<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processors中的主题 Re: IMX93 - AHAB - Secure Boot</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2075011#M235948</link>
    <description>&lt;P&gt;Yes, the SRK Hash not fused will raise the issue of the key hash not matched&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 09:05:30 GMT</pubDate>
    <dc:creator>Harvey021</dc:creator>
    <dc:date>2025-04-07T09:05:30Z</dc:date>
    <item>
      <title>IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2073790#M235854</link>
      <description>&lt;P&gt;Hello NXP Experts,&lt;/P&gt;&lt;P&gt;I have followed this guide&amp;nbsp;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2023.04/doc/imx/ahab/guides/mx8ulp_9x_secure_boot.txt" target="_blank"&gt;uboot-imx/doc/imx/ahab/guides/mx8ulp_9x_secure_boot.txt at lf_v2023.04 · nxp-imx/uboot-imx&lt;/A&gt;&amp;nbsp;in order to generate a PKI Tree and SRK_Table compatible with my target: IMX9332.&lt;/P&gt;&lt;P&gt;I have followed also the "i.MX Linux User's Guide" chapter "10.9.1 Automated image signing for secure boot", in order to generate a signed image with Yocto.&lt;/P&gt;&lt;P&gt;Looking at the generated binaries, I have found the SRK_Table generated, so I'm confident that bitbake works correctly.&lt;/P&gt;&lt;P&gt;I have also flashed my EVK with UUU.&lt;/P&gt;&lt;P&gt;In u-boot, I runned ahab_status and below there is the result:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="il_ciancio_0-1743690619755.png" style="width: 664px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/331300i89D7863F1363AF04/image-dimensions/664x307?v=v2" width="664" height="307" role="button" title="il_ciancio_0-1743690619755.png" alt="il_ciancio_0-1743690619755.png" /&gt;&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;Looking on other ticket in this wonderfull community, It seems that the problem is that I have not flashed the eFuse (and I did not).&lt;/P&gt;&lt;P&gt;What can I do If I want to test the signature on the SWs over the public keys in the SRK Table flashed? In other terms, Can I flash an OS without signature and during the boot I will have an error on the signature?&lt;/P&gt;&lt;P&gt;Please help me!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alessandro.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 14:36:01 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2073790#M235854</guid>
      <dc:creator>il_ciancio</dc:creator>
      <dc:date>2025-04-03T14:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2074844#M235935</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/248332"&gt;@il_ciancio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For official verification and container integrity checks, using the ahab_status is recommended.&lt;/P&gt;
&lt;P&gt;The signed images will trigger events if any error on both open and closed device.&lt;/P&gt;
&lt;P&gt;and images not signed or signing incorrectly won't boot on a closed device.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 06:15:49 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2074844#M235935</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-04-07T06:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2074978#M235945</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/192970"&gt;@Harvey021&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;I have putted the ahab_status from my board and looking at the error (see the table below)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="il_ciancio_0-1744015061232.png" style="width: 587px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/331585i75D7A0085F9DB9DA/image-dimensions/587x267?v=v2" width="587" height="267" role="button" title="il_ciancio_0-1744015061232.png" alt="il_ciancio_0-1744015061232.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;it seems that the only problem is that I have not flashed the e-fuse.&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 08:38:44 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2074978#M235945</guid>
      <dc:creator>il_ciancio</dc:creator>
      <dc:date>2025-04-07T08:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2075011#M235948</link>
      <description>&lt;P&gt;Yes, the SRK Hash not fused will raise the issue of the key hash not matched&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 09:05:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2075011#M235948</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-04-07T09:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2075013#M235949</link>
      <description>Thanks,&lt;BR /&gt;so the certificates generated by CST tool and the image generated and signed by Yocto are well configured, otherwise will I get other error?</description>
      <pubDate>Mon, 07 Apr 2025 09:08:20 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2075013#M235949</guid>
      <dc:creator>il_ciancio</dc:creator>
      <dc:date>2025-04-07T09:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2077018#M236107</link>
      <description>&lt;P&gt;SRK Hash acts as a role to establish root of trust. As stated from guide&amp;nbsp;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2024.04/doc/imx/ahab/introduction_ahab.txt" target="_self"&gt;introduction_ahab.txt&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"On the target device during the authentication process the AHAB code verify the&lt;BR /&gt;SRK Table against the SoC SRK_HASH fuses, in case the verification is successful&lt;BR /&gt;the root of trust is established and the AHAB code can progress with the image&lt;BR /&gt;authentication."&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 09:53:55 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2077018#M236107</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-04-09T09:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2077107#M236112</link>
      <description>So without fusing I can't verify (in order to test on the board the signature) if the image/certs/SRK table are properly generated?</description>
      <pubDate>Wed, 09 Apr 2025 11:59:32 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2077107#M236112</guid>
      <dc:creator>il_ciancio</dc:creator>
      <dc:date>2025-04-09T11:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: IMX93 - AHAB - Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2078014#M236164</link>
      <description>&lt;P&gt;The way with SRK Hash fusing is our recommended and verified procedure.&lt;/P&gt;
&lt;P&gt;You may try tool, OPENSSL, for help to images verification. However, we don't provide support for that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 06:42:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2078014#M236164</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-04-10T06:42:50Z</dc:date>
    </item>
  </channel>
</rss>

