<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックInvalid IVT structure: Secure boot in imx6</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Invalid-IVT-structure-Secure-boot-in-imx6/m-p/1618489#M202981</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to sign the u-boot and kernel image and dtb file together using the csf file.&lt;/P&gt;&lt;P&gt;So u-boot signing is done and working except getting one warning . but on kernel signing i am getting error like below.&lt;/P&gt;&lt;P&gt;&amp;gt; hab_auth_img 0x12000000 0x933348&lt;BR /&gt;hab fuse not enabled&lt;/P&gt;&lt;P&gt;Authenticate image from DDR location 0x12000000...&lt;BR /&gt;bad magic magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad length magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad version magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;Error: Invalid IVT structure&lt;/P&gt;&lt;P&gt;Allowed IVT structure:&lt;BR /&gt;IVT HDR = 0x4X2000D1&lt;BR /&gt;IVT ENTRY = 0xXXXXXXXX&lt;BR /&gt;IVT RSV1 = 0x0&lt;BR /&gt;IVT DCD = 0x0&lt;BR /&gt;IVT BOOT_DATA = 0xXXXXXXXX&lt;BR /&gt;IVT SELF = 0xXXXXXXXX&lt;BR /&gt;IVT CSF = 0xXXXXXXXX&lt;BR /&gt;IVT RSV2 = 0x0&lt;BR /&gt;MX6 HORIZON U-Boot &amp;gt;&lt;/P&gt;&lt;P&gt;Here my kernel vmlinuz size is&amp;nbsp;&lt;/P&gt;&lt;P&gt;hexdump -C vmlinuz-5.10.158-cip22+mel2 | tail -n 1&lt;BR /&gt;00932348&amp;nbsp;&lt;/P&gt;&lt;P&gt;so i padded this to 0x1000 and made it&amp;nbsp;&lt;/P&gt;&lt;P&gt;##objcopy -I binary -O binary --pad-to 0x933348 --gap-fill=0x00 vmlinuz-5.10.158-cip22+mel2 vmlinuz_pad.bin&lt;/P&gt;&lt;P&gt;then create the ivt using genivt.pl&lt;/P&gt;&lt;P&gt;below is content of my&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;#! /usr/bin/perl -w&lt;BR /&gt;&amp;nbsp;use strict;&lt;BR /&gt;&amp;nbsp;open(my $out, '&amp;gt;:raw', 'ivt.bin') or die "Unable to open: $!";&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x412000D1); # Signature&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x12000000); # Load Address (*load_address)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # Reserved&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # DCD pointer&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # Boot Data&lt;BR /&gt;&amp;nbsp;#print $out pack("V", 0x80EEA000); # Self Pointer (*ivt)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x12933348); # Self Pointer (*ivt)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x12933368); # CSF Pointer (*csf)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # Reserved&lt;BR /&gt;&amp;nbsp;close($out);&lt;/P&gt;&lt;P&gt;Self pointer (ivt) calculate as Load address + padded_image_size(vmlinuxz)&amp;nbsp;&lt;/P&gt;&lt;P&gt;CSF Pointer calculated as Load address + padded_img_size + 0x20&lt;/P&gt;&lt;P&gt;then used below cmd&lt;/P&gt;&lt;PRE&gt;cat zImage_pad.bin ivt.bin &amp;gt; zImage_pad_ivt.bin&lt;BR /&gt;&lt;BR /&gt;below is my csf-uboot-txt Authentication data content.&lt;BR /&gt;&lt;STRONG&gt; [Authenticate Data]&lt;BR /&gt; # Key slot index used to authenticate the image data&lt;BR /&gt; Verification index = 2&lt;BR /&gt; # Authenticate Start Address, Offset, Length and file&lt;BR /&gt; # Blocks = 0x877ff400 0x00000000 0x0009ec00 "u-boot-dtb.imx"&lt;BR /&gt;&lt;BR /&gt; Blocks = 0x177ff400 0x00 0x00092c00 "u-boot-dtb.imx", \&lt;BR /&gt; 0x12000000 0x00 0x00932348 "vmlinuz_pad_ivt.bin"&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;./cst --i csf_additional_images.txt --o csf_zImage.bin&lt;/PRE&gt;&lt;PRE&gt;Attach the CSF binary to the end of the image:

  $ cat zImage_pad_ivt.bin csf_zImage.bin &amp;gt; zImage_signed.bin&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I am loading the kernel image as below.&lt;BR /&gt;U-Boot &amp;gt; load mmc 3:1 0x12000000 /boot/zImage_uboot-signed.bin&lt;BR /&gt;9650864 bytes read in 298 ms (30.9 MiB/s)&lt;BR /&gt;MX6 HORIZON U-Boot &amp;gt;&lt;/PRE&gt;&lt;P&gt;U-Boot &amp;gt; hab_auth_img 0x12000000 0x933348&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;hab fuse not enabled&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Authenticate image from DDR location 0x12000000...&lt;BR /&gt;bad magic magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad length magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad version magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;Error: Invalid IVT structure&lt;/P&gt;&lt;P&gt;Allowed IVT structure:&lt;BR /&gt;IVT HDR = 0x4X2000D1&lt;BR /&gt;IVT ENTRY = 0xXXXXXXXX&lt;BR /&gt;IVT RSV1 = 0x0&lt;BR /&gt;IVT DCD = 0x0&lt;BR /&gt;IVT BOOT_DATA = 0xXXXXXXXX&lt;BR /&gt;IVT SELF = 0xXXXXXXXX&lt;BR /&gt;IVT CSF = 0xXXXXXXXX&lt;BR /&gt;IVT RSV2 = 0x0&lt;BR /&gt;MX6 HORIZON U-Boot &amp;gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Could someone please check this issue, any input would be appreciable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Mar 2023 09:46:37 GMT</pubDate>
    <dc:creator>rakesh3</dc:creator>
    <dc:date>2023-03-21T09:46:37Z</dc:date>
    <item>
      <title>Invalid IVT structure: Secure boot in imx6</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Invalid-IVT-structure-Secure-boot-in-imx6/m-p/1618489#M202981</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to sign the u-boot and kernel image and dtb file together using the csf file.&lt;/P&gt;&lt;P&gt;So u-boot signing is done and working except getting one warning . but on kernel signing i am getting error like below.&lt;/P&gt;&lt;P&gt;&amp;gt; hab_auth_img 0x12000000 0x933348&lt;BR /&gt;hab fuse not enabled&lt;/P&gt;&lt;P&gt;Authenticate image from DDR location 0x12000000...&lt;BR /&gt;bad magic magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad length magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad version magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;Error: Invalid IVT structure&lt;/P&gt;&lt;P&gt;Allowed IVT structure:&lt;BR /&gt;IVT HDR = 0x4X2000D1&lt;BR /&gt;IVT ENTRY = 0xXXXXXXXX&lt;BR /&gt;IVT RSV1 = 0x0&lt;BR /&gt;IVT DCD = 0x0&lt;BR /&gt;IVT BOOT_DATA = 0xXXXXXXXX&lt;BR /&gt;IVT SELF = 0xXXXXXXXX&lt;BR /&gt;IVT CSF = 0xXXXXXXXX&lt;BR /&gt;IVT RSV2 = 0x0&lt;BR /&gt;MX6 HORIZON U-Boot &amp;gt;&lt;/P&gt;&lt;P&gt;Here my kernel vmlinuz size is&amp;nbsp;&lt;/P&gt;&lt;P&gt;hexdump -C vmlinuz-5.10.158-cip22+mel2 | tail -n 1&lt;BR /&gt;00932348&amp;nbsp;&lt;/P&gt;&lt;P&gt;so i padded this to 0x1000 and made it&amp;nbsp;&lt;/P&gt;&lt;P&gt;##objcopy -I binary -O binary --pad-to 0x933348 --gap-fill=0x00 vmlinuz-5.10.158-cip22+mel2 vmlinuz_pad.bin&lt;/P&gt;&lt;P&gt;then create the ivt using genivt.pl&lt;/P&gt;&lt;P&gt;below is content of my&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;#! /usr/bin/perl -w&lt;BR /&gt;&amp;nbsp;use strict;&lt;BR /&gt;&amp;nbsp;open(my $out, '&amp;gt;:raw', 'ivt.bin') or die "Unable to open: $!";&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x412000D1); # Signature&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x12000000); # Load Address (*load_address)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # Reserved&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # DCD pointer&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # Boot Data&lt;BR /&gt;&amp;nbsp;#print $out pack("V", 0x80EEA000); # Self Pointer (*ivt)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x12933348); # Self Pointer (*ivt)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x12933368); # CSF Pointer (*csf)&lt;BR /&gt;&amp;nbsp;print $out pack("V", 0x0); # Reserved&lt;BR /&gt;&amp;nbsp;close($out);&lt;/P&gt;&lt;P&gt;Self pointer (ivt) calculate as Load address + padded_image_size(vmlinuxz)&amp;nbsp;&lt;/P&gt;&lt;P&gt;CSF Pointer calculated as Load address + padded_img_size + 0x20&lt;/P&gt;&lt;P&gt;then used below cmd&lt;/P&gt;&lt;PRE&gt;cat zImage_pad.bin ivt.bin &amp;gt; zImage_pad_ivt.bin&lt;BR /&gt;&lt;BR /&gt;below is my csf-uboot-txt Authentication data content.&lt;BR /&gt;&lt;STRONG&gt; [Authenticate Data]&lt;BR /&gt; # Key slot index used to authenticate the image data&lt;BR /&gt; Verification index = 2&lt;BR /&gt; # Authenticate Start Address, Offset, Length and file&lt;BR /&gt; # Blocks = 0x877ff400 0x00000000 0x0009ec00 "u-boot-dtb.imx"&lt;BR /&gt;&lt;BR /&gt; Blocks = 0x177ff400 0x00 0x00092c00 "u-boot-dtb.imx", \&lt;BR /&gt; 0x12000000 0x00 0x00932348 "vmlinuz_pad_ivt.bin"&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;./cst --i csf_additional_images.txt --o csf_zImage.bin&lt;/PRE&gt;&lt;PRE&gt;Attach the CSF binary to the end of the image:

  $ cat zImage_pad_ivt.bin csf_zImage.bin &amp;gt; zImage_signed.bin&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I am loading the kernel image as below.&lt;BR /&gt;U-Boot &amp;gt; load mmc 3:1 0x12000000 /boot/zImage_uboot-signed.bin&lt;BR /&gt;9650864 bytes read in 298 ms (30.9 MiB/s)&lt;BR /&gt;MX6 HORIZON U-Boot &amp;gt;&lt;/PRE&gt;&lt;P&gt;U-Boot &amp;gt; hab_auth_img 0x12000000 0x933348&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;hab fuse not enabled&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Authenticate image from DDR location 0x12000000...&lt;BR /&gt;bad magic magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad length magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;bad version magic=0x0 length=0xa000 version=0xe1&lt;BR /&gt;Error: Invalid IVT structure&lt;/P&gt;&lt;P&gt;Allowed IVT structure:&lt;BR /&gt;IVT HDR = 0x4X2000D1&lt;BR /&gt;IVT ENTRY = 0xXXXXXXXX&lt;BR /&gt;IVT RSV1 = 0x0&lt;BR /&gt;IVT DCD = 0x0&lt;BR /&gt;IVT BOOT_DATA = 0xXXXXXXXX&lt;BR /&gt;IVT SELF = 0xXXXXXXXX&lt;BR /&gt;IVT CSF = 0xXXXXXXXX&lt;BR /&gt;IVT RSV2 = 0x0&lt;BR /&gt;MX6 HORIZON U-Boot &amp;gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Could someone please check this issue, any input would be appreciable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 09:46:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Invalid-IVT-structure-Secure-boot-in-imx6/m-p/1618489#M202981</guid>
      <dc:creator>rakesh3</dc:creator>
      <dc:date>2023-03-21T09:46:37Z</dc:date>
    </item>
  </channel>
</rss>

