<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>MCUXpresso Secure Provisioning ToolのトピックRe: KW45 Secure Boot with no private key</title>
    <link>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2379026#M727</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/176703"&gt;@marek-trmac&lt;/a&gt;&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;I was wondering if that is the only solution? In this way, I need to "force" the OEM to implement such a custom HTTP server.&lt;BR /&gt;I say that because the OEM already has a server where I can upload my binary file for signing it.&lt;BR /&gt;In general, can you confirm that the only way to enable Secure Boot in KW45 is to go through Secure Provisioning Tool?&lt;BR /&gt;Thank you very much.&lt;BR /&gt;Regards,&lt;BR /&gt;Alessandro&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jun 2026 12:02:42 GMT</pubDate>
    <dc:creator>alereale</dc:creator>
    <dc:date>2026-06-09T12:02:42Z</dc:date>
    <item>
      <title>KW45 Secure Boot with no private key</title>
      <link>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2378355#M724</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;is there a method for authenticating images signed by external PKI? Let me explain better my question.&lt;/P&gt;&lt;P&gt;I would like to enable secure boot by burning fuse CUST_PROD_OEMFW_AUTH_PUK with sha-256 of public key. I have the certificate with the public key provided by the OEM but I don't have the related private key because I am not the signer. I can only sign my plain test by external portal with a dedicated PKI and obtain ECDSA signature.&lt;/P&gt;&lt;P&gt;I was referring to the following image&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alereale_0-1780922974962.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/388239i291BFFBA56D152FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alereale_0-1780922974962.png" alt="alereale_0-1780922974962.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but, assuming that i can obtain the signature, how can I know the exact tbs? in particular the data contained in the vector table?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alereale_1-1780923016190.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/388240iCB4A0DE3F26766E3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alereale_1-1780923016190.png" alt="alereale_1-1780923016190.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope I have explained my question in a good way.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 12:52:06 GMT</pubDate>
      <guid>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2378355#M724</guid>
      <dc:creator>alereale</dc:creator>
      <dc:date>2026-06-08T12:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: KW45 Secure Boot with no private key</title>
      <link>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2378385#M725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/254451"&gt;@alereale&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible to configure external signature provider. It is documented here: &lt;A href="https://docs.mcuxpresso.nxp.com/secure/latest/07_generic_workflows.html#signature-provider-workflow" target="_self"&gt;Signature provider - Generic workflows — Secure Provisioning Tool 26.03&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Short story: You need to implement custom HTTP server providing the API for signing the application, the sample implementation of the server is provided as a source code.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 13:56:16 GMT</pubDate>
      <guid>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2378385#M725</guid>
      <dc:creator>marek-trmac</dc:creator>
      <dc:date>2026-06-08T13:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: KW45 Secure Boot with no private key</title>
      <link>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2378593#M726</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AN14670 EdgeLock 2GO Provisioning via SPSDK for MCUs&lt;/P&gt;&lt;P&gt;AN14624 EdgeLock 2GO Provisioning via Secure Provisioning Tool (SEC) for MCUs&lt;/P&gt;&lt;P&gt;AN14109 KW45 and K32W148 Secure Boot Using the SEC Tool&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 00:20:09 GMT</pubDate>
      <guid>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2378593#M726</guid>
      <dc:creator>db16122</dc:creator>
      <dc:date>2026-06-09T00:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: KW45 Secure Boot with no private key</title>
      <link>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2379026#M727</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/176703"&gt;@marek-trmac&lt;/a&gt;&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;I was wondering if that is the only solution? In this way, I need to "force" the OEM to implement such a custom HTTP server.&lt;BR /&gt;I say that because the OEM already has a server where I can upload my binary file for signing it.&lt;BR /&gt;In general, can you confirm that the only way to enable Secure Boot in KW45 is to go through Secure Provisioning Tool?&lt;BR /&gt;Thank you very much.&lt;BR /&gt;Regards,&lt;BR /&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 12:02:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/MCUXpresso-Secure-Provisioning/KW45-Secure-Boot-with-no-private-key/m-p/2379026#M727</guid>
      <dc:creator>alereale</dc:creator>
      <dc:date>2026-06-09T12:02:42Z</dc:date>
    </item>
  </channel>
</rss>

