<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Doubt regarding ahab secure boot in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1864079#M223612</link>
    <description>&lt;P&gt;There is no such script for imx93, but you can have a try with openssl command. By the way, the SRK fuses have to be burned in case of close.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2024 06:07:11 GMT</pubDate>
    <dc:creator>Harvey021</dc:creator>
    <dc:date>2024-05-13T06:07:11Z</dc:date>
    <item>
      <title>Doubt regarding ahab secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1861283#M223450</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have just take a loot at this presentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.nxp.com/design/training/iot-security-unveiling-the-power-of-secure-boot-chain-of-trust-and-ip-protection-on-iot-on-i-mx-9-applications-processors:TIP-IOT-SECURITY-IP-PROTECTION-IMX9-APP-PROCESSORS" target="_blank"&gt;IoT Security: Unveiling the Power of Secure Boot, Chain of Trust and IP Protection on IoT on i.MX 9 Applications Processors | NXP Semiconductors&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regarding the secure boot at loading the secure bootloader this info is provided:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gorka_3_0-1715158413763.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277679i7D5B0F8105C5ACE5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gorka_3_0-1715158413763.png" alt="Gorka_3_0-1715158413763.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The corresponding previously created public key's fuse values are generated and flashed onto the OTP fuses.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gorka_3_1-1715158477358.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277680iA3EEA51BB1353AFA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gorka_3_1-1715158477358.png" alt="Gorka_3_1-1715158477358.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here a signed image is loaded and validated without ELE events.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gorka_3_2-1715158505953.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277681i75E7A84CFE8FA6F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gorka_3_2-1715158505953.png" alt="Gorka_3_2-1715158505953.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At last, after having tested a signed image, it closes ahab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand exactly what does ahab_close do.&lt;/P&gt;&lt;P&gt;Let's say that we have the fuses already burned (regarding SRK table) and now we load a signed bootloader with CONFIG_AHAB_BOOT=y in u-boot. If ahab_close is not done does it mean that the bootaloder is anyway verified but even if it does not match the signature it boots anyway? And after closing ahab does it mean that this time only properly signed images are booted?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Gorka.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 09:03:58 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1861283#M223450</guid>
      <dc:creator>Gorka_3</dc:creator>
      <dc:date>2024-05-08T09:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt regarding ahab secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1862292#M223500</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;That is correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 07:45:14 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1862292#M223500</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2024-05-09T07:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt regarding ahab secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1862306#M223502</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your reply. I have already builded a signed-flash.bin following this guide:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf-6.1.22-2.0.0/doc/imx/ahab/guides/mx8ulp_9x_secure_boot.txt" target="_blank" rel="noopener"&gt;uboot-imx/doc/imx/ahab/guides/mx8ulp_9x_secure_boot.txt at lf-6.1.22-2.0.0 · nxp-imx/uboot-imx · GitHub&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have flashed the bootloader to an sd and booted from it. No fuses have been flashed yet so they are as if srk table is all zeroes. The ahab_status i get is as follows:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gorka_3_0-1715240993926.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277909iBCF2E6C0662C36A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gorka_3_0-1715240993926.png" alt="Gorka_3_0-1715240993926.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have two questions. I see two ele events (two containers have been verified). The first one must be the global container (spl, ddr bin, ahab container and uboot+atf+tee container). It throws a bad key hash (since I haven't flash fuses yet its fine). But the second event indicates that the failure type is no authentication, does this mean that this second container haven't been signed (I am sure I have done it as in the guide is suggested)? And why there are no three events as ther eare three containers?&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 07:55:00 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1862306#M223502</guid>
      <dc:creator>Gorka_3</dc:creator>
      <dc:date>2024-05-09T07:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt regarding ahab secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1863001#M223535</link>
      <description>&lt;P&gt;Yes, event tells that not signed.&lt;/P&gt;&lt;P&gt;A container can contain one or more images which will also record events if with verification error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Harvey&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 03:48:31 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1863001#M223535</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2024-05-10T03:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt regarding ahab secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1863112#M223538</link>
      <description>&lt;P&gt;Your are right, it was not signed. Seems like there was an error in my script, now both containers throw the same bad hash error.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gorka_3_0-1715322260217.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/278117iF00950C700873770/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gorka_3_0-1715322260217.png" alt="Gorka_3_0-1715322260217.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyway, I would like to test if the generated image would match the hash with the correct srk table. Isn't it any script to verify this signature check? As far as fuses cannot be overriden in imx9, I don't see other option as trusting that the signature is correctly done and that it will boot correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 06:27:02 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1863112#M223538</guid>
      <dc:creator>Gorka_3</dc:creator>
      <dc:date>2024-05-10T06:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt regarding ahab secure boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1864079#M223612</link>
      <description>&lt;P&gt;There is no such script for imx93, but you can have a try with openssl command. By the way, the SRK fuses have to be burned in case of close.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 06:07:11 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Doubt-regarding-ahab-secure-boot/m-p/1864079#M223612</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2024-05-13T06:07:11Z</dc:date>
    </item>
  </channel>
</rss>

