<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: secure boot on the imx6ul using HABv4</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/secure-boot-on-the-imx6ul-using-HABv4/m-p/540821#M85324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, but the information you are requesting is treated as confidential info at this time and requires a signed NDA (Non-Disclosure Agreement). Naturally, we cannot discuss this with you in public anyway, this requires to be handled as a CASE. Be aware that to give you remote support through a CASE, we will still need the confirmation of a NXP employee that the NDA is in place. If you want to go this route, the next steps will be: If you have already signed a NDA agreement for this product, please contact the person who assisted you or create a SR and name us a NXP person that can confirm this. If you have not signed an agreement, please contact your local NXP Distributor Salesperson or FAE for assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Jaime&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Oct 2016 15:15:42 GMT</pubDate>
    <dc:creator>jamesbone</dc:creator>
    <dc:date>2016-10-04T15:15:42Z</dc:date>
    <item>
      <title>secure boot on the imx6ul using HABv4</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/secure-boot-on-the-imx6ul-using-HABv4/m-p/540820#M85323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am trying to perform a secure boot on the imx6ul using HABv4. I performed all the steps described below and I &lt;STRONG&gt;did not fuse the SRK table&lt;/STRONG&gt;. When I type hab_status in the U-boot command prompt, I get the HAB Events I have listed below.&lt;/P&gt;&lt;P&gt;So I would like to know, if not fusing the SRK table could be the reason for these events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps Performed:&lt;/P&gt;&lt;P&gt;Please see the steps performed below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Built u-boot.imx enabling the secure mode.&lt;/P&gt;&lt;P&gt;2. Generated all root public key files and corresponding hash.&lt;/P&gt;&lt;P&gt;3. Created csf file with the following content. Content of the file is listed at the end.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; My u-uboot.imx file is 0x55830. I extended it to 0x56000 using the following command.&lt;/P&gt;&lt;P&gt;objcopy -I binary -O binary --pad-to 0x656000 --gap-fill=0x5A u-boot.imx u-boot-pad.imx&lt;/P&gt;&lt;P&gt;5. Then I generated csf.bin file using the command below.&lt;/P&gt;&lt;P&gt;./cst -o u-boot_csf.bin -i uboot.csf&lt;/P&gt;&lt;P&gt;6. Merged image and csf data using the command below.&lt;/P&gt;&lt;P&gt;cat u-boot-pad.imx u-boot_csf.bin&amp;nbsp; &amp;gt; u-boot-signed.imx&lt;/P&gt;&lt;P&gt;7. Then extended the final image to 0x57000&lt;/P&gt;&lt;P&gt;objcopy -I binary -O binary --pad-to 0x57000 --gap-fill=0x5A u-boot-signed.imx u-boot-signed-pad.imx&lt;/P&gt;&lt;P&gt;8. The length of the block is calculated as: Length = u-boot-pad.imx (0x57000) - IVT_OFFSET (0x400).&lt;/P&gt;&lt;P&gt;And added 400 to the starting address as shown below.&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Address&amp;nbsp;&amp;nbsp;&amp;nbsp; Offset Length Data File Path&lt;/P&gt;&lt;P&gt;Blocks = 0x87800400 0x400 0x00055C00 "u-boot-pad.imx"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HAB Events:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secure boot disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HAB Configuration: 0xf0, HAB State: 0x66&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- HAB Event 1 -----------------&lt;/P&gt;&lt;P&gt;event data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xdb 0x00 0x1c 0x42 0x33 0x18 0xc0 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xca 0x00 0x14 0x00 0x02 0xc5 0x00 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x0d 0x34 0x87 0x80 0x04 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x05 0x5c 0x00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- HAB Event 2 -----------------&lt;/P&gt;&lt;P&gt;event data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xdb 0x00 0x14 0x42 0x33 0x0c 0xa0 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x00 0x87 0x7f 0xf7 0xd0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- HAB Event 3 -----------------&lt;/P&gt;&lt;P&gt;event data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xdb 0x00 0x14 0x42 0x33 0x0c 0xa0 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x00 0x87 0x7f 0xf7 0xfc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x01 0xf0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- HAB Event 4 -----------------&lt;/P&gt;&lt;P&gt;event data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xdb 0x00 0x14 0x42 0x33 0x0c 0xa0 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x00 0x87 0x7f 0xf7 0xf0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- HAB Event 5 -----------------&lt;/P&gt;&lt;P&gt;event data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xdb 0x00 0x14 0x42 0x33 0x0c 0xa0 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x00 0x87 0x80 0x00 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x00 0x04&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Command Sequency File Description:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Header]&lt;/P&gt;&lt;P&gt;Version = 4.0&lt;/P&gt;&lt;P&gt;Security Configuration = Open&lt;/P&gt;&lt;P&gt;Hash Algorithm = sha256&lt;/P&gt;&lt;P&gt;Engine Configuration = 0&lt;/P&gt;&lt;P&gt;Certificate Format = X509&lt;/P&gt;&lt;P&gt;Signature Format = CMS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;/P&gt;&lt;P&gt;File = "../crts/SRK_1_2_3_4_table.bin"&lt;/P&gt;&lt;P&gt;Source index = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;/P&gt;&lt;P&gt;File = "../crts/CSF1_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Key]&lt;/P&gt;&lt;P&gt;Verification index = 0&lt;/P&gt;&lt;P&gt;Target index = 2&lt;/P&gt;&lt;P&gt;File = "../crts/IMG1_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# Sign padded u-boot starting at the IVT through to the end with&lt;/P&gt;&lt;P&gt;# length = 0x2F000 (padded u-boot length) - 0x400 (IVT offset) = 0x2EC00&lt;/P&gt;&lt;P&gt;# This covers the essential parts: IVT, boot data and DCD.&lt;/P&gt;&lt;P&gt;# Blocks have the following definition:&lt;/P&gt;&lt;P&gt;# Image block start address on i.MX, Offset from start of image file,&lt;/P&gt;&lt;P&gt;# Length of block in bytes, image data file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;Verification index = 2&lt;/P&gt;&lt;P&gt;Blocks = 0x87800400 0x400 0x55C00 "u-boot-pad.imx"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2016 12:52:22 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/secure-boot-on-the-imx6ul-using-HABv4/m-p/540820#M85323</guid>
      <dc:creator>dhanushkadangam</dc:creator>
      <dc:date>2016-07-26T12:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: secure boot on the imx6ul using HABv4</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/secure-boot-on-the-imx6ul-using-HABv4/m-p/540821#M85324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, but the information you are requesting is treated as confidential info at this time and requires a signed NDA (Non-Disclosure Agreement). Naturally, we cannot discuss this with you in public anyway, this requires to be handled as a CASE. Be aware that to give you remote support through a CASE, we will still need the confirmation of a NXP employee that the NDA is in place. If you want to go this route, the next steps will be: If you have already signed a NDA agreement for this product, please contact the person who assisted you or create a SR and name us a NXP person that can confirm this. If you have not signed an agreement, please contact your local NXP Distributor Salesperson or FAE for assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Jaime&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Oct 2016 15:15:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/secure-boot-on-the-imx6ul-using-HABv4/m-p/540821#M85324</guid>
      <dc:creator>jamesbone</dc:creator>
      <dc:date>2016-10-04T15:15:42Z</dc:date>
    </item>
  </channel>
</rss>

