<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ahab_status error from imx93 secure boot in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856228#M223082</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Probably a cause as like " &lt;SPAN class="fontstyle0"&gt;By default, the NXP CST Signer Tool uses standard keys of type &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;ECC P256-SHA256 &lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;for i.MX 8/8x/8ULP/9 Family&lt;/SPAN&gt;" as stated from &amp;lt;&lt;SPAN class="fontstyle0"&gt;10.9.2 Prerequisites for preparing a signed image&lt;/SPAN&gt;&amp;gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
    <pubDate>Sun, 28 Apr 2024 08:40:50 GMT</pubDate>
    <dc:creator>Harvey021</dc:creator>
    <dc:date>2024-04-28T08:40:50Z</dc:date>
    <item>
      <title>ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1855533#M223037</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;professionals !&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm doing the secure boot on imx93. I use Yocto with&amp;nbsp;meta-nxp-security-reference-design/meta-secure-boot meta layer, which supports i.MX boot image signing automation to compile the signed uboot and kernel container.&lt;/P&gt;&lt;P&gt;First time, i&amp;nbsp;referred to the ahab document and generated the ecc sha384 keys, and got the signed uboot and kernel container. I flash it to first board and run ahab_status, it succeed&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JackyCheng_0-1714123124062.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/276096i3448FFC88508B341/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JackyCheng_0-1714123124062.png" alt="JackyCheng_0-1714123124062.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Second time, i generated the rsa-2048 sha256 keys, and&amp;nbsp;every steps else is the same with the first time. I flash the signed uboot and kernel to second board and run ahab_status, it failed, shows&amp;nbsp;&lt;/P&gt;&lt;P&gt;0x0287f7d6&lt;BR /&gt;IPC = MU APD (0x2)&lt;BR /&gt;CMD = ELE_OEM_CNTN_AUTH_REQ (0x87)&lt;BR /&gt;IND = ELE_BAD_CONTAINER_FAILURE_IND (0xF7)&lt;BR /&gt;STA = ELE_SUCCESS_IND (0xD6)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JackyCheng_1-1714123245917.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/276097iFBE4AFA404771E75/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JackyCheng_1-1714123245917.png" alt="JackyCheng_1-1714123245917.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm really confused why it can't work with the rsa keys, and what does the failure indication mean? I think the imx93 and ahab support both ECC and RSA, and i really follow the same step, just key type are different.&lt;/P&gt;&lt;P&gt;I am very eager to get your support and help! Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 09:25:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1855533#M223037</guid>
      <dc:creator>Jacky-Cheng</dc:creator>
      <dc:date>2024-04-26T09:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856228#M223082</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Probably a cause as like " &lt;SPAN class="fontstyle0"&gt;By default, the NXP CST Signer Tool uses standard keys of type &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;ECC P256-SHA256 &lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;for i.MX 8/8x/8ULP/9 Family&lt;/SPAN&gt;" as stated from &amp;lt;&lt;SPAN class="fontstyle0"&gt;10.9.2 Prerequisites for preparing a signed image&lt;/SPAN&gt;&amp;gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2024 08:40:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856228#M223082</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2024-04-28T08:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856240#M223084</link>
      <description>Hi Harvey, thanks for your reply first! But, it just said by default, not explicitly stated that other key types can't be used. So i wonder can RSA key type works? And if not, what's the reason? Thanks again!</description>
      <pubDate>Sun, 28 Apr 2024 09:01:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856240#M223084</guid>
      <dc:creator>Jacky-Cheng</dc:creator>
      <dc:date>2024-04-28T09:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856283#M223090</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;As AHAB should support RSA key. With checking the whole statement from the section " &lt;SPAN class="fontstyle0"&gt;10.9.2 Prerequisites for preparing a signed image&lt;/SPAN&gt;". my understanding is that the Signer Tool, by default, will use ECC type of keys for i.MX93 device for signing. Sorry, it is not available for me to have a test for now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you side have a test while using RSA keys? as stated here “&lt;SPAN class="fontstyle0"&gt;Note: &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;(Optional) Create and populate &lt;/SPAN&gt;&lt;SPAN class="fontstyle3"&gt;csf_hab4.cfg &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;and/or &lt;/SPAN&gt;&lt;SPAN class="fontstyle3"&gt;csf_ahab.cfg &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;with the preferred key type at the CST location to use your preferred PKI tree. The default configuration files are located at the CST Signer work directory in Yocto build.&lt;/SPAN&gt;”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2024 10:24:56 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1856283#M223090</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2024-04-28T10:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1859341#M223303</link>
      <description>&lt;P&gt;This issue has been resolved. As the IMX93&amp;nbsp;&lt;SPAN&gt;Reference Manual say, it support rsa-pss and ecc key, but not rsa key, so it is clear that imx93 doesn't support rsa type keys.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 03:20:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1859341#M223303</guid>
      <dc:creator>Jacky-Cheng</dc:creator>
      <dc:date>2024-05-06T03:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1860583#M223397</link>
      <description>&lt;P&gt;That is correct, no RSA with ele device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:43:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/1860583#M223397</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2024-05-07T13:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/2003462#M231318</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/232788"&gt;@Jacky-Cheng&lt;/a&gt;&amp;nbsp;actually i am also using imx93 with yocto and i want secure boot&amp;nbsp;i.MX 93 signed and encrypted AHAB image but as i am totally new to this i was unable to do after many attempts. What i did was added the layer to my source and then i am confused like how the generated how the keys generated what conf i need to add in local.conf and all can you please help me with this to provide steps!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks &amp;amp; regards&amp;nbsp;&lt;BR /&gt;Brati&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 07:32:29 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/2003462#M231318</guid>
      <dc:creator>brati_7</dc:creator>
      <dc:date>2024-11-28T07:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/2004353#M231363</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/192970"&gt;@Harvey021&lt;/a&gt;&amp;nbsp; I have compiled the image including the meta-secure-boot by follwing the document but previously i was using "core-image-selinux-imx93-11x11-lpddr4x-curiosity.rootfs.wic.zst" to flash now can you please tell what are the images i can use to flash and how can i flash please.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance&lt;BR /&gt;Brati&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 13:04:45 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/2004353#M231363</guid>
      <dc:creator>brati_7</dc:creator>
      <dc:date>2024-11-29T13:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: ahab_status error from imx93 secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/2046377#M234138</link>
      <description>&lt;P&gt;I ended up with the same errors of Jacky-Cheng...&lt;BR /&gt;Where is this statement located? I could not find it in the IMX93RM and SRM.&lt;BR /&gt;Are you referring to the table 4 in UG10106?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 12:58:01 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/ahab-status-error-from-imx93-secure-boot/m-p/2046377#M234138</guid>
      <dc:creator>Migli0</dc:creator>
      <dc:date>2025-02-18T12:58:01Z</dc:date>
    </item>
  </channel>
</rss>

