <description>&lt;P&gt;Thanks you very much igorpadykov.&lt;/P&gt;&lt;P&gt;The Applications Processor Reference Manual for this device (IMX6ULLRM) says the encrypted boot is supported. I humbly suggest to amend it in order to avoid other engineers waste their time trying to make it work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CarlosFG_0-1612770985948.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/136735i5D2D2039A08457E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CarlosFG_0-1612770985948.png" alt="CarlosFG_0-1612770985948.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 08:02:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1227781#M169119</guid>
      <dc:creator>CarlosFG</dc:creator>
      <dc:date>2021-02-08T08:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: iMX6 ull encrypted boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1228482#M169198</link>
      <description>&lt;DIV class="lia-message-body-accepted-solution-checkmark"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Hi CarlosFG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in theory it can be supported, but in practice NXP software implementation currently&lt;/P&gt;
&lt;P&gt;supports only CAAM based options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 04:52:38 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1228482#M169198</guid>
      <dc:creator>igorpadykov</dc:creator>
      <dc:date>2021-02-09T04:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: iMX6 ull encrypted boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1609304#M202311</link>
      <description>&lt;P&gt;Is there any update on this matter?&lt;/P&gt;&lt;P&gt;You wrote that there is currently only the CAAM based implementation.&lt;BR /&gt;&lt;BR /&gt;I hope there's a way to implement encrypted boot using the various keys. Unfortunately, I don't have access to the SRM.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 15:31:10 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/iMX6-ull-encrypted-boot/m-p/1609304#M202311</guid>
      <dc:creator>mprt</dc:creator>
      <dc:date>2023-03-03T15:31:10Z</dc:date>
    </item>
  </channel>
</rss>

