<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: High Assurance Boot Certificate Validity</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286884#M33938</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, if the validity period of the certificate expires nothing will happen.&amp;nbsp; The ROM/HAB does not enforce certificate validity periods and the Code Signing Tool will still allow code to be signed.&amp;nbsp; The intent is to enforce the cert validity periods with the code signing tool.&amp;nbsp; However, feature has not yet been added and is planned as an update to the code signing tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Rod&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Jun 2013 22:46:25 GMT</pubDate>
    <dc:creator>rodz</dc:creator>
    <dc:date>2013-06-11T22:46:25Z</dc:date>
    <item>
      <title>High Assurance Boot Certificate Validity</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286883#M33937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I work on a Freescale i.mx28 and I use High Assurance Boot (HAB).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When creating certificates with the "hab4_pki_tree.sh" script, which is provided with the Code Signing Tool, I can enter a certificate validity duration of max. 20 years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens after 20 year? Does the i.mx28 not boot anymore? Am I not able to sign software anymore? Or do I have to add new CSF and IMG certificates to sign software with them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are: Who checks the certificate duration and when? Which certificates have a limited duration (I assume the root-certificate has unlimited duration)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 13:13:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286883#M33937</guid>
      <dc:creator>christopherpres</dc:creator>
      <dc:date>2013-06-11T13:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: High Assurance Boot Certificate Validity</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286884#M33938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, if the validity period of the certificate expires nothing will happen.&amp;nbsp; The ROM/HAB does not enforce certificate validity periods and the Code Signing Tool will still allow code to be signed.&amp;nbsp; The intent is to enforce the cert validity periods with the code signing tool.&amp;nbsp; However, feature has not yet been added and is planned as an update to the code signing tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Rod&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 22:46:25 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286884#M33938</guid>
      <dc:creator>rodz</dc:creator>
      <dc:date>2013-06-11T22:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: High Assurance Boot Certificate Validity</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286885#M33939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rod,&lt;/P&gt;&lt;P&gt;Any update on the certificate expiry and certificate revocation and if the fuses can be revoked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2016 08:47:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/High-Assurance-Boot-Certificate-Validity/m-p/286885#M33939</guid>
      <dc:creator>gurukottur</dc:creator>
      <dc:date>2016-10-20T08:47:23Z</dc:date>
    </item>
  </channel>
</rss>

