<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SRK HASH write once feature in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/SRK-HASH-write-once-feature/m-p/1452543#M189963</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have Sabre I MX Solox Eval board. I am trying signed HABV4 boot. A want to ask a quick confirmation question may be obvious for many.&lt;/P&gt;&lt;P&gt;Think about you have one board and you are making trials on signed boot.&lt;/P&gt;&lt;P&gt;If the SRK_1_2_3_4_table.bin&amp;nbsp; is installed in CSF with "INSTALL SRK" command;&amp;nbsp; it is irreversible so the public key hashes written to those locations can not be changed.&amp;nbsp; That makes the very first trial is binding the board to set of private keys to sign images in later trials right?&amp;nbsp; So ; the user of the board needs to protect those private keys in order to be able to use the board later for signed boot.&lt;/P&gt;&lt;P&gt;As I understand blowing the SRK_LOCK fuse is just to protect what is written to those locations.&lt;/P&gt;&lt;P&gt;If this is the case (that I understand from the documents it is) , and the evaluation boards are sometimes hard to obtain, the people who may jump on to do a first trial very quick say using 2048 bit key and then decide to use 4096 bit key may have to look for a another board?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for answering/confirming (possibly trivial question) &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/61445"&gt;@nxp&lt;/a&gt; Tech support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2022 06:45:04 GMT</pubDate>
    <dc:creator>sfutaci</dc:creator>
    <dc:date>2022-05-04T06:45:04Z</dc:date>
    <item>
      <title>SRK HASH write once feature</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/SRK-HASH-write-once-feature/m-p/1452543#M189963</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have Sabre I MX Solox Eval board. I am trying signed HABV4 boot. A want to ask a quick confirmation question may be obvious for many.&lt;/P&gt;&lt;P&gt;Think about you have one board and you are making trials on signed boot.&lt;/P&gt;&lt;P&gt;If the SRK_1_2_3_4_table.bin&amp;nbsp; is installed in CSF with "INSTALL SRK" command;&amp;nbsp; it is irreversible so the public key hashes written to those locations can not be changed.&amp;nbsp; That makes the very first trial is binding the board to set of private keys to sign images in later trials right?&amp;nbsp; So ; the user of the board needs to protect those private keys in order to be able to use the board later for signed boot.&lt;/P&gt;&lt;P&gt;As I understand blowing the SRK_LOCK fuse is just to protect what is written to those locations.&lt;/P&gt;&lt;P&gt;If this is the case (that I understand from the documents it is) , and the evaluation boards are sometimes hard to obtain, the people who may jump on to do a first trial very quick say using 2048 bit key and then decide to use 4096 bit key may have to look for a another board?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for answering/confirming (possibly trivial question) &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/61445"&gt;@nxp&lt;/a&gt; Tech support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 06:45:04 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/SRK-HASH-write-once-feature/m-p/1452543#M189963</guid>
      <dc:creator>sfutaci</dc:creator>
      <dc:date>2022-05-04T06:45:04Z</dc:date>
    </item>
  </channel>
</rss>

