<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>K32 L Series MicrocontrollersのトピックHow to Enable Secure Boot on K32L3A</title>
    <link>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1861832#M176</link>
    <description>&lt;P&gt;I'm trying to implement secure boot on my project. I'm using the K32L3A and using BLhost to write the IFR's. I seem to have all other functions working&amp;nbsp;&lt;EM&gt;except&amp;nbsp;&lt;/EM&gt;secure boot. For simplicity of testing, I'm putting an unsigned image and not programming the RKTH onto the part. I would like to see it&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; boot&amp;nbsp;when I enable secure boot. My process is as follows.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Enable secure boot&lt;OL&gt;&lt;LI&gt;The command I use is: ./blhost --spi &amp;lt;mysettings&amp;gt; --noping -- flash-program-once 0x98 8 FFFFFF00FFFFFF00&lt;/LI&gt;&lt;LI&gt;According to this &lt;A href="https://community.nxp.com/t5/Kinetis-Microcontrollers/Programming-the-K32L3A-MCU-Flash-IFR-Fields/ta-p/1127171" target="_self"&gt;article&lt;/A&gt;&amp;nbsp;each bit in the IFR is mapped to a CCOB register and the register should be written with a 0xFF for b'1 and 0x00 for b'0. I should be writing 11101110 to the register, which according to the documentation is:&lt;UL&gt;&lt;LI&gt;secure boot enabled.&lt;/LI&gt;&lt;LI&gt;secure boot development mode disabled&lt;/LI&gt;&lt;LI&gt;if secure boot fails, go to bootloader mode.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jraczak_0-1715198758152.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277809iA0C882FF731FCC87/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jraczak_0-1715198758152.png" alt="jraczak_0-1715198758152.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Enable Flash security.&lt;OL&gt;&lt;LI&gt;The command I use is: ./blhost --spi&amp;nbsp; &amp;lt;mysettings&amp;gt; --noping -- flash-program-once 0x80 4 FFFFFFFF&lt;/LI&gt;&lt;LI&gt;I'm very confident this command works because any subsequent BLHost commands get a response of "security must be disabled".&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon reset, the unsigned image boots, meaning secure boot is not active. I can't find any examples of how to enable secure boot and based on the user guide, these seemed to be the only two&amp;nbsp;&lt;EM&gt;necessary&lt;/EM&gt; steps. Any help is appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2024 20:11:34 GMT</pubDate>
    <dc:creator>jraczak</dc:creator>
    <dc:date>2024-05-08T20:11:34Z</dc:date>
    <item>
      <title>How to Enable Secure Boot on K32L3A</title>
      <link>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1861832#M176</link>
      <description>&lt;P&gt;I'm trying to implement secure boot on my project. I'm using the K32L3A and using BLhost to write the IFR's. I seem to have all other functions working&amp;nbsp;&lt;EM&gt;except&amp;nbsp;&lt;/EM&gt;secure boot. For simplicity of testing, I'm putting an unsigned image and not programming the RKTH onto the part. I would like to see it&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; boot&amp;nbsp;when I enable secure boot. My process is as follows.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Enable secure boot&lt;OL&gt;&lt;LI&gt;The command I use is: ./blhost --spi &amp;lt;mysettings&amp;gt; --noping -- flash-program-once 0x98 8 FFFFFF00FFFFFF00&lt;/LI&gt;&lt;LI&gt;According to this &lt;A href="https://community.nxp.com/t5/Kinetis-Microcontrollers/Programming-the-K32L3A-MCU-Flash-IFR-Fields/ta-p/1127171" target="_self"&gt;article&lt;/A&gt;&amp;nbsp;each bit in the IFR is mapped to a CCOB register and the register should be written with a 0xFF for b'1 and 0x00 for b'0. I should be writing 11101110 to the register, which according to the documentation is:&lt;UL&gt;&lt;LI&gt;secure boot enabled.&lt;/LI&gt;&lt;LI&gt;secure boot development mode disabled&lt;/LI&gt;&lt;LI&gt;if secure boot fails, go to bootloader mode.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jraczak_0-1715198758152.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277809iA0C882FF731FCC87/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jraczak_0-1715198758152.png" alt="jraczak_0-1715198758152.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Enable Flash security.&lt;OL&gt;&lt;LI&gt;The command I use is: ./blhost --spi&amp;nbsp; &amp;lt;mysettings&amp;gt; --noping -- flash-program-once 0x80 4 FFFFFFFF&lt;/LI&gt;&lt;LI&gt;I'm very confident this command works because any subsequent BLHost commands get a response of "security must be disabled".&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon reset, the unsigned image boots, meaning secure boot is not active. I can't find any examples of how to enable secure boot and based on the user guide, these seemed to be the only two&amp;nbsp;&lt;EM&gt;necessary&lt;/EM&gt; steps. Any help is appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 20:11:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1861832#M176</guid>
      <dc:creator>jraczak</dc:creator>
      <dc:date>2024-05-08T20:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable Secure Boot on K32L3A</title>
      <link>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1863478#M177</link>
      <description>Is there any Endian byte swapping going on? That would not be apparent in writing all 0xFFs, it would in real data.&lt;BR /&gt;&lt;BR /&gt;M0+ are Little Endian.</description>
      <pubDate>Fri, 10 May 2024 12:46:38 GMT</pubDate>
      <guid>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1863478#M177</guid>
      <dc:creator>bobpaddock</dc:creator>
      <dc:date>2024-05-10T12:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable Secure Boot on K32L3A</title>
      <link>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1866669#M184</link>
      <description>&lt;P&gt;I was able to solve the issue. 0xFF and 0x00 only maps to logic 1's and 0's for some of the IFR's. It turns out, I just had to use &lt;SPAN&gt;./blhost --spi &amp;lt;mysettings&amp;gt; --noping -- flash-program-once 0x98 8 FFFFFFFFFFFFFFE1 to get my desired setting.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 01:36:54 GMT</pubDate>
      <guid>https://community.nxp.com/t5/K32-L-Series-Microcontrollers/How-to-Enable-Secure-Boot-on-K32L3A/m-p/1866669#M184</guid>
      <dc:creator>jraczak</dc:creator>
      <dc:date>2024-05-16T01:36:54Z</dc:date>
    </item>
  </channel>
</rss>

