<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRun unsigned kernel and dtb images on closed device</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1653652#M206160</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it possible to run unsigned kernel and dtb on closed imx6 device using signed u-boot but without&amp;nbsp;&lt;SPAN&gt;CONFIG_SECURE_BOOT and CONFIG_IMX_HUB config flags (so the authentication steps done by u-boot for the kernel and dtb will not be performed) ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohamed Ali&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 08:20:18 GMT</pubDate>
    <dc:creator>mohamed-ali_fod</dc:creator>
    <dc:date>2023-05-19T08:20:18Z</dc:date>
    <item>
      <title>Run unsigned kernel and dtb images on closed device</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1653652#M206160</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it possible to run unsigned kernel and dtb on closed imx6 device using signed u-boot but without&amp;nbsp;&lt;SPAN&gt;CONFIG_SECURE_BOOT and CONFIG_IMX_HUB config flags (so the authentication steps done by u-boot for the kernel and dtb will not be performed) ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohamed Ali&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 08:20:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1653652#M206160</guid>
      <dc:creator>mohamed-ali_fod</dc:creator>
      <dc:date>2023-05-19T08:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Run unsigned kernel and dtb images on closed device</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1655345#M206319</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/123550"&gt;@mohamed-ali_fod&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should be no problem to run Kernel and dtb. But not sure why you do that, as you see (&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2022.04/doc/imx/habv4/guides/mx6_mx7_secure_boot.txt" target="_blank"&gt;uboot-imx/mx6_mx7_secure_boot.txt at lf_v2022.04 · nxp-imx/uboot-imx · GitHub&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1.1 Building a u-boot-dtb.imx image supporting secure boot&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The U-Boot provides support to secure boot configuration and also provide&lt;BR /&gt;access to the HAB APIs exposed by the ROM vector table, the support is&lt;BR /&gt;enabled by selecting the CONFIG_IMX_HAB option.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When built with this configuration, the U-Boot provides extra functions for&lt;BR /&gt;HAB, such as the HAB status logs retrievement through the hab_status command&lt;BR /&gt;and support for extending the root of trust.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Harvey&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 06:37:55 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1655345#M206319</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2023-05-23T06:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Run unsigned kernel and dtb images on closed device</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1655430#M206330</link>
      <description>&lt;P&gt;Harvey,&lt;/P&gt;&lt;P&gt;That is your description:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.1 Building a u-boot-dtb.imx image supporting secure boot&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;The U-Boot provides support to secure boot configuration and also provide&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;access to the HAB APIs exposed by the ROM vector table&lt;/FONT&gt;, the support is&lt;BR /&gt;enabled by selecting the CONFIG_IMX_HAB option.&lt;/P&gt;&lt;P&gt;When built with this configuration, the U-Boot provides extra functions for&lt;BR /&gt;HAB, such as the HAB status logs retrievement through the hab_status command&lt;BR /&gt;and support for extending the root of trust.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is u-boot software to do that. It is optional. authenticating any data, here is kernel and/or dtb, is&amp;nbsp;customized software. Again, it is software.&lt;/P&gt;&lt;P&gt;Authenticating boot loader, here is u-boot of i.MX6, is mandatory. It is ROM code to do that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is your "why":&lt;/P&gt;&lt;P&gt;"But not sure why you do that"&lt;/P&gt;&lt;P&gt;My question is, why you ask "why"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;and you copy the description of "1.1 Building a u-boot-dtb.imx image supporting secure boot"&lt;/P&gt;&lt;P&gt;Have you even read it by yourself before you put here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 07:30:14 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Run-unsigned-kernel-and-dtb-images-on-closed-device/m-p/1655430#M206330</guid>
      <dc:creator>mason2036</dc:creator>
      <dc:date>2023-05-23T07:30:14Z</dc:date>
    </item>
  </channel>
</rss>

