<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RKTH in elftosb-gui  in LPC Microcontrollers</title>
    <link>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030479#M40116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RKTH is&amp;nbsp; 32 byte SHA-256 hash of SHA-256 hashes of up to four root public keys.Multiple root public keys are supported to allow for key revocation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_1.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/92342i72342CFD0349A528/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_1.png" alt="pastedImage_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You may review the information on&lt;A href="https://www.nxp.com/webapp/Download?colCode=UM11126"&gt; chapter 7 of the user manual&lt;/A&gt;&amp;nbsp;for the RKTH. Please let me know if you have further qustions.&lt;/P&gt;&lt;P&gt;For the "Seal security configuration" checkbox, I will confirm this information and update you as soon as possible.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Sabina&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Nov 2019 21:38:47 GMT</pubDate>
    <dc:creator>Sabina_Bruce</dc:creator>
    <dc:date>2019-11-14T21:38:47Z</dc:date>
    <item>
      <title>RKTH in elftosb-gui</title>
      <link>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030478#M40115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;I have some questions about cmpa and elftosb-gui tool&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;what is RKTH input in elftosb-gui-&amp;gt;device-&amp;gt;security tab? it is the value of ROTKH[...] in CMPA area? And how to write up to 4 ROTKH in CMPA?&lt;/P&gt;&lt;P&gt;2. what if&amp;nbsp; i uncheck "!!Seal security configuration!!" when i process the data?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Charles&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2019 06:15:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030478#M40115</guid>
      <dc:creator>binjun-charles_</dc:creator>
      <dc:date>2019-11-11T06:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: RKTH in elftosb-gui</title>
      <link>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030479#M40116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RKTH is&amp;nbsp; 32 byte SHA-256 hash of SHA-256 hashes of up to four root public keys.Multiple root public keys are supported to allow for key revocation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_1.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/92342i72342CFD0349A528/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_1.png" alt="pastedImage_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You may review the information on&lt;A href="https://www.nxp.com/webapp/Download?colCode=UM11126"&gt; chapter 7 of the user manual&lt;/A&gt;&amp;nbsp;for the RKTH. Please let me know if you have further qustions.&lt;/P&gt;&lt;P&gt;For the "Seal security configuration" checkbox, I will confirm this information and update you as soon as possible.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Sabina&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2019 21:38:47 GMT</pubDate>
      <guid>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030479#M40116</guid>
      <dc:creator>Sabina_Bruce</dc:creator>
      <dc:date>2019-11-14T21:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: RKTH in elftosb-gui</title>
      <link>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030480#M40117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sabina&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i understood it is the hash value of RKH table in signed image.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a further question about up to 4 certificates supported in the LPC55xx.&amp;nbsp; Assuming that i used 4 certificates which are the certificate chain. My understanding is the first one is Root certificate and then intermediate certificates, the last one is end certificate for signing image. When verifying the image, bootloader will go through all the certificates to check if image is authorized. My question is about certificate revocation. In my case, four certificates are&amp;nbsp;&lt;EM style="color: #999999; background-color: #ffffff; font-weight: normal; font-size: 13.600001335144043px;"&gt;&lt;SPAN class=""&gt;&lt;A data-keyword="an" style="color: #2b77c5; font-weight: bold; text-decoration: none;"&gt;an&lt;/A&gt; &lt;A data-keyword="integral" style="color: #2b77c5; font-weight: bold; text-decoration: none;"&gt;integral&lt;/A&gt; &lt;A data-keyword="whole" style="color: #2b77c5; font-weight: bold; text-decoration: none;"&gt;whole of trust.&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN class=""&gt;&lt;A data-keyword="whole" style="color: #2b77c5; font-weight: bold; text-decoration: none;"&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400;"&gt;&lt;SPAN&gt;Any of&amp;nbsp;&lt;SPAN&gt;certificates is revoked&amp;nbsp; means image will not pass verification.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A data-keyword="whole" style="color: #2b77c5; font-weight: bold; text-decoration: none;"&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400;"&gt;&lt;STRONG&gt; Is it right? And why can we select which certificate is revoked in CFPA area?.&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400; "&gt;&lt;STRONG&gt;And are there any documents about the detailed logic of how to verify the image using certificates in bootloader?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400; "&gt;Thank you in advance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Charles&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2019 05:59:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030480#M40117</guid>
      <dc:creator>binjun-charles_</dc:creator>
      <dc:date>2019-11-20T05:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: RKTH in elftosb-gui</title>
      <link>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030481#M40118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Charles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;Root of Trust key is a key managed by owner of key and this hash is written in PFR (like OTP). During booting ROM will authenticate certificates chain in image. 4 RoT keys are there for revocation possibility. Each RoT is also possible to revocate through serial numbers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;I believe the following two documents will help clarify the use of the above information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;&lt;A href="https://www.nxp.com/docs/en/application-note/AN12283.pdf"&gt;LPC55Sxx Secure Boot AN12283&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;&lt;A href="https://www.nxp.com/docs/en/application-note/AN12278.pdf"&gt;LPC55S69 Security Solutions for IoT AN12278&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;Please let me know if you have further questions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #51626f; background-color: #ffffff;"&gt;Sabina&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Nov 2019 04:30:49 GMT</pubDate>
      <guid>https://community.nxp.com/t5/LPC-Microcontrollers/RKTH-in-elftosb-gui/m-p/1030481#M40118</guid>
      <dc:creator>Sabina_Bruce</dc:creator>
      <dc:date>2019-11-24T04:30:49Z</dc:date>
    </item>
  </channel>
</rss>

