<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: Boot validation fails for MX6Q</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1392335#M185077</link>
    <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/1941"&gt;@Yuri&lt;/a&gt;&amp;nbsp;I added more details on the message above. Yes we do have the IVT. Please, let me know if you need more info.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Dec 2021 19:03:55 GMT</pubDate>
    <dc:creator>manra2021</dc:creator>
    <dc:date>2021-12-27T19:03:55Z</dc:date>
    <item>
      <title>Boot validation fails for MX6Q</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1391226#M184931</link>
      <description>&lt;P&gt;We are trying to implement the chain of trust using the HAB support for IMX6Q.&lt;/P&gt;&lt;P&gt;So far we followed the same instructions provided on this site&amp;nbsp;&lt;A href="https://boundarydevices.com/high-assurance-boot-hab-dummies/" target="_blank" rel="noopener"&gt;https://boundarydevices.com/high-assurance-boot-hab-dummies/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The generation of fuses, the keys, signing, etc works just fine.. there is no error reported.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are also considering that the following command:&lt;/P&gt;&lt;PRE&gt;hexdump -e '/4 "0x"' -e '/4 "%X""n"' &amp;lt; SRK_1_2_3_4_fuse.bin&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;Works for IMX6Q.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The problem: U-Boot signatures are OK, HAB reports no errors upon U-Boot entry.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;U-Boot then loads the signed boot script from flash. Signature validation fails. These errors are displayed: (copy from a previous comment):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;db 00 14 41&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;33 28 33 00 FAILURE, INV_CALL, CTX_TARGET&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;00 01 00 00&lt;BR /&gt;00 30 80 17&lt;BR /&gt;f0 00 00 00&lt;/P&gt;&lt;P&gt;db 00 24 41&lt;BR /&gt;33 30 ee 1d FAILURE, ENG_FAIL, CTX_EXIT, ENG_CAAM&lt;BR /&gt;00 04 00 02&lt;BR /&gt;00 00 00 00&lt;BR /&gt;55 55 00 03&lt;BR /&gt;00 00 00 00&lt;BR /&gt;00 00 00 00&lt;BR /&gt;00 00 00 00&lt;BR /&gt;00 00 00 06&lt;/P&gt;&lt;P&gt;Why ? What we are doing wrong ? We are using a board called Trizeps VII from K&amp;amp;K with IMX6Q (&lt;A href="https://www.keith-koep.com/en/products/som-system-on-module/trizeps-product-family/trizeps-vii" target="_blank" rel="noopener"&gt;https://www.keith-koep.com/en/products/som-system-on-module/trizeps-product-family/trizeps-vii&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 08:35:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1391226#M184931</guid>
      <dc:creator>manra2021</dc:creator>
      <dc:date>2021-12-23T08:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Boot validation fails for MX6Q</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1391632#M184967</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/195065"&gt;@manra2021&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; how the signed boot script is prepared? Has it IVT?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 03:16:10 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1391632#M184967</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2021-12-24T03:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Boot validation fails for MX6Q</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1391972#M185023</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/1941"&gt;@Yuri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More technical details about the problem: (could be sent to external parties to ask for help):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;CSF example is attached. (engine = SW, blocks = IVT (0x20) + image (0x4))&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;High-level system overview:&lt;BR /&gt;Plugin enabled. Plugin load addr = 0x907000. Plugin size (padded, with CSF) = 0x3000.&lt;BR /&gt;U-boot body load addr = 0x17800000.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The problem: U-Boot signatures are OK, HAB reports no errors upon U-Boot entry.&lt;BR /&gt;U-Boot then loads the signed boot script from flash. Signature validation fails. These errors are displayed: (copy from a previous comment):&lt;BR /&gt;db 00 14 41&lt;BR /&gt;33 28 33 00 FAILURE, INV_CALL, CTX_TARGET&lt;BR /&gt;00 01 00 00&lt;BR /&gt;00 30 80 17&lt;BR /&gt;f0 00 00 00&lt;/P&gt;&lt;P&gt;db 00 24 41&lt;BR /&gt;33 30 ee 1d FAILURE, ENG_FAIL, CTX_EXIT, ENG_CAAM&lt;BR /&gt;00 04 00 02&lt;BR /&gt;00 00 00 00&lt;BR /&gt;55 55 00 03&lt;BR /&gt;00 00 00 00&lt;BR /&gt;00 00 00 00&lt;BR /&gt;00 00 00 00&lt;BR /&gt;00 00 00 06&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The following experiments (below) do not affect the secure boot substantially: they do NOT break the Plugin + U-Boot body signature validation (it’s OK in all cases), but do NOT fix the boot script signature validation.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When I choose CSF engine = SW, the 1st error is shorter, and it’s longer for engine = CAAM:&lt;BR /&gt;- SW engine:&lt;BR /&gt;db 00 14 41&lt;BR /&gt;33 28 33 00 FAILURE, INV_CALL, CTX_TARGET&lt;BR /&gt;00 01 00 00&lt;BR /&gt;00 30 80 17&lt;BR /&gt;f0 00 00 00&lt;BR /&gt;- CAAM engine:&lt;BR /&gt;db 00 24 41&lt;BR /&gt;33 28 c0 00 FAILURE, INV_CALL, CTX_COMMAND&lt;BR /&gt;ca 00 1c 00 // these bytes match the U-Boot body’s CSF binary file. (last binary validated by HAB).&lt;BR /&gt;02 c5 1d 00&lt;BR /&gt;00 00 16 44&lt;BR /&gt;17 80 04 00&lt;BR /&gt;00 00 00 60&lt;BR /&gt;17 80 2c a0&lt;BR /&gt;00 07 c5 d4&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When I add another hab_rvt_exit() call just before the hab_rvt_entry() in the authenticate_image(), I get a new error before the 2 errors I got previously:&lt;BR /&gt;db 00 08 41&lt;BR /&gt;33 28 ee 00 FAILURE, INV_CALL, CTX_EXIT&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When I change the U-Boot Body’s CSF file (adjust Blocks section to only validate 4 bytes), the error matches the change:&lt;BR /&gt;db 00 24 41&lt;BR /&gt;33 28 c0 00 FAILURE, INV_CALL, CTX_COMMAND&lt;BR /&gt;ca 00 1c 00&lt;BR /&gt;02 c5 1d 00&lt;BR /&gt;00 00 16 44&lt;BR /&gt;17 80 04 00&lt;BR /&gt;00 00 00 60&lt;BR /&gt;17 80 2c a0&lt;BR /&gt;00 00 00 04&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When I Unlock RNG / MID in CSF file, the errors do not change.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When I put a “return” in the authenticate_image() just after the hab_rvt_entry(), the 2nd error disappears (as expected), meaning that the 1st error is logged in hab_rvt_entry(), and the 2nd is in hab_rvt_authenticate_image().&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;I’ve disabled the CONFIG_FSL_CAAM in U-Boot, the errors are still there.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the above observations, it looks like the HAB library didn’t finish validating the previous image. But it returned successfully. Thus, it’s not possible to validate any subsequent image using HAB.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 27 Dec 2021 00:09:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1391972#M185023</guid>
      <dc:creator>manra2021</dc:creator>
      <dc:date>2021-12-27T00:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Boot validation fails for MX6Q</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1392335#M185077</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/1941"&gt;@Yuri&lt;/a&gt;&amp;nbsp;I added more details on the message above. Yes we do have the IVT. Please, let me know if you need more info.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 19:03:55 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Boot-validation-fails-for-MX6Q/m-p/1392335#M185077</guid>
      <dc:creator>manra2021</dc:creator>
      <dc:date>2021-12-27T19:03:55Z</dc:date>
    </item>
  </channel>
</rss>

