<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processorsのトピックi.MX6UL NAND Secure Boot</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/i-MX6UL-NAND-Secure-Boot/m-p/1568888#M198676</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I was trying to develop secure boot on i.MX6UltraLite custom board with NAND boot device.&lt;/P&gt;&lt;P&gt;Prior to enabling secure boot support in i.MX6UltraLite custom board, I have performed a secure boot on the i.MX6UL EVK using HABv4.&lt;/P&gt;&lt;P&gt;i.MX6UL EVK can boot up from SD card and get no HAB events found using hab_status command.&lt;/P&gt;&lt;P&gt;The signed Linux Kernel image is also successfully executed without generating any HAB events.&lt;/P&gt;&lt;P&gt;I perform the same steps on i.MX6UltraLite custom board.&lt;/P&gt;&lt;P&gt;However, it's failed to boot up from NAND after I burn signed U-Boot image into NAND using UUU.&lt;/P&gt;&lt;P&gt;I am also unable to verify&amp;nbsp;&lt;SPAN&gt;HAB events with&amp;nbsp;hab_status command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I try to run UUU using "uuu.exe -v ./uuu_nand.auto" command again.&lt;/P&gt;&lt;P&gt;UUU appears to hang with&amp;nbsp;"Wait for Known Device Appear..." message.&lt;/P&gt;&lt;P&gt;i.MX6UltraLite custom board is connected to the computer with micro USB cable.&lt;/P&gt;&lt;P&gt;But it can't detect the device and always hang with "Wait for Known Device Appear..." message.&lt;/P&gt;&lt;P&gt;After that, I can't burn any U-Boot into NAND using UUU anymore.&lt;/P&gt;&lt;P&gt;Is there any way to flash U-Boot image again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BootROM should boot U-Boot image even if it has no valid signature before the device is closed as mentioned in documents related to secure boot.&lt;/P&gt;&lt;P&gt;I didn't blow fuse to close the device.&lt;/P&gt;&lt;P&gt;Both of EVK and custom board are in open state.&lt;/P&gt;&lt;P&gt;Whether I burn a signed U-Boot image with a correct signature or a wrong signature into i.MX6UL EVK, BootROM always allows U-Boot to boot up from SD card.&lt;/P&gt;&lt;P&gt;But i.MX6UltraLite custom board can't boot up once I enable secure boot features.&lt;/P&gt;&lt;P&gt;Why&amp;nbsp;i.MX6UltraLite custom board and&amp;nbsp;i.MX6UL EVK have different result?&lt;/P&gt;&lt;P&gt;Does i.MX6UltraLite custom board booting from NAND require some additional configuration?&lt;/P&gt;&lt;P&gt;I have followed the below steps to enable the secure boot features of the i.MX6UltraLite custom board.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Followed CST user guide to generate PKIs tree, SRK tables using cst-3.3.1.&lt;/LI&gt;&lt;LI&gt;Add "CONFIG_SECURE_BOOT=y" in mx6ul_14x14_evk_nand_defconfig and build it.&lt;/LI&gt;&lt;LI&gt;Create the CSF description file and generate the CSF binary file using CST tool.&lt;/LI&gt;&lt;LI&gt;Append CSF signature to the end of U-Boot image.&lt;/LI&gt;&lt;LI&gt;program SRK Hash fuse values in the SRK_HASH[255:0] fuses using U-Boot fuse tool.&lt;/LI&gt;&lt;LI&gt;Flash signed U-Boot image into NAND flash using UUU.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The difference between i.MX6UltraLite custom board and i.MX6UL EVK are as follows.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;i.MX6UltraLite custom board&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;i.MX6UL EVK&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;Boot Device&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;NAND&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;SD&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="47px" class="lia-align-center"&gt;Build Environment&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="47px" class="lia-align-center"&gt;build U-Boot in Yocto Project&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="47px" class="lia-align-center"&gt;build U-Boot in standalone environment&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="25px" class="lia-align-center"&gt;The file where &lt;SPAN&gt;CONFIG_SECURE_BOOT&lt;/SPAN&gt;&amp;nbsp;is added&lt;/TD&gt;&lt;TD height="25px" class="lia-align-center"&gt;mx6ul_14x14_evk_nand_defconfig&lt;/TD&gt;&lt;TD height="25px" class="lia-align-center"&gt;mx6ul_14x14_evk_defconfig&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="77px" class="lia-align-center"&gt;&lt;P&gt;Value of OTP Bank0 Word6&lt;/P&gt;&lt;P&gt;(OCOTP_CFG5)&lt;/P&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="77px" class="lia-align-center"&gt;0x00080040&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="77px" class="lia-align-center"&gt;0x00000000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Please check the attachments for details.&lt;/P&gt;&lt;P&gt;What I missed in the above procedure?&lt;/P&gt;&lt;P&gt;It's appreciated if you could give me some suggestions to resolve this issue.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Dec 2022 08:48:37 GMT</pubDate>
    <dc:creator>TammyTsai</dc:creator>
    <dc:date>2022-12-13T08:48:37Z</dc:date>
    <item>
      <title>i.MX6UL NAND Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX6UL-NAND-Secure-Boot/m-p/1568888#M198676</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I was trying to develop secure boot on i.MX6UltraLite custom board with NAND boot device.&lt;/P&gt;&lt;P&gt;Prior to enabling secure boot support in i.MX6UltraLite custom board, I have performed a secure boot on the i.MX6UL EVK using HABv4.&lt;/P&gt;&lt;P&gt;i.MX6UL EVK can boot up from SD card and get no HAB events found using hab_status command.&lt;/P&gt;&lt;P&gt;The signed Linux Kernel image is also successfully executed without generating any HAB events.&lt;/P&gt;&lt;P&gt;I perform the same steps on i.MX6UltraLite custom board.&lt;/P&gt;&lt;P&gt;However, it's failed to boot up from NAND after I burn signed U-Boot image into NAND using UUU.&lt;/P&gt;&lt;P&gt;I am also unable to verify&amp;nbsp;&lt;SPAN&gt;HAB events with&amp;nbsp;hab_status command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I try to run UUU using "uuu.exe -v ./uuu_nand.auto" command again.&lt;/P&gt;&lt;P&gt;UUU appears to hang with&amp;nbsp;"Wait for Known Device Appear..." message.&lt;/P&gt;&lt;P&gt;i.MX6UltraLite custom board is connected to the computer with micro USB cable.&lt;/P&gt;&lt;P&gt;But it can't detect the device and always hang with "Wait for Known Device Appear..." message.&lt;/P&gt;&lt;P&gt;After that, I can't burn any U-Boot into NAND using UUU anymore.&lt;/P&gt;&lt;P&gt;Is there any way to flash U-Boot image again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BootROM should boot U-Boot image even if it has no valid signature before the device is closed as mentioned in documents related to secure boot.&lt;/P&gt;&lt;P&gt;I didn't blow fuse to close the device.&lt;/P&gt;&lt;P&gt;Both of EVK and custom board are in open state.&lt;/P&gt;&lt;P&gt;Whether I burn a signed U-Boot image with a correct signature or a wrong signature into i.MX6UL EVK, BootROM always allows U-Boot to boot up from SD card.&lt;/P&gt;&lt;P&gt;But i.MX6UltraLite custom board can't boot up once I enable secure boot features.&lt;/P&gt;&lt;P&gt;Why&amp;nbsp;i.MX6UltraLite custom board and&amp;nbsp;i.MX6UL EVK have different result?&lt;/P&gt;&lt;P&gt;Does i.MX6UltraLite custom board booting from NAND require some additional configuration?&lt;/P&gt;&lt;P&gt;I have followed the below steps to enable the secure boot features of the i.MX6UltraLite custom board.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Followed CST user guide to generate PKIs tree, SRK tables using cst-3.3.1.&lt;/LI&gt;&lt;LI&gt;Add "CONFIG_SECURE_BOOT=y" in mx6ul_14x14_evk_nand_defconfig and build it.&lt;/LI&gt;&lt;LI&gt;Create the CSF description file and generate the CSF binary file using CST tool.&lt;/LI&gt;&lt;LI&gt;Append CSF signature to the end of U-Boot image.&lt;/LI&gt;&lt;LI&gt;program SRK Hash fuse values in the SRK_HASH[255:0] fuses using U-Boot fuse tool.&lt;/LI&gt;&lt;LI&gt;Flash signed U-Boot image into NAND flash using UUU.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The difference between i.MX6UltraLite custom board and i.MX6UL EVK are as follows.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;i.MX6UltraLite custom board&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;i.MX6UL EVK&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;Boot Device&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;NAND&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px" class="lia-align-center"&gt;SD&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="47px" class="lia-align-center"&gt;Build Environment&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="47px" class="lia-align-center"&gt;build U-Boot in Yocto Project&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="47px" class="lia-align-center"&gt;build U-Boot in standalone environment&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="25px" class="lia-align-center"&gt;The file where &lt;SPAN&gt;CONFIG_SECURE_BOOT&lt;/SPAN&gt;&amp;nbsp;is added&lt;/TD&gt;&lt;TD height="25px" class="lia-align-center"&gt;mx6ul_14x14_evk_nand_defconfig&lt;/TD&gt;&lt;TD height="25px" class="lia-align-center"&gt;mx6ul_14x14_evk_defconfig&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="77px" class="lia-align-center"&gt;&lt;P&gt;Value of OTP Bank0 Word6&lt;/P&gt;&lt;P&gt;(OCOTP_CFG5)&lt;/P&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="77px" class="lia-align-center"&gt;0x00080040&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="77px" class="lia-align-center"&gt;0x00000000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Please check the attachments for details.&lt;/P&gt;&lt;P&gt;What I missed in the above procedure?&lt;/P&gt;&lt;P&gt;It's appreciated if you could give me some suggestions to resolve this issue.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 08:48:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX6UL-NAND-Secure-Boot/m-p/1568888#M198676</guid>
      <dc:creator>TammyTsai</dc:creator>
      <dc:date>2022-12-13T08:48:37Z</dc:date>
    </item>
  </channel>
</rss>

