<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: i.MX93 AHAB Secure Boot in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2201907#M242047</link>
    <description>&lt;P&gt;$ hexdump -C SRK_1_2_3_4_table.bin |head&lt;BR /&gt;00000000 d7 b4 01 42 e1 6c 00 27 00 02 00 80 30 00 30 00 |...B.l.'....0.0.|&lt;BR /&gt;00000010 03 41 64 13 d5 b6 e8 1d 4d 08 4a 3b d2 78 2e 9c |.Ad.....M.J;.x..|&lt;BR /&gt;00000020 ba db 9b ef 13 6a 0e c6 d4 d4 0c b0 3c 9f 46 8a |.....j......&amp;lt;.F.|&lt;BR /&gt;00000030 31 d0 68 63 1f 7c 76 d5 cb 48 a6 6a 63 1f f9 3a |1.hc.|v..H.jc..:|&lt;BR /&gt;00000040 d3 d9 34 e2 67 71 0f 17 af 38 0c 11 10 a7 bc 7a |..4.gq...8.....z|&lt;BR /&gt;00000050 32 90 e5 c4 50 f8 ce 64 8c b2 61 97 ca 40 ea dc |2...P..d..a..@..|&lt;BR /&gt;00000060 9d 7b a5 a1 6d 12 f5 7d 20 46 a9 5e ca 8d 0b 06 |.{..m..} F.^....|&lt;BR /&gt;00000070 e1 6c 00 27 00 02 00 80 30 00 30 00 f5 c0 f4 44 |.l.'....0.0....D|&lt;BR /&gt;00000080 21 88 8a 53 c7 f8 d6 02 85 d2 8f a3 bc b7 dd e1 |!..S............|&lt;BR /&gt;00000090 17 eb 6c 01 4c 3e d8 e0 07 ee 41 6f 64 27 3c 81 |..l.L&amp;gt;....Aod'&amp;lt;.|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;irmware-ele-imx-2.0.2-89161a8.bin&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2025 13:44:56 GMT</pubDate>
    <dc:creator>yaen</dc:creator>
    <dc:date>2025-11-10T13:44:56Z</dc:date>
    <item>
      <title>i.MX93 AHAB Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2192945#M241653</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I’m trying to produce a signed bootloader for i.MX93 using both CST&lt;BR /&gt;(&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2025.04/doc/imx/ahab/" target="_blank"&gt;https://github.com/nxp-imx/uboot-imx/blob/lf_v2025.04/doc/imx/ahab/&lt;/A&gt;)&lt;BR /&gt;and SPSDK&lt;BR /&gt;(&lt;A href="https://docs.nxp.com/bundle/AN14785/page/topics/introduction.html" target="_blank"&gt;https://docs.nxp.com/bundle/AN14785/page/topics/introduction.html&lt;/A&gt;),&lt;BR /&gt;following the official guides.&lt;/P&gt;&lt;P&gt;Both methods complete, but signature verification reports warnings:&lt;/P&gt;&lt;P&gt;nxpimage bootable-image verify -f mimx9352 -b hsm_flash.bin -m serial_downloader&lt;BR /&gt;...&lt;BR /&gt;Summary table of verifier results:&lt;BR /&gt;+-----------+---------+-------+&lt;BR /&gt;| Succeeded | Warning | Error |&lt;BR /&gt;+-----------+---------+-------+&lt;BR /&gt;| 587 | 5 | 0 |&lt;BR /&gt;+-----------+---------+-------+&lt;/P&gt;&lt;P&gt;Overall result: Warning&lt;/P&gt;&lt;P&gt;After programming the SRK hash as advised in&lt;BR /&gt;&lt;A href="https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2073790and" target="_blank"&gt;https://community.nxp.com/t5/i-MX-Processors/IMX93-AHAB-Secure-Boot/m-p/2073790and&lt;/A&gt; rebooting, I get:&lt;/P&gt;&lt;P&gt;ahab_status&lt;BR /&gt;Lifecycle: 0x00000008, OEM Open&lt;BR /&gt;0x0287fad6&lt;BR /&gt;IPC = MU APD (0x2)&lt;BR /&gt;CMD = ELE_OEM_CNTN_AUTH_REQ (0x87)&lt;BR /&gt;IND = ELE_BAD_KEY_HASH_FAILURE_IND (0xFA)&lt;BR /&gt;STA = ELE_SUCCESS_IND (0xD6)&lt;/P&gt;&lt;P&gt;Could you clarify:&lt;/P&gt;&lt;P&gt;What causes the ELE_BAD_KEY_HASH_FAILURE_IND in this context?&lt;/P&gt;&lt;P&gt;Are the “warnings” from nxpimage verify expected, or do they indicate a signature mismatch?&lt;/P&gt;&lt;P&gt;Which toolchain (CST or SPSDK) is currently recommended for i.MX93 AHAB, and is there a verified example configuration available?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Yaakov&lt;/P&gt;</description>
      <pubDate>Sun, 26 Oct 2025 09:54:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2192945#M241653</guid>
      <dc:creator>yaen</dc:creator>
      <dc:date>2025-10-26T09:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX93 AHAB Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2193324#M241663</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The key hash (in SRK Table) verification does not match that in the OTP fuse may cause.&lt;/P&gt;
&lt;P&gt;Please share how you generate key and SRK Table and Hash.&lt;/P&gt;
&lt;P&gt;Please note that, for i.MX93, a subordinate SGK key is not supported and&amp;nbsp;In i.MX 8ULP/9x, the expected SRK HASH is of 256 bit.&lt;/P&gt;
&lt;P&gt;Please reference -&amp;nbsp;&lt;A href="https://github.com/nxp-imx/uboot-imx/blob/lf_v2025.04/doc/imx/ahab/introduction_ahab.txt" target="_self"&gt;The Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 08:25:02 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2193324#M241663</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-10-27T08:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX93 AHAB Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2197058#M241852</link>
      <description>&lt;P&gt;Hi Harvey,&lt;/P&gt;&lt;P&gt;I generated the SRK Table and key hash with:&lt;/P&gt;&lt;PRE&gt;srktool -a -d sha256 -s sha384 -t SRK_1_2_3_4_table.bin \
           -e SRK_1_2_3_4_fuse.bin -f 1 -c \
           SRK1_sha384_secp384r1_v3_usr_crt.pem,\
SRK2_sha384_secp384r1_v3_usr_crt.pem,\
SRK3_sha384_secp384r1_v3_usr_crt.pem,\
SRK4_sha384_secp384r1_v3_usr_crt.pem&lt;/PRE&gt;&lt;P&gt;following the reference that you sent&lt;/P&gt;&lt;P&gt;Is there a preferred procedure to ensure the hash matches the fuse expectations?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Yaakov&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 12:37:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2197058#M241852</guid>
      <dc:creator>yaen</dc:creator>
      <dc:date>2025-11-02T12:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX93 AHAB Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2198735#M241921</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/228938"&gt;@yaen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check your SRK Table&amp;nbsp;hexdump -C SRK_1_2_3_4_table.bin | head and share.&lt;/P&gt;
&lt;P&gt;Also share the version of your ELE FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 05:40:39 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2198735#M241921</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-11-05T05:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX93 AHAB Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2201907#M242047</link>
      <description>&lt;P&gt;$ hexdump -C SRK_1_2_3_4_table.bin |head&lt;BR /&gt;00000000 d7 b4 01 42 e1 6c 00 27 00 02 00 80 30 00 30 00 |...B.l.'....0.0.|&lt;BR /&gt;00000010 03 41 64 13 d5 b6 e8 1d 4d 08 4a 3b d2 78 2e 9c |.Ad.....M.J;.x..|&lt;BR /&gt;00000020 ba db 9b ef 13 6a 0e c6 d4 d4 0c b0 3c 9f 46 8a |.....j......&amp;lt;.F.|&lt;BR /&gt;00000030 31 d0 68 63 1f 7c 76 d5 cb 48 a6 6a 63 1f f9 3a |1.hc.|v..H.jc..:|&lt;BR /&gt;00000040 d3 d9 34 e2 67 71 0f 17 af 38 0c 11 10 a7 bc 7a |..4.gq...8.....z|&lt;BR /&gt;00000050 32 90 e5 c4 50 f8 ce 64 8c b2 61 97 ca 40 ea dc |2...P..d..a..@..|&lt;BR /&gt;00000060 9d 7b a5 a1 6d 12 f5 7d 20 46 a9 5e ca 8d 0b 06 |.{..m..} F.^....|&lt;BR /&gt;00000070 e1 6c 00 27 00 02 00 80 30 00 30 00 f5 c0 f4 44 |.l.'....0.0....D|&lt;BR /&gt;00000080 21 88 8a 53 c7 f8 d6 02 85 d2 8f a3 bc b7 dd e1 |!..S............|&lt;BR /&gt;00000090 17 eb 6c 01 4c 3e d8 e0 07 ee 41 6f 64 27 3c 81 |..l.L&amp;gt;....Aod'&amp;lt;.|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;irmware-ele-imx-2.0.2-89161a8.bin&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 13:44:56 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2201907#M242047</guid>
      <dc:creator>yaen</dc:creator>
      <dc:date>2025-11-10T13:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX93 AHAB Secure Boot</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2202244#M242067</link>
      <description>&lt;P&gt;The hash algorithm looks fine.&lt;/P&gt;
&lt;P&gt;Please try to check if&amp;nbsp;sha256sum of SRK_1_2_3_4_table matches with the SRK_1_2_3_4_fuse.bin and also read the fuse values that already burned on SoC and do match.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 02:14:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX93-AHAB-Secure-Boot/m-p/2202244#M242067</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2025-11-11T02:14:26Z</dc:date>
    </item>
  </channel>
</rss>

