<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processors中的主题 Re: Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2254367#M242611</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for your interest in NXP Semiconductor products,&lt;/P&gt;
&lt;P&gt;Can you please confirm both manifest and meta-layer are branch aligned?&lt;/P&gt;
&lt;P&gt;The documentation to get started should be found under chapter &lt;A href="https://www.nxp.com/docs/en/user-guide/UG10163.pdf" target="_self"&gt;10.9 Security reference design&lt;/A&gt;. Could you share a fresh build log following the steps quoted?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 03 Dec 2025 17:05:04 GMT</pubDate>
    <dc:creator>JosephAtNXP</dc:creator>
    <dc:date>2025-12-03T17:05:04Z</dc:date>
    <item>
      <title>Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2253725#M242588</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I am currently integrating the meta-nxp-security-reference-design layer into our Yocto build system to enable secure boot for i.MX93. Following NXP's recommendation, I am using SPSDK for the AHAB signing process. During this integration, I have encountered two issues that prevent successful builds for custom hardware with HSM-based signing.&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;SoC:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;i.MX93&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Security Layer:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="vscode-file://vscode-app/c:/Program%20Files/Microsoft%20VS%20Code/resources/app/out/vs/code/electron-browser/workbench/workbench.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://github.com/nxp-imx-support/meta-nxp-security-reference-design/tree/scarthgap-6.6.23-2.0.0&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;SPSDK Version:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;3.4.0&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Signing Method:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SPSDK with spsdk_PKCS11 plugin&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Issue 1:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Missing KERNEL_DTB Parameter Breaks Custom Board Support&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;file:&lt;/STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;meta-secure-boot/recipes-secure-boot/imx-mkimage/imx-boot_%.bbappend&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The kernel container build command lacks the DTB parameter: make&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;SOC=${IMX_BOOT_SOC_TARGET} flash_kernel --&amp;gt; no dtb file input&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The iMX93/soc.mak has a hardcoded default:KERNEL_DTB ?= imx93-11x11-evk.dtb&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;EM&gt;Build fails for custom boards with:make[1]: *** No rule to make target 'imx93-11x11-evk.dtb', needed by 'flash_kernel'. Stop.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issue 2: imx_signer Generates Incorrect YAML for PKCS11/HSM Signing&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Files:&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;meta-secure-boot/recipes-secure-boot/linux/linux-imx-signature.bb&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;imx_signer tool&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;imx_signer reads my spsdk_ahab.cfg but generates nxpimage_config.yaml with hardcoded default paths instead of my PKCS11 configuration.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;imx_signer doesn't parse PKCS11 configuration from CFG files correctly. It:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Ignores signer=type=pkcs11(spsdk yaml reference file contains signer not signature_provider) and uses type=file instead&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Ignores srk_array_X paths and uses hardcoded template paths&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Appears designed for file-based signing only&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;Issue 1&lt;/STRONG&gt;: Can you add KERNEL_DTB parameter support to the flash_kernel recipe or should I follow different approach please suggest?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;Issue 2&lt;/STRONG&gt;: Does imx_signer support PKCS11 configuration? If not, what's the recommended approach for HSM signing with the security reference design?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Is there documentation reference for using PKCS11/HSM with meta-nxp-security-reference-design?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 05:52:06 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2253725#M242588</guid>
      <dc:creator>udayMouli</dc:creator>
      <dc:date>2025-12-03T05:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2254367#M242611</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for your interest in NXP Semiconductor products,&lt;/P&gt;
&lt;P&gt;Can you please confirm both manifest and meta-layer are branch aligned?&lt;/P&gt;
&lt;P&gt;The documentation to get started should be found under chapter &lt;A href="https://www.nxp.com/docs/en/user-guide/UG10163.pdf" target="_self"&gt;10.9 Security reference design&lt;/A&gt;. Could you share a fresh build log following the steps quoted?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 17:05:04 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2254367#M242611</guid>
      <dc:creator>JosephAtNXP</dc:creator>
      <dc:date>2025-12-03T17:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2255051#M242627</link>
      <description>&lt;P&gt;Thanks for your response and the documentation pointers—I've been referencing the same NXP Security Reference Design to integrate secure boot into our Yocto build for i.MX devices.&lt;/P&gt;&lt;P&gt;However, I'm running into a compatibility issue with the prerequisites mentioned in the document. The document specifies that for both CST and SPSDK, the private key password must be in a file named&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;key_pass.txt&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the keys folder. In our setup, the private keys are securely stored in a Hardware Security Module (HSM), not as local files.&lt;/P&gt;&lt;P&gt;Directly using SPSDK's&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;nxpimage ahab sign&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;spsdk-pkcs11&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;plugin works perfectly—I can sign successfully with a YAML config file, leveraging the HSM via PKCS#11.&lt;/P&gt;&lt;P&gt;The challenge arises in Yocto, where the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;imx_signer&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tool acts as a wrapper. It converts the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;.cfg&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file to YAML and handles signing. The command looks like this:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;EM&gt;&lt;SPAN&gt;S&lt;STRONG&gt;IG_TOOL_PATH=${SIG_TOOL_PATH} SIG_DATA_PATH=${SIG_DATA_PATH} ${DEPLOY_DIR_IMAGE}/${BOOT_TOOLS}/&lt;FONT color="#FF0000"&gt;imx_signer&lt;/FONT&gt; -d -i ${DEPLOY_DIR_IMAGE}/${BOOT_IMAGE_SD} -c ${SIGNDIR}/${SIG_CFGFILE}&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;I've set&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SIG_TOOL_PATH&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to the SPSDK binary location and&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SIG_DATA_PATH&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to include the public keys and&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;spsdk_ahab.cfg&lt;SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;I have attached failure log and yaml file generated for reference&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 04 Dec 2025 08:22:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2255051#M242627</guid>
      <dc:creator>udayMouli</dc:creator>
      <dc:date>2025-12-04T08:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2256331#M242689</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/251287"&gt;@udayMouli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems strange, it fails when it doesn't find the binaries or the data, could you share your history output so I can replicate on my side? Also, share the tree output for the following paths.&lt;/P&gt;
&lt;P&gt;$ tree /home/xxx/spsdk/venv/&lt;BR /&gt;$ tree /home/xxx/secureboot/&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2025 22:22:55 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2256331#M242689</guid>
      <dc:creator>JosephAtNXP</dc:creator>
      <dc:date>2025-12-05T22:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2256648#M242714</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/206442"&gt;@JosephAtNXP&lt;/a&gt;,&lt;/P&gt;&lt;DIV&gt;Could you please share an email address where I can send the complete details? The log may contain sensitive information, so I’ll send it separately.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks,&lt;/DIV&gt;&lt;DIV&gt;Uday&lt;/DIV&gt;</description>
      <pubDate>Mon, 08 Dec 2025 04:27:39 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2256648#M242714</guid>
      <dc:creator>udayMouli</dc:creator>
      <dc:date>2025-12-08T04:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Two Issues in meta-nxp-security-reference-design for i.MX93 Custom Board with HSM Signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2257379#M242734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/251287"&gt;@udayMouli&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Please create a private ticket&amp;nbsp;&lt;A href="https://support.nxp.com/s/?language=en_US" target="_blank"&gt;https://support.nxp.com/s/?language=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I will make sure to follow up on it.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 17:25:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Two-Issues-in-meta-nxp-security-reference-design-for-i-MX93/m-p/2257379#M242734</guid>
      <dc:creator>JosephAtNXP</dc:creator>
      <dc:date>2025-12-08T17:25:16Z</dc:date>
    </item>
  </channel>
</rss>

