<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processorsのトピックi.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405146#M246360</link>
    <description>&lt;DIV class=""&gt;&lt;STRONG&gt;Hi Team,&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;We are currently working on importing a private key to an &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:10454109626952377055,headlineOfferDocid:16942149593012699800,productDocid:16942149593012699800&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgPEAE" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; device following the guidelines in application note &lt;STRONG&gt;AN14898&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Environment &amp;amp; References:&lt;/STRONG&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Target Device:&lt;/STRONG&gt; &lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:10454109626952377055,headlineOfferDocid:16942149593012699800,productDocid:16942149593012699800&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgREAM" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Demo Application:&lt;/STRONG&gt; &lt;SPAN class=""&gt;&lt;A href="https://www.google.com/url?sa=i&amp;amp;source=web&amp;amp;rct=j&amp;amp;url=CAESUgHuR6pNa-EbAS1iH71iTgn4T9F2guNuMAxogsURan4yjzrB1gZSke31V576eb41E5BUnnTw7K4fpEpVcqz9ye_p14WDwPK3Sgo3P439I4b-1l0%3D&amp;amp;uoh=2&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQy_kOegYIAAgREAU&amp;amp;opi=89978449&amp;amp;cd&amp;amp;psig=AOvVaw0sojBqG5zQSjPkioZOx9Rr&amp;amp;ust=1786775774500000" target="_blank" rel="noopener"&gt;imx_sec_apps/imx-ele-apps&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;SPSDK Version:&lt;/STRONG&gt; Latest standard toolset&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Activities Completed So Far:&lt;/STRONG&gt;&lt;/DIV&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Installed Python, pip, and the SPSDK toolset.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Successfully built both the Host and Device applications.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Copied device/bin/ele_key_import and device/scripts/run_test_on_board.sh to our target &lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:17964331766201285693,headlineOfferDocid:12207024310313732767,productDocid:12207024310313732767&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgVEAM" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt; hardware.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Executed the device-side flow to generate nxp_prod_ka_puk.bin.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Transferred nxp_prod_ka_puk.bin back to our host environment.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Generated SRK keys (secp384r1) using the SPSDK utility according to the SPSDK Documentation since we do not have final production keys yet.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Generated the signed_msg.bin on the host side using the standard key import template (with the -k parameter set to secp384r1).&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Transferred the generated signed_msg.bin&lt;SPAN class=""&gt; to the &lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:17964331766201285693,headlineOfferDocid:12207024310313732767,productDocid:12207024310313732767&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgVEAk" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt; hardware.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Command used to generate signed message:&lt;BR /&gt;&lt;STRONG&gt;nxpimage signed-msg export -c key_exchange_temp.yaml -w assets&lt;/STRONG&gt;&lt;BR /&gt;Attached key_exchange_temp.yaml for reference.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;When running run_test_on_board.sh on the i.MX95 target device, all files are found, but the EdgeLock Enclave rejects the signature on the signed message block.Here is our target terminal log:&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;nxp_prod_ka_puk.bin exists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;oem_public_key.pem exists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;signed_msg.bin exists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Hello, World! Jul 16 2026:06:54:40 9547bbd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Signed Message: 728 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;02d802890200000000000000b8000000000000000000000000000000000000000000000000000000000000000000000000000000e6a7000000004701000000000000000000000000000000004707000000454c45090102090000000000920001010000000040000009010008000000000100000000000070577819deccdf2670d801e8f4291d3539081da49b1e1b63d55039e5993242b30f0000000000000000000000000000000000000000000000000000000000000000011c029000001000b40100000000000000a4015a01000000d7340143e14c00270102000030003000c2a99777d1fc00dc7e14d3d43ac3f68a44d9b52c882d3c09eac0db7fac1901242576bac6143785e5815db546e385d81000000000000000000000000000000000e14c00270102000030003000e358e1159c0cb645e7059c1b04b49e39b3563167472507278245d4dee439dd32e7ce3da413e397cbd7959cf147d25c2300000000000000000000000000000000e14c00270102000030003000482fb4f1ceb6e266221b0a13dbbb04c637a1c238b76b108397e98eb4557cafb2075036e05b9a0ee4fa6aa09a5f3951e500000000000000000000000000000000e14c00270102000030003000c93a6b4881ae912da31da8249e4f58473eb88cc1dc46f5ec6d363dc52b8a5c12c91e711ad726153d382dabbe6bef27cc000000000000000000000000000000000068005d00000000a5e31e11bfb02c62756d9d3ba5152768e5bea9aab8f3f13ccf3bd287a0438e9708088cafc5671e2aaf1bc3b413457b6a59a691dcef672fa65dac12ed328effac963c41ec0200b0a9acf67e0f2755f752872f77d2c20d6987f80e8008ac26de3d006800d800000000f4cf9cc965b3643d5dc5c5070a506196649daf898d328afd18e88eb9ece96e39646bf6385b9d42e1fc2f93f07f66e9c8c914becef9394c0c3cf549766483c7f94b6a9325bea51b79280eb76484e064637570c0ef7387ec0ffb8398ec36966c3a00000000&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;OEM Import PUK: 65 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;0451c46d24d30864c5275c634a3a339949654b34c0a4f294a8c107c504360ff4b55044918b71b16109a7bbfba8fbcf49b91720ad8e9c0109e6b2eed8f6a504ab64&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;hsm_open_session success&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;hsm_open_key_store_service success&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;hsm_open_key_management_service success&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;SAB Error: SAB CMD [0x47] Resp [0x1829] - Invalid Signature in SIGNED message.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;hsm_key_exchange failed err:0xfe&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Key exchange failed: 254&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Any insight on resolving this signature verification issue for the i.MX95 would be greatly appreciated.&lt;/P&gt;Thanks,&lt;BR /&gt;Ankit Agrawal&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Fri, 14 Aug 2026 06:43:54 GMT</pubDate>
    <dc:creator>Ankit_Agrawal</dc:creator>
    <dc:date>2026-08-14T06:43:54Z</dc:date>
    <item>
      <title>i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405146#M246360</link>
      <description>&lt;DIV class=""&gt;&lt;STRONG&gt;Hi Team,&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;We are currently working on importing a private key to an &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:10454109626952377055,headlineOfferDocid:16942149593012699800,productDocid:16942149593012699800&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgPEAE" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; device following the guidelines in application note &lt;STRONG&gt;AN14898&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Environment &amp;amp; References:&lt;/STRONG&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Target Device:&lt;/STRONG&gt; &lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:10454109626952377055,headlineOfferDocid:16942149593012699800,productDocid:16942149593012699800&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgREAM" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Demo Application:&lt;/STRONG&gt; &lt;SPAN class=""&gt;&lt;A href="https://www.google.com/url?sa=i&amp;amp;source=web&amp;amp;rct=j&amp;amp;url=CAESUgHuR6pNa-EbAS1iH71iTgn4T9F2guNuMAxogsURan4yjzrB1gZSke31V576eb41E5BUnnTw7K4fpEpVcqz9ye_p14WDwPK3Sgo3P439I4b-1l0%3D&amp;amp;uoh=2&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQy_kOegYIAAgREAU&amp;amp;opi=89978449&amp;amp;cd&amp;amp;psig=AOvVaw0sojBqG5zQSjPkioZOx9Rr&amp;amp;ust=1786775774500000" target="_blank" rel="noopener"&gt;imx_sec_apps/imx-ele-apps&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;SPSDK Version:&lt;/STRONG&gt; Latest standard toolset&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Activities Completed So Far:&lt;/STRONG&gt;&lt;/DIV&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Installed Python, pip, and the SPSDK toolset.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Successfully built both the Host and Device applications.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Copied device/bin/ele_key_import and device/scripts/run_test_on_board.sh to our target &lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:17964331766201285693,headlineOfferDocid:12207024310313732767,productDocid:12207024310313732767&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgVEAM" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt; hardware.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Executed the device-side flow to generate nxp_prod_ka_puk.bin.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Transferred nxp_prod_ka_puk.bin back to our host environment.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Generated SRK keys (secp384r1) using the SPSDK utility according to the SPSDK Documentation since we do not have final production keys yet.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Generated the signed_msg.bin on the host side using the standard key import template (with the -k parameter set to secp384r1).&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Transferred the generated signed_msg.bin&lt;SPAN class=""&gt; to the &lt;SPAN&gt;&lt;A href="https://www.google.com/search?ibp=oshop&amp;amp;prds=pvt:hg,pvo:29,imageDocid:17964331766201285693,headlineOfferDocid:12207024310313732767,productDocid:12207024310313732767&amp;amp;q=product&amp;amp;sa=X&amp;amp;ved=2ahUKEwjCpfTLwJ-WAxW5m-EIHYlGM_cQxa4PegYIAAgVEAk" target="_blank" rel="noopener"&gt;i.MX95&lt;/A&gt;&lt;/SPAN&gt; hardware.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Command used to generate signed message:&lt;BR /&gt;&lt;STRONG&gt;nxpimage signed-msg export -c key_exchange_temp.yaml -w assets&lt;/STRONG&gt;&lt;BR /&gt;Attached key_exchange_temp.yaml for reference.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;When running run_test_on_board.sh on the i.MX95 target device, all files are found, but the EdgeLock Enclave rejects the signature on the signed message block.Here is our target terminal log:&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;nxp_prod_ka_puk.bin exists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;oem_public_key.pem exists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;signed_msg.bin exists.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Hello, World! Jul 16 2026:06:54:40 9547bbd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Signed Message: 728 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;02d802890200000000000000b8000000000000000000000000000000000000000000000000000000000000000000000000000000e6a7000000004701000000000000000000000000000000004707000000454c45090102090000000000920001010000000040000009010008000000000100000000000070577819deccdf2670d801e8f4291d3539081da49b1e1b63d55039e5993242b30f0000000000000000000000000000000000000000000000000000000000000000011c029000001000b40100000000000000a4015a01000000d7340143e14c00270102000030003000c2a99777d1fc00dc7e14d3d43ac3f68a44d9b52c882d3c09eac0db7fac1901242576bac6143785e5815db546e385d81000000000000000000000000000000000e14c00270102000030003000e358e1159c0cb645e7059c1b04b49e39b3563167472507278245d4dee439dd32e7ce3da413e397cbd7959cf147d25c2300000000000000000000000000000000e14c00270102000030003000482fb4f1ceb6e266221b0a13dbbb04c637a1c238b76b108397e98eb4557cafb2075036e05b9a0ee4fa6aa09a5f3951e500000000000000000000000000000000e14c00270102000030003000c93a6b4881ae912da31da8249e4f58473eb88cc1dc46f5ec6d363dc52b8a5c12c91e711ad726153d382dabbe6bef27cc000000000000000000000000000000000068005d00000000a5e31e11bfb02c62756d9d3ba5152768e5bea9aab8f3f13ccf3bd287a0438e9708088cafc5671e2aaf1bc3b413457b6a59a691dcef672fa65dac12ed328effac963c41ec0200b0a9acf67e0f2755f752872f77d2c20d6987f80e8008ac26de3d006800d800000000f4cf9cc965b3643d5dc5c5070a506196649daf898d328afd18e88eb9ece96e39646bf6385b9d42e1fc2f93f07f66e9c8c914becef9394c0c3cf549766483c7f94b6a9325bea51b79280eb76484e064637570c0ef7387ec0ffb8398ec36966c3a00000000&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;OEM Import PUK: 65 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;0451c46d24d30864c5275c634a3a339949654b34c0a4f294a8c107c504360ff4b55044918b71b16109a7bbfba8fbcf49b91720ad8e9c0109e6b2eed8f6a504ab64&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;hsm_open_session success&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;hsm_open_key_store_service success&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;hsm_open_key_management_service success&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;SAB Error: SAB CMD [0x47] Resp [0x1829] - Invalid Signature in SIGNED message.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;hsm_key_exchange failed err:0xfe&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Key exchange failed: 254&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Any insight on resolving this signature verification issue for the i.MX95 would be greatly appreciated.&lt;/P&gt;Thanks,&lt;BR /&gt;Ankit Agrawal&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 14 Aug 2026 06:43:54 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405146#M246360</guid>
      <dc:creator>Ankit_Agrawal</dc:creator>
      <dc:date>2026-08-14T06:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405172#M246363</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/265595"&gt;@Ankit_Agrawal&lt;/a&gt;,&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;Our internal team is reviewing your issue and will update you accordingly.&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;In the meantime, please review the case below, which is similar to the issue you are encountering.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;The suggested solution is to verify that the &lt;STRONG&gt;fuse_version&lt;/STRONG&gt; matches correctly.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.nxp.com/t5/i-MX-Processors/hsm-import-key-returns-with-0xF0-Bad-Signature/td-p/2163777" target="_blank" rel="noopener"&gt;https://community.nxp.com/t5/i-MX-Processors/hsm-import-key-returns-with-0xF0-Bad-Signature/td-p/2163777&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 08:38:30 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405172#M246363</guid>
      <dc:creator>Richard_Kim</dc:creator>
      <dc:date>2026-08-14T08:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405183#M246365</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/265595"&gt;@Ankit_Agrawal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering if you burn SRKH&amp;nbsp; after SRK generation.&amp;nbsp; for necessary sign.yaml file please check my attached file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please try below command (precondition is you should have flash.bin: bootloader of system) to generate SRKH.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;STRONG&gt;nxpimage ahab sign -c sign.yaml -b flash.bin -o flash_directsign.bin -fs outputs&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;output will be as below.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jessie_Lee_0-1786699088609.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/394634i183A58F59E3D03AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jessie_Lee_0-1786699088609.png" alt="Jessie_Lee_0-1786699088609.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Jessie_Lee_0-1786699088609.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and from the ouputs folder, you could see bcf file(ahab_oem0_srk0_hash_nxpele.bcf).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you could follow below fuse command&amp;nbsp; (index 128 ~143) that you need to fuse for SRKH.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# nxpele AHAB SRKH fuses programming script&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# Generated by SPSDK 3.4.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# Family: mimx9596, Revision: latest&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# Value: 0xCCC0605919B6400771CF88A002FB6BF27DFA9CE09BAD94516DD7E4D399369A8FF5A6A1A671809DF4A71A7CB208B4EDC009CDF3FF25EC074DECBBEE8300D5D44C&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# Description: SHA512 hash digest of hash of four SRK keys&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# Grouped register name: SRKH&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# OTP ID: OEM_SRKH0, Value: 0x5960C0CC&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;write-fuse --index 128 --data 0x5960C0CC&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH1, Value: 0x0740B619&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;write-fuse --index 129 --data 0x740B619&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH2, Value: 0xA088CF71&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 130 --data 0xA088CF71&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH3, Value: 0xF26BFB02&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 131 --data 0xF26BFB02&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH4, Value: 0xE09CFA7D&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 132 --data 0xE09CFA7D&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH5, Value: 0x5194AD9B&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 133 --data 0x5194AD9B&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH6, Value: 0xD3E4D76D&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 134 --data 0xD3E4D76D&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH7, Value: 0x8F9A3699&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 135 --data 0x8F9A3699&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH8, Value: 0xA6A1A6F5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 136 --data 0xA6A1A6F5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH9, Value: 0xF49D8071&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 137 --data 0xF49D8071&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH10, Value: 0xB27C1AA7&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 138 --data 0xB27C1AA7&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH11, Value: 0xC0EDB408&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 139 --data 0xC0EDB408&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH12, Value: 0xFFF3CD09&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 140 --data 0xFFF3CD09&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH13, Value: 0x4D07EC25&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 141 --data 0x4D07EC25&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH14, Value: 0x83EEBBEC&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 142 --data 0x83EEBBEC&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;# OTP ID: OEM_SRKH15, Value: 0x4CD4D500&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;write-fuse --index 143 --data 0x4CD4D500&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;you could use below command to burn SRKH&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;nxpele -f mimx9596 batch outputs\ahab_oem0_srk0_hash_nxpele.bcf&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you burn the SRKH already but failed with below invalid singing, please share the singed_message.bin to us.&amp;nbsp; with your SRKH (including srk output all).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 09:48:38 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2405183#M246365</guid>
      <dc:creator>Jessie_Lee</dc:creator>
      <dc:date>2026-08-14T09:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2408024#M246498</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/59403"&gt;@Jessie_Lee&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;BR /&gt;We have located the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;flash.bin&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file and are able to perform the necessary steps to generate the SRKH.&lt;BR /&gt;After generating the SRKH, we need to fuse it to the hardware. To perform the fuse operation, the hardware/board must be in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Fastboot mode&lt;/STRONG&gt;. Could you please help us switch the device to Fastboot mode?&lt;/P&gt;&lt;P&gt;While attempting to fuse the keys, we are encountering the following error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ankit_Agrawal_0-1787636692485.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/395273i5339C853FDF13C46/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ankit_Agrawal_0-1787636692485.png" alt="Ankit_Agrawal_0-1787636692485.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Ankit_Agrawal_0-1787636692485.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It appears that the device is not currently in Fastboot mode. Any guidance on how to enable Fastboot mode on the board would be greatly appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Thanks,&amp;nbsp;&lt;BR /&gt;Ankit&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 05:45:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2408024#M246498</guid>
      <dc:creator>Ankit_Agrawal</dc:creator>
      <dc:date>2026-08-25T05:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2408050#M246500</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/265595"&gt;@Ankit_Agrawal&lt;/a&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Please follow up below steps to burn SRK using SPSDK&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;STRONG&gt;step#1&lt;/STRONG&gt;. when you boot device, stop at u-boot console , run&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;u-boot=&amp;gt; fastboot 0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;STRONG&gt;step#2&lt;/STRONG&gt;.&amp;nbsp; In SPSDK console , you must there is no ahab events) using below command.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;nxpele -f mimx9596 get-events&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;STRONG&gt;step#3&lt;/STRONG&gt;. If there is no event,&amp;nbsp; you could burn SRK key now in SPSDK console.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN&gt;nxpele -f mimx9596 batch outputs\ahab_oem2_srk0_hash_nxpele.bcf&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN&gt;BRs&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN&gt;jessie&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 06:44:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2408050#M246500</guid>
      <dc:creator>Jessie_Lee</dc:creator>
      <dc:date>2026-08-25T06:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2412889#M246682</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/59403"&gt;@Jessie_Lee&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It is reported that things are not working as shown below. Is it possible to get some support?&lt;BR /&gt;--------------------------------------------------------------------------------------------------------------&lt;BR /&gt;However, when I execute the command to perform the fuse operation, I encounter the error below.&lt;BR /&gt;I tried resetting the hardware too, but I'm still facing the same issue. Do you have any ideas on why this might be happening?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rakhyoung_0-1789101296622.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/396261iB193BE3690252F57/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rakhyoung_0-1789101296622.png" alt="rakhyoung_0-1789101296622.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;rakhyoung_0-1789101296622.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/265595"&gt;@Ankit_Agrawal&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Feel free to provide additional explanation if necessary.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 04:38:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2412889#M246682</guid>
      <dc:creator>rakhyoung</dc:creator>
      <dc:date>2026-09-11T04:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: i.MX95: EdgeLock Enclave Key Import Error - SAB CMD [0x47] Resp [0x1829] (Invalid Signature)</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2413028#M246686</link>
      <description>&lt;P&gt;from&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/265595"&gt;@Ankit_Agrawal&lt;/a&gt;&amp;nbsp; , there was fastboot entering issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/232008"&gt;@rakhyoung&lt;/a&gt;&amp;nbsp; Do you mean you are also having issue to enter fastboot ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you try to&amp;nbsp; below command..? that I shared.. above?&amp;nbsp; what is error when you try to below fastboot 0 at uboot stage?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;STRONG&gt;step#1&lt;/STRONG&gt;. when you boot device, stop at u-boot console , run&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;u-boot=&amp;gt; fastboot 0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;BRs&lt;/P&gt;
&lt;P&gt;jessie&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 09:55:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/i-MX95-EdgeLock-Enclave-Key-Import-Error-SAB-CMD-0x47-Resp/m-p/2413028#M246686</guid>
      <dc:creator>Jessie_Lee</dc:creator>
      <dc:date>2026-09-11T09:55:18Z</dc:date>
    </item>
  </channel>
</rss>

