<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AHAB: validating signed OS container in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/AHAB-validating-signed-OS-container/m-p/1339635#M180037</link>
    <description>&lt;P&gt;Hi Oliver&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;answer from team:&lt;/P&gt;
&lt;P&gt;---------------------&lt;/P&gt;
&lt;P&gt;If your test chip is not closed, then even the os container authentication failed, it won't effect the kernal boot.&lt;/P&gt;
&lt;P&gt;For os container, you can authenticate it by "auth_cntr addr" command in uboot.&lt;/P&gt;
&lt;P&gt;Then after run the command, you can use ahab_status to see if there are increasing ahab events, which is caused by authenticating os container, then you can know if the os container is signed correctly or not.&lt;/P&gt;
&lt;P&gt;---------------------&lt;/P&gt;
&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 07:47:30 GMT</pubDate>
    <dc:creator>igorpadykov</dc:creator>
    <dc:date>2021-09-14T07:47:30Z</dc:date>
    <item>
      <title>AHAB: validating signed OS container</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/AHAB-validating-signed-OS-container/m-p/1333220#M179445</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I've managed successfully to create signed container files that will boot (mostly following &lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt" target="_blank"&gt;https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt &lt;/A&gt;and &lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_spl_secure_boot.txt" target="_blank"&gt;https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_spl_secure_boot.txt&lt;/A&gt;) without any SECO events after programming the fuses.&lt;/P&gt;&lt;P&gt;However, when I boot the signed Linux container, it will boot even if I have signed it with the wrong keys. I haven't yet closed the device, but I would have expected some sort of warning or the like anyway. Is there any way to check whether the authentication of the kernel container was successful or not without closing the device?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 11:19:20 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/AHAB-validating-signed-OS-container/m-p/1333220#M179445</guid>
      <dc:creator>OlegHahm</dc:creator>
      <dc:date>2021-09-01T11:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: AHAB: validating signed OS container</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/AHAB-validating-signed-OS-container/m-p/1339635#M180037</link>
      <description>&lt;P&gt;Hi Oliver&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;answer from team:&lt;/P&gt;
&lt;P&gt;---------------------&lt;/P&gt;
&lt;P&gt;If your test chip is not closed, then even the os container authentication failed, it won't effect the kernal boot.&lt;/P&gt;
&lt;P&gt;For os container, you can authenticate it by "auth_cntr addr" command in uboot.&lt;/P&gt;
&lt;P&gt;Then after run the command, you can use ahab_status to see if there are increasing ahab events, which is caused by authenticating os container, then you can know if the os container is signed correctly or not.&lt;/P&gt;
&lt;P&gt;---------------------&lt;/P&gt;
&lt;P&gt;Best regards&lt;BR /&gt;igor&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 07:47:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/AHAB-validating-signed-OS-container/m-p/1339635#M180037</guid>
      <dc:creator>igorpadykov</dc:creator>
      <dc:date>2021-09-14T07:47:30Z</dc:date>
    </item>
  </channel>
</rss>

