<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: problems with cst-2.3.1</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501830#M81251</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry I forgot to include the log entries from how I answered the questions when I started the script. I did answer "no" when asked about using an existing CA key ( see below).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:33.543 2016] ./hab4_pki_tree.sh&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This script is a part of the Code signing tools for Freescale's&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; High Assurance Boot.&amp;nbsp; It generates a basic PKI tree.&amp;nbsp; The PKI&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tree consists of one or more Super Root Keys (SRK), with each&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SRK having two subordinate keys: &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + a Command Sequence File (CSF) key &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Image key. &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Additional keys can be added to the PKI tree but a separate &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; script is available for this.&amp;nbsp; This this script assumes openssl&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is installed on your system and is included in your search &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; path.&amp;nbsp; Finally, the private keys generated are password &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protectedwith the password provided by the file key_pass.txt.&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The format of the file is the password repeated twice:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; my_password&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; my_password&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All private keys in the PKI tree are in PKCS #8 format will be&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protected by the same password.&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016] Do you want to use an existing CA key (y/n)?:&amp;nbsp; n&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:45.850 2016] Enter key length in bits for PKI tree:&amp;nbsp; 4096&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:49.751 2016] Enter PKI tree duration (years):&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:52.233 2016] How many Super Root Keys should be generated?&amp;nbsp; 4&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:54.355 2016] Do you want the SRK certificates to have the CA flag set? (y/n)?:&amp;nbsp; y&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] +++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] + Generating CA key and certificate +&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] +++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] Generating a 4096 bit RSA private key&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] ...++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.707 2016] ................................................................................................................................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.831 2016] writing new private key to 'temp_ca.pem'&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.831 2016] -----&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.893 2016] &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jan 2016 14:24:25 GMT</pubDate>
    <dc:creator>julesg</dc:creator>
    <dc:date>2016-01-20T14:24:25Z</dc:date>
    <item>
      <title>problems with cst-2.3.1</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501828#M81249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I downloaded cst-2.3.1 from this website and have unpacked the file onto a system running Ubuntu 12.04.5 LTS 64-bit. I have created the key_pass.txt and serial files as directed but when I run the hab4_pki_tree.sh script I get the following errors (taken from a log file generated by the terminal client I am using):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tue Jan 19 15:05:59.893 2016] ++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.893 2016] + Generating SRK key and certificate 1 +&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.893 2016] ++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.893 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.909 2016] Generating RSA private key, 4096 bit long modulus&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.909 2016] ..........................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:00.236 2016] ..............................................................................................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.080 2016] e is 65537 (0x10001)&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.111 2016] Using configuration from ../ca/openssl.cnf&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.111 2016] unable to load CA private key&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.111 2016] 140363626993312:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:539:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] 140363626993312:error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 cipherfinal error:p12_decr.c:104:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] 140363626993312:error:2306A075:PKCS12 routines:PKCS12_item_decrypt_d2i:pkcs12 pbe crypt error:p12_decr.c:130:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] 140363626993312:error:0907B00D:PEM routines:PEM_READ_BIO_PRIVATEKEY:ASN1 lib:pem_pkey.c:132:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] Error opening Certificate ../crts/SRK1_sha256_4096_65537_v3_ca_crt.pem&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] 140265689716384:error:02001002:system library:fopen:No such file or directory:bss_file.c:398:fopen('../crts/SRK1_sha256_4096_65537_v3_ca_crt.pem','r')&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] 140265689716384:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.127 2016] unable to load certificate&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] ++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] + Generating CSF key and certificate 1 +&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] ++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] Generating RSA private key, 4096 bit long modulus&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:01.142 2016] ..................................................................................................................................................................................................................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.874 2016] ...++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.905 2016] e is 65537 (0x10001)&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] Using configuration from ../ca/openssl.cnf&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] unable to load CA private key&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] 139735995864736:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:539:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] 139735995864736:error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 cipherfinal error:p12_decr.c:104:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] 139735995864736:error:2306A075:PKCS12 routines:PKCS12_item_decrypt_d2i:pkcs12 pbe crypt error:p12_decr.c:130:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] 139735995864736:error:0907B00D:PEM routines:PEM_READ_BIO_PRIVATEKEY:ASN1 lib:pem_pkey.c:132:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] Error opening Certificate ../crts/CSF1_1_sha256_4096_65537_v3_usr_crt.pem&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] 140679265150624:error:02001002:system library:fopen:No such file or directory:bss_file.c:398:fopen('../crts/CSF1_1_sha256_4096_65537_v3_usr_crt.pem','r')&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] 140679265150624:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.936 2016] unable to load certificate&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.952 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.952 2016] ++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.952 2016] + Generating IMG key and certificate 1 +&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.952 2016] ++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.952 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.967 2016] Generating RSA private key, 4096 bit long modulus&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:02.967 2016] ........................................................................................................................................................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:04.253 2016] ....................................................................................................................................................................................................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.877 2016] e is 65537 (0x10001)&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.893 2016] Using configuration from ../ca/openssl.cnf&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.893 2016] unable to load CA private key&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] 140552183891616:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:539:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] 140552183891616:error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 cipherfinal error:p12_decr.c:104:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] 140552183891616:error:2306A075:PKCS12 routines:PKCS12_item_decrypt_d2i:pkcs12 pbe crypt error:p12_decr.c:130:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] 140552183891616:error:0907B00D:PEM routines:PEM_READ_BIO_PRIVATEKEY:ASN1 lib:pem_pkey.c:132:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] Error opening Certificate ../crts/IMG1_1_sha256_4096_65537_v3_usr_crt.pem&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] 140225580635808:error:02001002:system library:fopen:No such file or directory:bss_file.c:398:fopen('../crts/IMG1_1_sha256_4096_65537_v3_usr_crt.pem','r')&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] 140225580635808:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:06:05.908 2016] unable to load certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get similar errors for each SRK. Any idea what the problem could be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 20:22:53 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501828#M81249</guid>
      <dc:creator>julesg</dc:creator>
      <dc:date>2016-01-19T20:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: problems with cst-2.3.1</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501829#M81250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; From section 3.2.2 (Running the hab4_pki_tree script Example) of "HABCST_UG.pdf" :&lt;/P&gt;&lt;P&gt;"Run the hab4_pki_tree.sh script. The script will ask a series of questions:&lt;/P&gt;&lt;P&gt;— Do you want to use an existing CA key (y/n)?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try "Choose no here ...".&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2016 07:36:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501829#M81250</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2016-01-20T07:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: problems with cst-2.3.1</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501830#M81251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry I forgot to include the log entries from how I answered the questions when I started the script. I did answer "no" when asked about using an existing CA key ( see below).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:33.543 2016] ./hab4_pki_tree.sh&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This script is a part of the Code signing tools for Freescale's&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; High Assurance Boot.&amp;nbsp; It generates a basic PKI tree.&amp;nbsp; The PKI&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tree consists of one or more Super Root Keys (SRK), with each&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SRK having two subordinate keys: &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + a Command Sequence File (CSF) key &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Image key. &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Additional keys can be added to the PKI tree but a separate &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; script is available for this.&amp;nbsp; This this script assumes openssl&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is installed on your system and is included in your search &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; path.&amp;nbsp; Finally, the private keys generated are password &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protectedwith the password provided by the file key_pass.txt.&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The format of the file is the password repeated twice:&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; my_password&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; my_password&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All private keys in the PKI tree are in PKCS #8 format will be&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protected by the same password.&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:35.932 2016] Do you want to use an existing CA key (y/n)?:&amp;nbsp; n&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:45.850 2016] Enter key length in bits for PKI tree:&amp;nbsp; 4096&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:49.751 2016] Enter PKI tree duration (years):&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:52.233 2016] How many Super Root Keys should be generated?&amp;nbsp; 4&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:54.355 2016] Do you want the SRK certificates to have the CA flag set? (y/n)?:&amp;nbsp; y&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] +++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] + Generating CA key and certificate +&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] +++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] &lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] Generating a 4096 bit RSA private key&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.676 2016] ...++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:58.707 2016] ................................................................................................................................................++&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.831 2016] writing new private key to 'temp_ca.pem'&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.831 2016] -----&lt;/P&gt;&lt;P&gt;[Tue Jan 19 15:05:59.893 2016] &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2016 14:24:25 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501830#M81251</guid>
      <dc:creator>julesg</dc:creator>
      <dc:date>2016-01-20T14:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: problems with cst-2.3.1</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501831#M81252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps it makes sense to try under root (sudo).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jan 2016 04:24:07 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501831#M81252</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2016-01-21T04:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: problems with cst-2.3.1</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501832#M81253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried again but this time under root using sudo but I still get the same errors. It looks like it doesn't like the CA private key that was previously generated for some reason. Why would this happen?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2016 16:20:09 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501832#M81253</guid>
      <dc:creator>julesg</dc:creator>
      <dc:date>2016-01-28T16:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: problems with cst-2.3.1</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501833#M81254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Please look at comment of&amp;nbsp; &lt;SPAN class="tm7"&gt;Ben Foose&lt;/SPAN&gt; in the following thread&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.nxp.com/message/624469?et=watches.email.thread#comment-624469" title="https://community.freescale.com/message/624469?et=watches.email.thread#comment-624469"&gt;https://community.freescale.com/message/624469?et=watches.email.thread#comment-624469&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2016 08:00:39 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/problems-with-cst-2-3-1/m-p/501833#M81254</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2016-03-15T08:00:39Z</dc:date>
    </item>
  </channel>
</rss>

