<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CST Signing Process in Mode = HSM in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805624#M219905</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/207913"&gt;@hector_delgado&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am using 3rd party HSM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;jbhaijy&lt;/P&gt;</description>
    <pubDate>Tue, 13 Feb 2024 05:57:23 GMT</pubDate>
    <dc:creator>jbhaijy</dc:creator>
    <dc:date>2024-02-13T05:57:23Z</dc:date>
    <item>
      <title>CST Signing Process in Mode = HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1797065#M219322</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am signing the i.MX6 SPL &amp;amp; U-boot images through CST in Mode = HSM. I am able to sign the SPL &amp;amp; SPL is authenticated by i.MX6 HAB.&lt;/P&gt;&lt;P&gt;We also signed the i.MX6 u-boot but while flashing it got stuck with message failed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jbhaijy_3-1706551175136.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/260603i4BA8B59875173BF7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jbhaijy_3-1706551175136.png" alt="jbhaijy_3-1706551175136.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For u-boot signing we have process set to sign the u-boot with [Authenticate Data] for DCD block along with [Authenticate Data] for HAB Blocks in the CSF file. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jbhaijy_1-1706551105121.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/260601iA633C63EBC7C7B50/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jbhaijy_1-1706551105121.png" alt="jbhaijy_1-1706551105121.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As per the document attached &amp;amp; &lt;A href="https://community.nxp.com/t5/i-MX-Processors/CST-3-3-2-Mode-HSM-for-Remote-HSM-signing/m-p/1726455#M212886" target="_self"&gt;discussed here as well&lt;/A&gt;, when we execute the CST in ‘Mode = HSM’ it generates the data_imgcsf.bin &amp;amp; data_csfsig.bin but the sig_request.txt is showing three unique_tag. I also confirmed that csf.bin(output of cst tool) is also having three unique_tag which I think there will be three signature needed to be replace with unique_tags. But the CST generated only data_imgcsf.bin &amp;amp; data_csfsig.bin. &lt;STRONG&gt;What will be the 3rd .bin which will get signed from HSM? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jbhaijy_2-1706551105140.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/260602iC4B9806630F70E71/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jbhaijy_2-1706551105140.png" alt="jbhaijy_2-1706551105140.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After comparing HSM signed u-boot image with working u-boot(signed without HSM mode) it seems that the working u-boot also has three signatures but the HSM signed u-boot have only 2 signatures &amp;amp; missing one more signature in the u-boot. &amp;nbsp;&lt;/P&gt;&lt;P&gt;I think because of missing signature the the flashing got stuck &amp;amp; failed.&lt;/P&gt;&lt;P&gt;Request you to please help to solve this missing signature problem.&lt;/P&gt;&lt;P&gt;CST tool version: CST-3.4.0&lt;/P&gt;&lt;P&gt;Working OS: Ubuntu 18.04&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;jbhaijy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 18:11:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1797065#M219322</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-01-29T18:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: CST Signing Process in Mode = HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1800251#M219543</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/148045"&gt;@jbhaijy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I hope you're doing well. Let me check this thoroughly and I'll get back to you as soon as possible. Also, just to be sure, i.MX 6 processors are to be used with HAB not AHAB (as it was implied with your attached document) but I'm sure you probably may have uploaded the wrong file even though you might have used the correct one for the signing process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Hector.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 20:14:06 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1800251#M219543</guid>
      <dc:creator>hector_delgado</dc:creator>
      <dc:date>2024-02-01T20:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: CST Signing Process in Mode = HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805447#M219889</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/148045"&gt;@jbhaijy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Could you please let me know if you're using a third party HSM or are you using softhsm2 like the examples from our HSM guide?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Hector.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 18:26:57 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805447#M219889</guid>
      <dc:creator>hector_delgado</dc:creator>
      <dc:date>2024-02-12T18:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: CST Signing Process in Mode = HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805624#M219905</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/207913"&gt;@hector_delgado&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am using 3rd party HSM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;jbhaijy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 05:57:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805624#M219905</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-02-13T05:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: CST Signing Process in Mode = HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805628#M219906</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/207913"&gt;@hector_delgado&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have solved the problem by combining the two different [Authenticate Data] in one. Like below,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jbhaijy_0-1707804116568.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/262898iF4B6BA41C6A5B553/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jbhaijy_0-1707804116568.png" alt="jbhaijy_0-1707804116568.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this case the CST generates signature binary for CSF commands &amp;amp; combined signature data binary for actual image.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 06:03:54 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST-Signing-Process-in-Mode-HSM/m-p/1805628#M219906</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-02-13T06:03:54Z</dc:date>
    </item>
  </channel>
</rss>

