<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CST3.4.0 with HSM in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1904451#M226035</link>
    <description>&lt;P&gt;You can download from&amp;nbsp;&lt;A href="https://www.nxp.com/search?keyword=IMX_CST_TOOL" target="_blank"&gt;https://www.nxp.com/search?keyword=IMX_CST_TOOL&lt;/A&gt;&lt;BR /&gt;Default this CST tool have HSM support but you need to configure your CSF to get it images signed from HSM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Explore the documentation in this tool for further details.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2024 14:23:42 GMT</pubDate>
    <dc:creator>jbhaijy</dc:creator>
    <dc:date>2024-07-09T14:23:42Z</dc:date>
    <item>
      <title>CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1793834#M219083</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using latest CST-3.4.0 &amp;amp; I want to explore the CST-3.4.0 with third party HSM. I configured openssl.cnf as like below,&lt;/P&gt;&lt;P&gt;openssl_conf = openssl_init&lt;BR /&gt;[openssl_init]&lt;BR /&gt;engines = engine_section&lt;BR /&gt;[engine_section]&lt;BR /&gt;pkcs11 = pkcs11_section&lt;BR /&gt;[pkcs11_section]&lt;BR /&gt;#Path to the Compiled OpenSSL PKCS11 from OpenSC - libp11&lt;BR /&gt;dynamic_path = /usr/lib/x86_64-linux-gnu/engines-1.1/libpkcs11.so&lt;BR /&gt;MODULE_PATH = /home/jbhaijy/digicert/smtools-linux-x64/smpkcs11.so&lt;/P&gt;&lt;P&gt;I run the CST with -b pkcs11 option to sign the images through HSM, but I am getting below errors.&lt;/P&gt;&lt;P&gt;./cst --verbose -b pkcs11 -i dev_spl.csf -o dev_spl.bin&lt;BR /&gt;Install SRK&lt;BR /&gt;Install CSFK&lt;BR /&gt;Certificate not found.&lt;BR /&gt;Public key certificate is invalid in file pkcs11:model=DigiCert%20PKCS%2311;manufacturer=DigiCert;serial=SS0123456789;token=Virtual%20PKCS%2311%20Token;id=%36%34%33%39%61%63%61%32%2D%35%36%61%30%2D%34%64%64%63%2D%39%36%30%39%2D%65%62%64%39%31%63%36%33%65%33%62%39;object=imx6-hab-csf2-key-test;type=private&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me identify the problems here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for you support.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 13:27:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1793834#M219083</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-01-23T13:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1793985#M219101</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/148045"&gt;@jbhaijy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I hope you're doing well!&lt;/P&gt;
&lt;P&gt;What i.MX are you using? Is it a custom board or one of our EVKs? Also, what distro and version of Linux are you using in your host environment?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Hector.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 16:56:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1793985#M219101</guid>
      <dc:creator>hector_delgado</dc:creator>
      <dc:date>2024-01-23T16:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1793989#M219102</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/207913"&gt;@hector_delgado&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for the reply.&amp;nbsp;&lt;BR /&gt;We want to have CST signing solution for i.MX6 &amp;amp; i.MX8 both. Both are custom boards. I am running Ubuntu-22.04 VM.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 17:06:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1793989#M219102</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-01-23T17:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1794763#M219155</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/148045"&gt;@jbhaijy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Have you followed all steps from our Application Note Using Code-Signing Tool with Hardware Security Module (&lt;A href="https://www.nxp.com/webapp/Download?colCode=AN12812&amp;amp;location=null" target="_blank"&gt;https://www.nxp.com/webapp/Download?colCode=AN12812&amp;amp;location=null&lt;/A&gt;)?&lt;/P&gt;
&lt;P&gt;Even though it's an old guide, I believe it should still apply to our current CST release.&lt;/P&gt;
&lt;P&gt;Let me know if this was of any help.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Hector.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 16:47:43 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1794763#M219155</guid>
      <dc:creator>hector_delgado</dc:creator>
      <dc:date>2024-01-24T16:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1796359#M219264</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/207913"&gt;@hector_delgado&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed the steps mentioned in the AN12812, Instead of SoftHSM we are using 3rd party HSM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be the possible reasons?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;jbhaijy&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 13:03:15 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1796359#M219264</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-01-27T13:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1800245#M219541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/148045"&gt;@jbhaijy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Could you try the following changes to your openssl.cnf file?&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;openssl_conf = openssl_def

[openssl_def]
engines = engine_section


[engine_section]
pkcs11 = pkcs11_section


[pkcs11_section]
engine_id = pkcs11
#Path to the Compiled OpenSSL PKCS11 from OpenSC - libp11
dynamic_path = /usr/lib/x86_64-linux-gnu/engines-1.1/libpkcs11.so
MODULE_PATH = /home/jbhaijy/digicert/smtools-linux-x64/smpkcs11.so
init = 0&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;Let me know if it solves the issue.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Hector.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 19:53:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1800245#M219541</guid>
      <dc:creator>hector_delgado</dc:creator>
      <dc:date>2024-02-01T19:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1904000#M226021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/148045"&gt;@jbhaijy&lt;/a&gt;&amp;nbsp; how to get latest cst with hsm, unable to find the latest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 09:17:02 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1904000#M226021</guid>
      <dc:creator>mathiyalagan_c</dc:creator>
      <dc:date>2024-07-09T09:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1904451#M226035</link>
      <description>&lt;P&gt;You can download from&amp;nbsp;&lt;A href="https://www.nxp.com/search?keyword=IMX_CST_TOOL" target="_blank"&gt;https://www.nxp.com/search?keyword=IMX_CST_TOOL&lt;/A&gt;&lt;BR /&gt;Default this CST tool have HSM support but you need to configure your CSF to get it images signed from HSM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Explore the documentation in this tool for further details.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 14:23:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1904451#M226035</guid>
      <dc:creator>jbhaijy</dc:creator>
      <dc:date>2024-07-09T14:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1905774#M226060</link>
      <description>&lt;P&gt;&lt;A href="https://community.nxp.com/t5/i-MX-Processors-Knowledge-Base/HSM-Code-Signing-Journey/ta-p/1882244" target="_blank"&gt;https://community.nxp.com/t5/i-MX-Processors-Knowledge-Base/HSM-Code-Signing-Journey/ta-p/1882244&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 02:34:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/1905774#M226060</guid>
      <dc:creator>roke</dc:creator>
      <dc:date>2024-07-11T02:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: CST3.4.0 with HSM</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/2186761#M241432</link>
      <description>&lt;P&gt;I am trying to accomplish the signature using Digicert for imx93 with AHAB.&lt;/P&gt;&lt;P&gt;I am able to sign both&amp;nbsp;&lt;SPAN&gt;os_cntr_signed.bin and&amp;nbsp;&amp;nbsp;imx-boot-imx93-var-som-aski-sd.bin-flash_singleboot_gdet but once I try to verify them using&amp;nbsp;~/cst-4.0.0/linux64/bin/ahab_image_verifier I get a incoherent result:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By doing: ahab_image_verifier os_cntr_signed.bin 0 0&amp;nbsp; &amp;nbsp;I get&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#999999"&gt;Signature Block:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;Version: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;Length: 2648 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;Tag: 0x90&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;Certificate Offset: 0x0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;SRK Table/Array Offset: 0x10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;SRK Table:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Tag: 0xD7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Length: 2112 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Version: 66&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;SRK Record:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Tag: 0xE1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Length: 527 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sign Algorithm: &lt;STRONG&gt;RSA&lt;/STRONG&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Hash Algorithm: &lt;STRONG&gt;SHA2_384&lt;/STRONG&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Key Size/Curve: &lt;STRONG&gt;RSA4096&lt;/STRONG&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SRK Flags: CA Flags &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Modulus (N):&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;.....&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;Signature verification failed&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While by doing:&amp;nbsp;ahab_image_verifier imx-boot-imx93-var-som-aski-sd.bin-flash_singleboot_gdet 0 0&amp;nbsp; &amp;nbsp; I get:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#808080"&gt;&lt;SPAN&gt;Signature Block:&lt;BR /&gt;&amp;nbsp;Version: 0&lt;BR /&gt;&amp;nbsp;Length: 400 bytes&lt;BR /&gt;&amp;nbsp;Tag: 0x90&lt;BR /&gt;&amp;nbsp;Certificate Offset: 0x0&lt;BR /&gt;&amp;nbsp;SRK Table/Array Offset: 0x10&lt;BR /&gt;&amp;nbsp;SRK Table:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Tag: 0xD7&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Length: 308 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Version: 66&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;SRK Record:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Tag: 0xE1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Length: 76 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sign Algorithm: &lt;STRONG&gt;ECDSA&lt;/STRONG&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Hash Algorithm: &lt;STRONG&gt;SHA2_256&lt;/STRONG&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Key Size/Curve: &lt;STRONG&gt;PRIME256V1&lt;/STRONG&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SRK Flags: None &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;X Coordinate:&amp;nbsp; ....&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Y Coordinate:&amp;nbsp; ...&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#808080"&gt;&lt;SPAN&gt;......&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#808080"&gt;Signature verification successful&lt;BR /&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;I used the same csf.cfg as input to cst-signer, thus same SRK Table and Digicert Token are used in cst's .csf files&lt;BR /&gt;&lt;BR /&gt;does anybody have a clue?! I also posted this question in&amp;nbsp;&lt;A href="https://community.nxp.com/t5/i-MX-Processors/Testing-signed-images/m-p/1669327/highlight/false#M207604" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 15:33:41 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/CST3-4-0-with-HSM/m-p/2186761#M241432</guid>
      <dc:creator>imx8mp_developer</dc:creator>
      <dc:date>2025-10-15T15:33:41Z</dc:date>
    </item>
  </channel>
</rss>

