<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: u-boot signing for imx8qxp secure boot in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1754869#M215500</link>
    <description>&lt;P&gt;1),&amp;nbsp; If you check the soc.mak, the out is flash.bin&lt;/P&gt;
&lt;P&gt;2),&amp;nbsp;csf_boot_image_sgk.txt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 09:49:53 GMT</pubDate>
    <dc:creator>Harvey021</dc:creator>
    <dc:date>2023-11-09T09:49:53Z</dc:date>
    <item>
      <title>u-boot signing for imx8qxp secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1753677#M215392</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on secure boot of imx8qxp-mek board and i am following the below doc for that.&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/mx8_mx8x_spl_secure_boot.txt" target="_blank"&gt;https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/mx8_mx8x_spl_secure_boot.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Since I am using the flash_spl binary for target so I am using above doc.&lt;/P&gt;&lt;P&gt;I have certain doubts, please help me to understand on this.&lt;/P&gt;&lt;P&gt;1) As per doc first we have to sign the "u-boot-atf-container.img" and then final flash_spl will have 3 containers.&lt;/P&gt;&lt;P&gt;scfw_tcm.bin, u-boot-spl.bin, u-boot-atf-container.img&lt;/P&gt;&lt;P&gt;In above we have signed u-boot-atd-container.img and using it further for creating the flash.bin.&lt;/P&gt;&lt;P&gt;but in the doc its mentioned&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;"The flash.bin file include three containers and the second container have to be&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;signed using the Code Signing Tool (CST)."&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Here 2nd container i think is u-boot-spl.bin . So, do we need to sign this also or not ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please clarify on this&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) I am using csf_uboot_atf.txt for signing the&amp;nbsp;u-boot-atf-container.img,&amp;nbsp; and since i have generated the SRK key with CA flags enabled so ,which csf file should i use to create final signed image flash.bin &lt;FONT color="#FF0000"&gt;.&lt;STRONG&gt;csf_boot_image_sgh.txt or csf_boot.txt&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Please suggest some input on these doubts.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Regards,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Rk&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 19:20:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1753677#M215392</guid>
      <dc:creator>rakesh3</dc:creator>
      <dc:date>2023-11-07T19:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: u-boot signing for imx8qxp secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1754869#M215500</link>
      <description>&lt;P&gt;1),&amp;nbsp; If you check the soc.mak, the out is flash.bin&lt;/P&gt;
&lt;P&gt;2),&amp;nbsp;csf_boot_image_sgk.txt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 09:49:53 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1754869#M215500</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2023-11-09T09:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: u-boot signing for imx8qxp secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1755605#M215562</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/192970"&gt;@Harvey021&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for reply,&lt;/P&gt;&lt;P&gt;for 1 ) I meant that as per the doc mentioned&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;"The flash.bin file include three containers and the second container have to be&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;signed using the Code Signing Tool (CST)."&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;flash_spl: $(MKIMG) $(AHAB_IMG) scfw_tcm.bin u-boot-spl.bin u-boot-atf-container.img&lt;/P&gt;&lt;P&gt;Here 2nd container for flash.bin i think is u-boot-spl.bin . So, do we need to sign this u-boot-spl.bin or not ? if yes then how , its not mentioned in the doc. please suggest .&lt;/P&gt;&lt;P&gt;thanks for clarify the 2nd point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rk&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 12:29:39 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1755605#M215562</guid>
      <dc:creator>rakesh3</dc:creator>
      <dc:date>2023-11-10T12:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: u-boot signing for imx8qxp secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1755963#M215591</link>
      <description>&lt;P&gt;Yes, you need to include the u-boot-spl.bin which will be wrapped into flash.bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 02:39:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/u-boot-signing-for-imx8qxp-secure-boot/m-p/1755963#M215591</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2023-11-13T02:39:16Z</dc:date>
    </item>
  </channel>
</rss>

