Code Signing Tool with a Hardware Security Module

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

Code Signing Tool with a Hardware Security Module

跳至解决方案
264 次查看
endrunner_smw
Contributor III

I am aware that there are multiple versions of the code signing tool from different locations.

I currently am using the CST located at github.com/nxp-qoriq/cst. This appears to be version 2.0 and matches what documentation I seem to come across. I have also seen versions in the 3.* range as well as a 4.* version. From postings on the forums it seems these version 3 and 4 versions of CST can support a HSM through some configuration changes.

However, I can't seem to find an equivalent for CST 2.0? Can CST 2.0 utilize a HSM? If yes what steps would be required, if no, then can other versions of CST be used as drop in replacements?

I also noticed that the latest CST 4 doesn't appear to have actual source code available, or am I just looking in the wrong place? The precompiled binaries are only available for x86_64, but I'm developing natively on the LS1043A aarch64, so the precompiled binaries are obviously not an option. I don't mind building a different version, I just need to know where the source is and if there are any compatibility issues to be aware of?

Thank you for your time.

标记 (3)
0 项奖励
回复
1 解答
191 次查看
Bio_TICFSL
NXP TechSupport
NXP TechSupport

Hello,

CST 2.0 does not have documented native HSM/PKCSsupport; for Layerscape the supported path is detached external signing with --img_hash plus sign_embedding , while i.MX CST 3.x/newer adds HSM features but is not verified as a drop-in replacement for QorIQ CST 2.0.

 

Regards

在原帖中查看解决方案

0 项奖励
回复
1 回复
192 次查看
Bio_TICFSL
NXP TechSupport
NXP TechSupport

Hello,

CST 2.0 does not have documented native HSM/PKCSsupport; for Layerscape the supported path is detached external signing with --img_hash plus sign_embedding , while i.MX CST 3.x/newer adds HSM features but is not verified as a drop-in replacement for QorIQ CST 2.0.

 

Regards

0 项奖励
回复
%3CLINGO-SUB%20id%3D%22lingo-sub-2358847%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%B8%A6%E6%9C%89%E7%A1%AC%E4%BB%B6%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E6%A8%A1%E5%9D%97%E7%9A%84%E4%BB%A3%E7%A0%81%E7%AD%BE%E5%90%8D%E5%B7%A5%E5%85%B7%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2358847%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E6%88%91%E7%9F%A5%E9%81%93%E4%B8%8D%E5%90%8C%E5%9C%B0%E7%82%B9%E6%9C%89%E5%A4%9A%E4%B8%AA%E7%89%88%E6%9C%AC%E7%9A%84%E4%BB%A3%E7%A0%81%E7%AD%BE%E5%90%8D%E5%B7%A5%E5%85%B7%E3%80%82%3C%2FP%3E%3CP%3E%E6%88%91%E7%9B%AE%E5%89%8D%E4%BD%BF%E7%94%A8%E7%9A%84%E6%98%AF%E4%BD%8D%E4%BA%8E%20github.com%2Fnxp-qoriq%2Fcst%20%E7%9A%84%20CST%E3%80%82%E8%BF%99%E4%BC%BC%E4%B9%8E%E6%98%AF%202.0%20%E7%89%88%EF%BC%8C%E4%B8%8E%E6%88%91%E6%89%80%E7%9C%8B%E5%88%B0%E7%9A%84%E6%96%87%E6%A1%A3%E7%9B%B8%E7%AC%A6%E3%80%82%E6%88%91%E8%BF%98%E7%9C%8B%E5%88%B0%E8%BF%87%203.*%20%E8%8C%83%E5%9B%B4%E5%86%85%E7%9A%84%E7%89%88%E6%9C%AC%E4%BB%A5%E5%8F%8A%204.*%20%E7%89%88%E6%9C%AC%E3%80%82%E4%BB%8E%E8%AE%BA%E5%9D%9B%E4%B8%8A%E7%9A%84%E5%B8%96%E5%AD%90%E6%9D%A5%E7%9C%8B%EF%BC%8CCST%20%E7%9A%84%E7%AC%AC%203%20%E7%89%88%E5%92%8C%E7%AC%AC%204%20%E7%89%88%E4%BC%BC%E4%B9%8E%E5%8F%AF%E4%BB%A5%E9%80%9A%E8%BF%87%E6%9B%B4%E6%94%B9%E4%B8%80%E4%BA%9B%E9%85%8D%E7%BD%AE%E6%9D%A5%E6%94%AF%E6%8C%81%20HSM%E3%80%82%3C%2FP%3E%3CP%3E%E4%BD%86%E6%98%AF%EF%BC%8C%E6%88%91%E4%BC%BC%E4%B9%8E%E6%89%BE%E4%B8%8D%E5%88%B0%20CST%202.0%20%E7%9A%84%E7%9B%B8%E5%BA%94%E7%89%88%E6%9C%AC%EF%BC%9FCST%202.0%20%E5%8F%AF%E4%BB%A5%E4%BD%BF%E7%94%A8%20HSM%20%E5%90%97%EF%BC%9F%E5%A6%82%E6%9E%9C%E5%8F%AF%E4%BB%A5%EF%BC%8C%E9%9C%80%E8%A6%81%E9%87%87%E5%8F%96%E4%BB%80%E4%B9%88%E6%AD%A5%E9%AA%A4%EF%BC%9B%E5%A6%82%E6%9E%9C%E4%B8%8D%E5%8F%AF%E4%BB%A5%EF%BC%8C%E9%82%A3%E4%B9%88%E6%98%AF%E5%90%A6%E5%8F%AF%E4%BB%A5%E4%BD%BF%E7%94%A8%E5%85%B6%E4%BB%96%E7%89%88%E6%9C%AC%E7%9A%84%20CST%20%E6%9D%A5%E6%9B%BF%E4%BB%A3%EF%BC%9F%3C%2FP%3E%3CP%3E%E6%88%91%E8%BF%98%E6%B3%A8%E6%84%8F%E5%88%B0%E6%9C%80%E6%96%B0%E7%9A%84%20CST%204%20%E4%BC%BC%E4%B9%8E%E6%B2%A1%E6%9C%89%E5%AE%9E%E9%99%85%E7%9A%84%E6%BA%90%E4%BB%A3%E7%A0%81%EF%BC%8C%E8%BF%98%E6%98%AF%E6%88%91%E6%89%BE%E9%94%99%E4%BA%86%E5%9C%B0%E6%96%B9%EF%BC%9F%E9%A2%84%E7%BC%96%E8%AF%91%E7%9A%84%E4%BA%8C%E8%BF%9B%E5%88%B6%E6%96%87%E4%BB%B6%E4%BB%85%E9%80%82%E7%94%A8%E4%BA%8E%20x86_64%EF%BC%8C%E4%BD%86%E6%88%91%E6%AD%A3%E5%9C%A8%20LS1043A%20aarch64%20%E4%B8%8A%E8%BF%9B%E8%A1%8C%E6%9C%AC%E5%9C%B0%E5%BC%80%E5%8F%91%EF%BC%8C%E5%9B%A0%E6%AD%A4%E9%A2%84%E7%BC%96%E8%AF%91%E7%9A%84%E4%BA%8C%E8%BF%9B%E5%88%B6%E6%96%87%E4%BB%B6%E6%98%BE%E7%84%B6%E4%B8%8D%E6%98%AF%E4%B8%80%E4%B8%AA%E9%80%89%E9%A1%B9%E3%80%82%E6%88%91%E4%B8%8D%E4%BB%8B%E6%84%8F%E6%9E%84%E5%BB%BA%E4%B8%80%E4%B8%AA%E4%B8%8D%E5%90%8C%E7%9A%84%E7%89%88%E6%9C%AC%EF%BC%8C%E6%88%91%E5%8F%AA%E6%83%B3%E7%9F%A5%E9%81%93%E6%BA%90%E4%BB%A3%E7%A0%81%E5%9C%A8%E5%93%AA%E9%87%8C%EF%BC%8C%E6%98%AF%E5%90%A6%E6%9C%89%E4%BB%BB%E4%BD%95%E9%9C%80%E8%A6%81%E6%B3%A8%E6%84%8F%E7%9A%84%E5%85%BC%E5%AE%B9%E6%80%A7%E9%97%AE%E9%A2%98%EF%BC%9F%3C%2FP%3E%3CP%3E%E6%84%9F%E8%B0%A2%E6%82%A8%E6%8A%BD%E5%87%BA%E5%AE%9D%E8%B4%B5%E6%97%B6%E9%97%B4%E3%80%82%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2359491%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Code%20Signing%20Tool%20with%20a%20Hardware%20Security%20Module%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2359491%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E4%BD%A0%E5%A5%BD%3C%2FP%3E%0A%3CP%3ECST%202.0%20%E4%B8%8D%E6%94%AF%E6%8C%81%E6%9C%AC%E5%9C%B0%20HSM%2FPKCS%EF%BC%9B%E5%AF%B9%E4%BA%8E%20Layerscape%EF%BC%8C%E6%94%AF%E6%8C%81%E7%9A%84%E8%B7%AF%E5%BE%84%E6%98%AF%E4%BD%BF%E7%94%A8%3CCODE%20class%3D%22%22%3E--img_hash%3C%2FCODE%3E%E5%8A%A0%E4%B8%8A%3CCODE%20class%3D%22%22%3Esign_embedding%3C%2FCODE%3E%E8%BF%9B%E8%A1%8C%E5%88%86%E7%A6%BB%E5%BC%8F%E5%A4%96%E9%83%A8%E7%AD%BE%E5%90%8D%EF%BC%8C%E8%80%8C%20i.MX%20CST%203.x%2Fnewer%20%E5%A2%9E%E5%8A%A0%E4%BA%86%20HSM%20%E5%8A%9F%E8%83%BD%EF%BC%8C%E4%BD%86%E6%9C%AA%E7%BB%8F%E9%AA%8C%E8%AF%81%E5%8F%AF%E7%9B%B4%E6%8E%A5%E6%9B%BF%E4%BB%A3%20QorIQ%20CST%202.0%E3%80%82%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%E6%AD%A4%E8%87%B4%3C%2FP%3E%3C%2FLINGO-BODY%3E