<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Signing firmware part by part in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647915#M98978</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U-boot can authenticate other additional parts of system, using&amp;nbsp;&lt;/P&gt;&lt;P&gt;authenticate_image function for it in the same manner as for&amp;nbsp; uImage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note: If this post answers your question, please click the Correct Answer &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Apr 2017 06:29:16 GMT</pubDate>
    <dc:creator>Yuri</dc:creator>
    <dc:date>2017-04-27T06:29:16Z</dc:date>
    <item>
      <title>Signing firmware part by part</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647914#M98977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am currently working on performing secure boot on imx6ul using habv4. In my system the firmware is separated in to two parts other than boot loader. One is with kernel+rootfs (Part A) and the other part contains some critical application services (Part B) provided by another party (it’s mounted as a separate partition to the OS). The idea is to bug fix or change one part and flash it to the system without touching or bothering about the other.&lt;/P&gt;&lt;P&gt;I followed the steps provided by nxp and successfully signed and verified the boot loader and the complete firmware part (Part A + Part B) without any HAB events.&lt;/P&gt;&lt;P&gt;But when signing kernel + rootfs + critical app part (Part A + Part B), since the all signatures information are given in a single csf file which is embedded in the final image, I will not be able to write the Part A (kernel+rootfs) or Part B (critical app part ) separately after changing one part. How can I sign two parts separately so I can update only the relevant part and respective signature?&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Pra&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 05:34:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647914#M98977</guid>
      <dc:creator>prashanweerasin</dc:creator>
      <dc:date>2017-04-27T05:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Signing firmware part by part</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647915#M98978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U-boot can authenticate other additional parts of system, using&amp;nbsp;&lt;/P&gt;&lt;P&gt;authenticate_image function for it in the same manner as for&amp;nbsp; uImage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note: If this post answers your question, please click the Correct Answer &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 06:29:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647915#M98978</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-04-27T06:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Signing firmware part by part</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647916#M98979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yuri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for replying me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understood correctly you are suggesting to invoke&amp;nbsp;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;authenticate_image function using&amp;nbsp;u-boot script. Is there any other way to automate this ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Pra.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 07:02:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647916#M98979</guid>
      <dc:creator>prashanweerasin</dc:creator>
      <dc:date>2017-04-27T07:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Signing firmware part by part</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647917#M98980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Pra !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I am afraid we do not have examples (automation technique) for &amp;nbsp;&lt;/P&gt;&lt;P&gt;using several signing parts with U-boot.&lt;/P&gt;&lt;P&gt;You should call &amp;nbsp;additional&amp;nbsp;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;authenticate_image function from U-boot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;Yuri.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 07:16:00 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Signing-firmware-part-by-part/m-p/647917#M98980</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-04-27T07:16:00Z</dc:date>
    </item>
  </channel>
</rss>

