<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic imx8qxp-mek secure boot in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1741826#M214242</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using the imx8qxp-mek board and trying to implement the secure boot in that&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have enable the OCNFIG_AHAB_BOOT config in uboot. and followed the instruction given in&amp;nbsp;&lt;/P&gt;&lt;P&gt;/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt&lt;/P&gt;&lt;P&gt;I am using the 6.1.54 linux kernel version and uboot version 2023.04&amp;nbsp; lf-6.1.36_2.1.0 version .&lt;/P&gt;&lt;P&gt;I have attached the output of&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ cd &amp;lt;work&amp;gt;/imx-mkimage&lt;BR /&gt;$ make SOC=iMX8QX flash&lt;/P&gt;&lt;P&gt;and I am using the below csf data to generate the signed img.&lt;/P&gt;&lt;P&gt;$ cd &amp;lt;work&amp;gt;&lt;BR /&gt;$ ./release/linux64/bin/cst -i csf_boot_image.txt -o flash.signed.bin&lt;/P&gt;&lt;P&gt;[Header]&lt;BR /&gt;Target = AHAB&lt;BR /&gt;Version = 1.0&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;BR /&gt;# SRK table generated by srktool&lt;BR /&gt;File = "../crts/SRK_1_2_3_4_table.bin"&lt;BR /&gt;# Public key certificate in PEM format&lt;BR /&gt;Source = "../crts/SRK1_sha256_prime256v1_v3_ca_crt.pem"&lt;BR /&gt;# Index of the public key certificate within the SRK table (0 .. 3)&lt;BR /&gt;Source index = 0&lt;BR /&gt;# Type of SRK set (NXP or OEM)&lt;BR /&gt;Source set = OEM&lt;BR /&gt;# bitmask of the revoked SRKs&lt;BR /&gt;Revocations = 0x0&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;# Binary to be signed generated by mkimage&lt;BR /&gt;File = "flash.bin"&lt;BR /&gt;# Offsets = Container header Signature block (printed out by mkimage)&lt;BR /&gt;Offsets = 0x400 0x510&lt;/P&gt;&lt;P&gt;1) Is the above Authentication Data is Fine to use with mentioned Offsets .&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Is the padding automatically happening during the process of building u-boot/kernel image ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rk&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 06:26:46 GMT</pubDate>
    <dc:creator>rakesh3</dc:creator>
    <dc:date>2023-10-18T06:26:46Z</dc:date>
    <item>
      <title>imx8qxp-mek secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1741826#M214242</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using the imx8qxp-mek board and trying to implement the secure boot in that&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have enable the OCNFIG_AHAB_BOOT config in uboot. and followed the instruction given in&amp;nbsp;&lt;/P&gt;&lt;P&gt;/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt&lt;/P&gt;&lt;P&gt;I am using the 6.1.54 linux kernel version and uboot version 2023.04&amp;nbsp; lf-6.1.36_2.1.0 version .&lt;/P&gt;&lt;P&gt;I have attached the output of&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ cd &amp;lt;work&amp;gt;/imx-mkimage&lt;BR /&gt;$ make SOC=iMX8QX flash&lt;/P&gt;&lt;P&gt;and I am using the below csf data to generate the signed img.&lt;/P&gt;&lt;P&gt;$ cd &amp;lt;work&amp;gt;&lt;BR /&gt;$ ./release/linux64/bin/cst -i csf_boot_image.txt -o flash.signed.bin&lt;/P&gt;&lt;P&gt;[Header]&lt;BR /&gt;Target = AHAB&lt;BR /&gt;Version = 1.0&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;BR /&gt;# SRK table generated by srktool&lt;BR /&gt;File = "../crts/SRK_1_2_3_4_table.bin"&lt;BR /&gt;# Public key certificate in PEM format&lt;BR /&gt;Source = "../crts/SRK1_sha256_prime256v1_v3_ca_crt.pem"&lt;BR /&gt;# Index of the public key certificate within the SRK table (0 .. 3)&lt;BR /&gt;Source index = 0&lt;BR /&gt;# Type of SRK set (NXP or OEM)&lt;BR /&gt;Source set = OEM&lt;BR /&gt;# bitmask of the revoked SRKs&lt;BR /&gt;Revocations = 0x0&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;BR /&gt;# Binary to be signed generated by mkimage&lt;BR /&gt;File = "flash.bin"&lt;BR /&gt;# Offsets = Container header Signature block (printed out by mkimage)&lt;BR /&gt;Offsets = 0x400 0x510&lt;/P&gt;&lt;P&gt;1) Is the above Authentication Data is Fine to use with mentioned Offsets .&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Is the padding automatically happening during the process of building u-boot/kernel image ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rk&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 06:26:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1741826#M214242</guid>
      <dc:creator>rakesh3</dc:creator>
      <dc:date>2023-10-18T06:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: imx8qxp-mek secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1744180#M214534</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is the above Authentication Data is Fine to use with mentioned Offsets.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-&amp;gt; It is fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the padding automatically happening during the process of building u-boot/kernel image?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-&amp;gt; 0x400 is padded to 1kb alignment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regads&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Harvey&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 05:36:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1744180#M214534</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2023-10-23T05:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: imx8qxp-mek secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1744710#M214578</link>
      <description>&lt;P&gt;Thanks for reply,&lt;/P&gt;&lt;P&gt;I am signing the kernel for secure boot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have used the mentioned steps in the&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/sign_os_cntr.txt" target="_blank" rel="noopener"&gt;https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/sign_os_cntr.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But while build the kernel&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ make SOC=imx8qx flash_kernel&lt;BR /&gt;I was getting error for not found Image file. So i renamed the kernel image&amp;nbsp;vmlinux-6.1.54-cip6+mel2 to Image.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I&lt;STRONG&gt;s this correct ? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Because I am not getting the Image what is mentioned in the imx-mkimage/iMX8QX/soc.mk for flash_kernel build.&lt;/P&gt;&lt;P&gt;After successfully building the kernel img container using above renamed method, I signed the kernel img using CST tool using below cmd&lt;/P&gt;&lt;P&gt;$./release/linux64/bin/cst -i csf_linux_img.txt -o os_cntr_signed.bin&lt;/P&gt;&lt;P&gt;I tried to load the kernel img to ram using sd card boot&lt;/P&gt;&lt;P&gt;=&amp;gt;&amp;nbsp;load mmc 1:1 ${cntr_addr} /boot/os_cntr_signed.bin&lt;/P&gt;&lt;P&gt;But I got below error.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;=&amp;gt; load mmc 1:1 ${cntr_addr} /opt/os_cntr_signed.bin&lt;BR /&gt;checksum verify failed on 22216704 found 000000DB wanted 000000E8&lt;BR /&gt;checksum verify failed on 22216704 found 00000054 wanted 00000038&lt;BR /&gt;checksum verify failed on 22216704 found 000000DB wanted 000000E8&lt;BR /&gt;bad tree block 22216704, bytenr mismatch, want=22216704, have=3757466704011408333&lt;BR /&gt;BTRFS: cannot read chunk root&lt;BR /&gt;Can't set block device&lt;BR /&gt;=&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;2)&lt;STRONG&gt; I am using the uboot/include/configs/imx8qxp_mek.h&amp;nbsp; file. Can we give both Image and os_contr_signed.bin as load&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;"loadimage=fatload mmc ${mmcdev}:${mmcpart} ${loadaddr} ${image}\0" \&lt;BR /&gt;"loadfdt=fatload mmc ${mmcdev}:${mmcpart} ${fdt_addr} ${fdt_file}\0" \&lt;BR /&gt;"loadcntr=fatload mmc ${mmcdev}:${mmcpart} ${cntr_addr} ${cntr_file}\0" \&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Or Just for testing we can simply give the&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I have tested with below command as mentioned in doc for testing the Os authentication&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Note: OS image can also be authenticated by running a U-Boot command:&lt;/P&gt;&lt;P&gt;=&amp;gt; auth_cntr &amp;lt;Container address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/sign_os_cntr.txt" target="_blank" rel="noopener"&gt;https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/sign_os_cntr.txt&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;=&amp;gt; auth_cntr ${cntr_addr}&lt;BR /&gt;Authenticate OS container at 0x98000000&lt;BR /&gt;container length 672&lt;BR /&gt;img 0, dst 0x80200000, src 0x2550145024x, size 0x222dc00&lt;BR /&gt;img 1, dst 0x83000000, src 0x2585984000x, size 0x19400&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I think 1st img0 is the Image(kernel img) and 2nd img1 is the dtb img. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;1) Is the above authentication of images is good to go for flashing the keys ?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;2&lt;STRONG&gt;) In the below lines mentioned in the include/configs/imx8qxp_mek.h&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;"loadimage=fatload mmc ${mmcdev}:${mmcpart} ${loadaddr} ${image}\0" \&lt;BR /&gt;+ "loadfdt=fatload mmc ${mmcdev}:${mmcpart} ${fdt_addr} ${fdt_file}\0" \&lt;BR /&gt;+ "loadcntr=fatload mmc ${mmcdev}:${mmcpart} ${cntr_addr} ${cntr_file}\0" \&lt;BR /&gt;+ "auth_os=auth_cntr ${cntr_addr}\0" \&lt;BR /&gt;+ "boot_os=booti ${loadaddr} - ${fdt_addr};\0" \&lt;BR /&gt;+ "mmcboot=echo Booting from mmc ...; " \&lt;BR /&gt;+ "run mmcargs; " \&lt;BR /&gt;+ "if test ${sec_boot} = yes; then " \&lt;BR /&gt;+ "if run auth_os; then " \&lt;BR /&gt;+ "run boot_os; " \&lt;BR /&gt;+ "else " \&lt;BR /&gt;+ "echo ERR: failed to authenticate; " \&lt;BR /&gt;+ "fi; " \&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We are loading the unsigned img at loadaddr and then loading the singed image at cntr_addr.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this steps correct to verify the signed kernel img ? Why we are loading the unsigned and then signed kernel img ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to cross verify the signed kernel/uboot img ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Please give suggestion on this .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 10:02:48 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/imx8qxp-mek-secure-boot/m-p/1744710#M214578</guid>
      <dc:creator>rakesh3</dc:creator>
      <dc:date>2023-10-24T10:02:48Z</dc:date>
    </item>
  </channel>
</rss>

