Secure Debug on ls1028a

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Secure Debug on ls1028a

1,550 Views
tomzy_0
Contributor I

Hi,

I want to test Secure Debug on a ls1028a based custom board. For now, I performed following steps:

1. Fuse registers using fuse_fip and the following input_fuse_file

/*
* Copyright 2018 NXP
*/

---------------------------------------------------
PLATFORM=LS1028
---------------------------------------------------
POVDD_GPIO=
---------------------------------------------------
OTPMK_FLAGS=0010
OTPMK_0=11111111
OTPMK_1=22222222
OTPMK_2=33333333
OTPMK_3=44444444
OTPMK_4=aab702d7
OTPMK_5=f9506757
OTPMK_6=cfb3b401
OTPMK_7=b5462445
---------------------------------------------------
SRKH_0=9f05646d
SRKH_1=eb7e034b
SRKH_2=a5c8da66
SRKH_3=0215ce65
SRKH_4=34bec8dd
SRKH_5=500d48bb
SRKH_6=665582c0
SRKH_7=8b826a4f
---------------------------------------------------
OEM_UID_0=11223344
OEM_UID_1=55667788
OEM_UID_2=99001122
OEM_UID_3=33445566
OEM_UID_4=77889900
---------------------------------------------------
DCV_0=68686868
DCV_1=67676767
DRV_0=6168745f
DRV_1=5f726e6e
---------------------------------------------------
DBG_LVL=001
---------------------------------------------------
WP=
ITS=
NSEC=
ZD=
K0=
K1=
K2=
K3=
K4=
K5=
K6=
FR0=
FR1=
---------------------------------------------------
OUTPUT_FUSE_FILENAME=fuse_scr.bin
---------------------------------------------------

DRV created with gen_drv_drbg

λ ./gen_drv_drbg A2 6168745f5f726e6e

#----------------------------------------------------#
#------- -------- -------- -------#
#------- CST (Code Signing Tool) Version 2.0 -------#
#------- -------- -------- -------#
#----------------------------------------------------#

DRV[63:0] after Hamming Code is:
6168745f5f726e6e
NAME | BITS | VALUE
_________|______________|____________
DRV 0 | 63 - 32 | 6168745f
DRV 1 | 31 - 0 | 5f726e6e

I am able to confirm that those were correctly fused, by booting, and checking from U-Boot shell

no hamming code error

md 0x1e80024 1
01e80024: 00000000 ....

dblev set to 1, dcvr also fused

=> md 0x1e80204 3
01e80204: 00000001 68686868 67676767 ....hhhhgggg

drvr set to 1

=> md 0x1e80210 2
01e80210: ffffffff ffffffff ........

Yet I am not able to connect. When I try with code warrior (Version: 11.5.12; Build Id: 221209), in target connection configuration I set `Secure debug key:` and provide the key there  `0x6e6e725f5f746861` (reversed endianness) and try to inspect i got an error with info
[CCS: subcore error during multicore operation]

I was trying to follow Secure_boot.pptx presentation (link: https://community.nxp.com/t5/Layerscape-Knowledge-Base/Secure-boot-Fuse-Provisioning-Secure-debug/ta...) and test it from CCS but got the following

(bin) 54 % delete all
(bin) 55 % config cc cwtap:192.168.0.32
(bin) 56 % show cc
0: CodeWarrior TAP (cwtap:192.168.0.32) CC software ver. {0.0}
(bin) 57 %
(bin) 57 % ccs::config_chain {ls1028a dap}
SAP2: Secure debug violation
(bin) 58 % display ccs::get_config_chain
Chain Position 0: LS1028A
Chain Position 1: DAP
Chain Position 2: SAP2
(bin) 59 %
(bin) 59 % ccs::config_chain {ls1028a dap sap2}
LS1028A: std::bad_alloc
(bin) 60 % ccs::config_chain {ls1028a dap}
SAP2: Secure debug violation
(bin) 61 % display ccs::get_config_chain
Chain Position 0: LS1028A
Chain Position 1: DAP
Chain Position 2: SAP2
(bin) 62 % display ccs::read_reg 0 sdcr 1 8
SAP2 error - read SAP_STATUS

what is SAP2 error? I am unable to find any kind of information about it.

Is there something I am doing wrongly?

Labels (1)
0 Kudos
Reply
10 Replies

1,394 Views
tomzy_0
Contributor I

Is there something more I can try? Or maybe challenge/response procedure cannot be executed on ls1028a? Right now it behave like I had closed the jtag, but IIUC configuration used in input_fuse_file should set it to conditionally closed without notification. Also register read from U-Boot shell tell me the same information.

0 Kudos
Reply

1,459 Views
LFGP
NXP TechSupport
NXP TechSupport

dear @tomzy_0 ,

Please be sure that your device partnumber nomenclature has a letter E on it.

On the other hand, please be sure regarding the "debug level" register has not been closet, see below

--------------------------------------------------
# Specify Debug Level in binary form. [Optional]
# 000 -> Wide open: Debug portals are enabled unconditionally.
# 001 -> Conditionally open via challenge response, without notification.
# 01x -> Conditionally open via challenge response, with notification.
# 1xx -> Closed. All debug portals are disabled.
DBG_LVL=
---------------------------------------------------

 

best regards

LFGP

 

0 Kudos
Reply

1,437 Views
tomzy_0
Contributor I

@LFGP 

IIUC SoC with E in part number means that security is on? I will confirm that tomorrow, but I am nearly sure that it has to have E since I am able to run Secure Boot procedure on it.

As for debug level.. I mentioned in my original post that right now I have lvl 001 which is
# 001 -> Conditionally open via challenge response, without notification.

Below output from U-Boot shell.

=> md 0x1e80204 3
01e80204: 00000001 68686868 67676767 ....hhhhgggg

So 0x1e80204 is 00000001 -> DB_LVL set to 001.

@LFGP  What else can be wrong here? How I can debug this further?

0 Kudos
Reply

1,424 Views
tomzy_0
Contributor I

@LFGP I am using https://www.nxp.com/part/LS1027AXE7NQA so it has a letter E on it.

0 Kudos
Reply

1,510 Views
LFGP
NXP TechSupport
NXP TechSupport

dear @tomzy_0 ,

What is SAP2 meaning? ans. it is the Secure Access Port.
 
If the device is set to open the JTAG port, the SAP2 stays locked until you authenticate by the challenge/response event.
Any attempt to enumerate or access it before you passed the challenge/response event, it will yield a “Secure debug violation”, that’s why your are seeing the CCS logs message "Secure debug violation” and “SAP2 error – read SAP_STATUS”.
 
please review the next case, it is related your case.
 
BR
LFGP
0 Kudos
Reply

1,503 Views
tomzy_0
Contributor I

@LFGP thanks for quick reply. Unfortunately I already followed the steps provided in thread that you mentioned - the same were in the presentation I linked in my post. I also posted results of running such commands. I am even unable to read DCV as CCS in return print error log.

@yipingwang hello. Sorry for direct mention but I saw you was the one who replied in the thread. If I am not mistaken, you was also responsible for making the Secure Boot presentation.

Would you be able to help? Difference between presentation and my case is that I am using ls1028a.

The chain needs to be configured differently ({ls1028a dap/sap2} vs {ls1043a dap sap2}). But it is hard to tell if this is a real issue here. I guess there is no such thing as CCS documentation - without this it is hard to even debug further.

I will go back to one of my questions. Does Secure Debug needs additional conditions under which it can work? ITS set? Maybe SB_EN will be enough? Maybe other bit of RCW should be set?

0 Kudos
Reply

1,530 Views
tomzy_0
Contributor I

Are there any additional conditions under which the Secure Debug can work? Do I need to boot with Secure Boot? Be in any kind of SECMON state?

0 Kudos
Reply

1,318 Views
LFGP
NXP TechSupport
NXP TechSupport
dear @tomzy_0,

you need to set the SB_EN = 1 and
IT_S =0
download the SEC reference manual
https://www.nxp.com/webapp/sps/download/preDownload.jsp?render=true

you could try the next approach (adjust it for LS1028a) :
Check the SecMon_HP Status Register (location 0x1e90014), Bits OTPMK_ZERO, OTMPK_SYNDROME and PE should be 0 otherwise there is some error in the OTPMK fuse blown by you.
b. If OTMPK fuse is correct (see Step 1), check the SCRATCHRW2(0x1ee0204) register for errors.
c. If Error code of step b is 0 then check the System Security Monitor State filed of HPSR.
System Security Monitor State (0x9)
If ITS fuse = 1, then it means ISBC code has reset the board. This may be due to the following reasons:
Hash of the public key used to sign the ESBC u-boot doesn't match with the value in SRK Hash Fuse
Or
Signature verification of the image failed.
SSM_STATE (0xd) or Non Secure State (0xb)
Check the entry point field in the ESBC header.

If entry point is correct, ensure that u-boot image has been compiled with the required secure boot configuration.

BR
LFGP
0 Kudos
Reply

740 Views
tomzy_0
Contributor I

@LFGP 

Hi, sorry for late reply. Below are outputs from the U-Boot shell.

```
=> md 0x1e90014 1
01e90014: 80002900 .)..
```

So, SecMon State set to Check. OTPMK_ZERO is 0. I do not know what is the OTPMK_SYNDROM or PE.

```
=> md 0x1ee0204 1
01ee0204: 00000000 ....
```

SCRATCHRW2 set to 0 so no errors. BTW, Hamming code is also zero - so everything should be ok.

```
=> md 0x1e80024
01e80024: 00000000 ....
```

Should the Secure Monitor be in different state?

0 Kudos
Reply

725 Views
tomzy_0
Contributor I
I also checked the connection from CodeWarrior GUI with CCS logs set to DEBUG - this is what I found

ccs_get_config_chain
serverh = 0
device_list: (size = 3)
ccs_get_config_chain; ccs_error = 0
ccs_get_config_chain
serverh = 0
device_list: (size = 3)
device[0]:: core_type=LS1028A(301)
device[1]:: core_type=DAP(232)
device[2]:: core_type=SAP2(272)
ccs_get_config_chain; ccs_error = 0
ccs_read_register
coreh = [serverh:0;cc_index:0;chain_pos:0]
index = 8192
count = 1
size = 8
value: (size =
00000000 00000000
ccs_read_register; ccs_error = 56
Error message: SAP2 error - read SAP_STATUS
ccs_get_config_chain
serverh = 0
device_list: (size = 3)
ccs_get_config_chain; ccs_error = 0
ccs_get_config_chain
serverh = 0
device_list: (size = 3)
device[0]:: core_type=LS1028A(301)
device[1]:: core_type=DAP(232)
device[2]:: core_type=SAP2(272)
ccs_get_config_chain; ccs_error = 0
ccs_write_register
coreh = [serverh:0;cc_index:0;chain_pos:0]
index = 8193
count = 1
size = 8
value: (size =
6168745F 5F726E6E
ccs_write_register; ccs_error = 56
Error message: SAP2 error - read SAP_STATUS


It looks like reading Challenge Value return all 0's and SAP2 error where it should return the challenge value that I am able to read from U-Boot shell. Why is that happening?
0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2319429%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ESecure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2319429%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20want%20to%20test%20Secure%20Debug%20on%20a%20ls1028a%20based%20custom%20board.%20For%20now%2C%20I%20performed%20following%20steps%3A%3CBR%20%2F%3E%3CBR%20%2F%3E1.%20Fuse%20registers%20using%20fuse_fip%20and%20the%20following%20input_fuse_file%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3E%2F*%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20Copyright%202018%20NXP%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%2F%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EPLATFORM%3C%2FSPAN%3E%3CSPAN%3E%3DLS1028%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EPOVDD_GPIO%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_FLAGS%3C%2FSPAN%3E%3CSPAN%3E%3D0010%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_0%3C%2FSPAN%3E%3CSPAN%3E%3D11111111%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_1%3C%2FSPAN%3E%3CSPAN%3E%3D22222222%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_2%3C%2FSPAN%3E%3CSPAN%3E%3D33333333%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_3%3C%2FSPAN%3E%3CSPAN%3E%3D44444444%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_4%3C%2FSPAN%3E%3CSPAN%3E%3Daab702d7%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_5%3C%2FSPAN%3E%3CSPAN%3E%3Df9506757%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_6%3C%2FSPAN%3E%3CSPAN%3E%3Dcfb3b401%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOTPMK_7%3C%2FSPAN%3E%3CSPAN%3E%3Db5462445%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_0%3C%2FSPAN%3E%3CSPAN%3E%3D9f05646d%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_1%3C%2FSPAN%3E%3CSPAN%3E%3Deb7e034b%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_2%3C%2FSPAN%3E%3CSPAN%3E%3Da5c8da66%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_3%3C%2FSPAN%3E%3CSPAN%3E%3D0215ce65%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_4%3C%2FSPAN%3E%3CSPAN%3E%3D34bec8dd%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_5%3C%2FSPAN%3E%3CSPAN%3E%3D500d48bb%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_6%3C%2FSPAN%3E%3CSPAN%3E%3D665582c0%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ESRKH_7%3C%2FSPAN%3E%3CSPAN%3E%3D8b826a4f%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOEM_UID_0%3C%2FSPAN%3E%3CSPAN%3E%3D11223344%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOEM_UID_1%3C%2FSPAN%3E%3CSPAN%3E%3D55667788%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOEM_UID_2%3C%2FSPAN%3E%3CSPAN%3E%3D99001122%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOEM_UID_3%3C%2FSPAN%3E%3CSPAN%3E%3D33445566%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOEM_UID_4%3C%2FSPAN%3E%3CSPAN%3E%3D77889900%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EDCV_0%3C%2FSPAN%3E%3CSPAN%3E%3D68686868%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EDCV_1%3C%2FSPAN%3E%3CSPAN%3E%3D67676767%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EDRV_0%3C%2FSPAN%3E%3CSPAN%3E%3D6168745f%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EDRV_1%3C%2FSPAN%3E%3CSPAN%3E%3D5f726e6e%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EDBG_LVL%3C%2FSPAN%3E%3CSPAN%3E%3D001%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EWP%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EITS%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ENSEC%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EZD%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK0%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK1%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK2%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK3%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK4%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK5%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EK6%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EFR0%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EFR1%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E---------------------------------------------------%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EOUTPUT_FUSE_FILENAME%3C%2FSPAN%3E%3CSPAN%3E%3Dfuse_scr.bin%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%3CSPAN%3E---------------------------------------------------%3CBR%20%2F%3E%3CBR%20%2F%3EDRV%20created%20with%20gen_drv_drbg%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3CP%3E%CE%BB%20.%2Fgen_drv_drbg%20A2%206168745f5f726e6e%3C%2FP%3E%3CP%3E%23----------------------------------------------------%23%3CBR%20%2F%3E%23-------%20--------%20--------%20-------%23%3CBR%20%2F%3E%23-------%20CST%20(Code%20Signing%20Tool)%20Version%202.0%20-------%23%3CBR%20%2F%3E%23-------%20--------%20--------%20-------%23%3CBR%20%2F%3E%23----------------------------------------------------%23%3C%2FP%3E%3CP%3EDRV%5B63%3A0%5D%20after%20Hamming%20Code%20is%3A%3CBR%20%2F%3E6168745f5f726e6e%3CBR%20%2F%3ENAME%20%7C%20BITS%20%7C%20VALUE%3CBR%20%2F%3E_________%7C______________%7C____________%3CBR%20%2F%3EDRV%200%20%7C%2063%20-%2032%20%7C%206168745f%3CBR%20%2F%3EDRV%201%20%7C%2031%20-%200%20%7C%205f726e6e%3CBR%20%2F%3E%3CBR%20%2F%3EI%20am%20able%20to%20confirm%20that%20those%20were%20correctly%20fused%2C%20by%20booting%2C%20and%20checking%20from%20U-Boot%20shell%3CBR%20%2F%3E%3CBR%20%2F%3Eno%20hamming%20code%20error%3CBR%20%2F%3E%3CBR%20%2F%3Emd%200x1e80024%201%3CBR%20%2F%3E01e80024%3A%2000000000%20....%3CBR%20%2F%3E%3CBR%20%2F%3Edblev%20set%20to%201%2C%20dcvr%20also%20fused%3CBR%20%2F%3E%3CBR%20%2F%3E%3D%26gt%3B%20md%200x1e80204%203%3CBR%20%2F%3E01e80204%3A%2000000001%2068686868%2067676767%20....hhhhgggg%3CBR%20%2F%3E%3CBR%20%2F%3Edrvr%20set%20to%201%3CBR%20%2F%3E%3CBR%20%2F%3E%3D%26gt%3B%20md%200x1e80210%202%3CBR%20%2F%3E01e80210%3A%20ffffffff%20ffffffff%20........%3CBR%20%2F%3E%3CBR%20%2F%3EYet%20I%20am%20not%20able%20to%20connect.%20When%20I%20try%20with%20code%20warrior%20(Version%3A%2011.5.12%3B%20Build%20Id%3A%20221209)%2C%20in%20target%20connection%20configuration%20I%20set%20%60Secure%20debug%20key%3A%60%20and%20provide%20the%20key%20there%26nbsp%3B%20%600x6e6e725f5f746861%60%20(reversed%20endianness)%20and%20try%20to%20inspect%20i%20got%20an%20error%20with%20info%3CBR%20%2F%3E%5BCCS%3A%20subcore%20error%20during%20multicore%20operation%5D%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20trying%20to%20follow%20Secure_boot.pptx%20presentation%20(link%3A%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FLayerscape-Knowledge-Base%2FSecure-boot-Fuse-Provisioning-Secure-debug%2Fta-p%2F1988564%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fcommunity.nxp.com%2Ft5%2FLayerscape-Knowledge-Base%2FSecure-boot-Fuse-Provisioning-Secure-debug%2Fta-p%2F1988564%3C%2FA%3E)%20and%20test%20it%20from%20CCS%20but%20got%20the%20following%3CBR%20%2F%3E%3CBR%20%2F%3E(bin)%2054%20%25%20delete%20all%3CBR%20%2F%3E(bin)%2055%20%25%20config%20cc%20cwtap%3A192.168.0.32%3CBR%20%2F%3E(bin)%2056%20%25%20show%20cc%3CBR%20%2F%3E0%3A%20CodeWarrior%20TAP%20(cwtap%3A192.168.0.32)%20CC%20software%20ver.%20%7B0.0%7D%3CBR%20%2F%3E(bin)%2057%20%25%3CBR%20%2F%3E(bin)%2057%20%25%20ccs%3A%3Aconfig_chain%20%7Bls1028a%20dap%7D%3CBR%20%2F%3ESAP2%3A%20Secure%20debug%20violation%3CBR%20%2F%3E(bin)%2058%20%25%20display%20ccs%3A%3Aget_config_chain%3CBR%20%2F%3EChain%20Position%200%3A%20LS1028A%3CBR%20%2F%3EChain%20Position%201%3A%20DAP%3CBR%20%2F%3EChain%20Position%202%3A%20SAP2%3CBR%20%2F%3E(bin)%2059%20%25%3CBR%20%2F%3E(bin)%2059%20%25%20ccs%3A%3Aconfig_chain%20%7Bls1028a%20dap%20sap2%7D%3CBR%20%2F%3ELS1028A%3A%20std%3A%3Abad_alloc%3CBR%20%2F%3E(bin)%2060%20%25%20ccs%3A%3Aconfig_chain%20%7Bls1028a%20dap%7D%3CBR%20%2F%3ESAP2%3A%20Secure%20debug%20violation%3CBR%20%2F%3E(bin)%2061%20%25%20display%20ccs%3A%3Aget_config_chain%3CBR%20%2F%3EChain%20Position%200%3A%20LS1028A%3CBR%20%2F%3EChain%20Position%201%3A%20DAP%3CBR%20%2F%3EChain%20Position%202%3A%20SAP2%3CBR%20%2F%3E(bin)%2062%20%25%20display%20ccs%3A%3Aread_reg%200%20sdcr%201%208%3CBR%20%2F%3ESAP2%20error%20-%20read%20SAP_STATUS%3CBR%20%2F%3E%3CBR%20%2F%3Ewhat%20is%20SAP2%20error%3F%20I%20am%20unable%20to%20find%20any%20kind%20of%20information%20about%20it.%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20there%20something%20I%20am%20doing%20wrongly%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2319429%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3EQorIQ%20LS1%20Devices%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2322786%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2322786%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EIs%20there%20something%20more%20I%20can%20try%3F%20Or%20maybe%20challenge%2Fresponse%20procedure%20cannot%20be%20executed%20on%20ls1028a%3F%20Right%20now%20it%20behave%20like%20I%20had%20closed%20the%20jtag%2C%20but%20IIUC%20configuration%20used%20in%20input_fuse_file%20should%20set%20it%20to%20conditionally%20closed%20without%20notification.%20Also%20register%20read%20from%20U-Boot%20shell%20tell%20me%20the%20same%20information.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2321154%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2321154%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203371%22%20target%3D%22_blank%22%3E%40LFGP%3C%2FA%3E%26nbsp%3BI%20am%20using%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fpart%2FLS1027AXE7NQA%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fpart%2FLS1027AXE7NQA%3C%2FA%3E%26nbsp%3Bso%20it%20%3CSPAN%3Ehas%20a%20letter%20E%20on%20it.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2321041%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2321041%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203371%22%20target%3D%22_blank%22%3E%40LFGP%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EIIUC%20SoC%20with%20E%20in%20part%20number%20means%20that%20security%20is%20on%3F%20I%20will%20confirm%20that%20tomorrow%2C%20but%20I%20am%20nearly%20sure%20that%20it%20has%20to%20have%20E%20since%20I%20am%20able%20to%20run%20Secure%20Boot%20procedure%20on%20it.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20for%20debug%20level..%20I%20mentioned%20in%20my%20original%20post%20that%20right%20now%20I%20have%20lvl%20001%20which%20is%3CBR%20%2F%3E%3CSPAN%3E%23%20001%20-%26gt%3B%20Conditionally%20open%20via%20challenge%20response%2C%20without%20notification.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3EBelow%20output%20from%20U-Boot%20shell.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3E%3D%26gt%3B%20md%200x1e80204%203%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3E01e80204%3A%2000000001%2068686868%2067676767%20....hhhhgggg%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3ESo%200x1e80204%20is%2000000001%20-%26gt%3B%20DB_LVL%20set%20to%20001.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203371%22%20target%3D%22_blank%22%3E%40LFGP%3C%2FA%3E%26nbsp%3B%20What%20else%20can%20be%20wrong%20here%3F%20How%20I%20can%20debug%20this%20further%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2320940%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2320940%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3Edear%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F255919%22%20target%3D%22_blank%22%3E%40tomzy_0%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CP%3EPlease%20be%20sure%20that%20your%20device%20partnumber%20nomenclature%20has%20a%20letter%20E%20on%20it.%3C%2FP%3E%0A%3CP%3EOn%20the%20other%20hand%2C%20please%20be%20sure%20regarding%20the%20%22debug%20level%22%20register%20has%20not%20been%20closet%2C%20see%20below%3C%2FP%3E%0A%3CP%3E--------------------------------------------------%3CBR%20%2F%3E%23%20Specify%20Debug%20Level%20in%20binary%20form.%20%5BOptional%5D%3CBR%20%2F%3E%23%20000%20-%26gt%3B%20Wide%20open%3A%20Debug%20portals%20are%20enabled%20unconditionally.%3CBR%20%2F%3E%23%20001%20-%26gt%3B%20Conditionally%20open%20via%20challenge%20response%2C%20without%20notification.%3CBR%20%2F%3E%23%2001x%20-%26gt%3B%20Conditionally%20open%20via%20challenge%20response%2C%20with%20notification.%3CBR%20%2F%3E%23%201xx%20-%26gt%3B%20Closed.%20All%20debug%20portals%20are%20disabled.%3CBR%20%2F%3EDBG_LVL%3D%3CBR%20%2F%3E---------------------------------------------------%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditor_8664aa7b01106LFGP_1%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3Ebest%20regards%3C%2FP%3E%0A%3CP%3ELFGP%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2320093%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2320093%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203371%22%20target%3D%22_blank%22%3E%40LFGP%3C%2FA%3E%26nbsp%3Bthanks%20for%20quick%20reply.%20Unfortunately%20I%20already%20followed%20the%20steps%20provided%20in%20thread%20that%20you%20mentioned%20-%20the%20same%20were%20in%20the%20presentation%20I%20linked%20in%20my%20post.%20I%20also%20posted%20results%20of%20running%20such%20commands.%20I%20am%20even%20unable%20to%20read%20DCV%20as%20CCS%20in%20return%20print%20error%20log.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52411%22%20target%3D%22_blank%22%3E%40yipingwang%3C%2FA%3E%26nbsp%3Bhello.%20Sorry%20for%20direct%20mention%20but%20I%20saw%20you%20was%20the%20one%20who%20replied%20in%20the%20thread.%20If%20I%20am%20not%20mistaken%2C%20you%20was%20also%20responsible%20for%20making%20the%20Secure%20Boot%20presentation.%3CBR%20%2F%3E%3CBR%20%2F%3EWould%20you%20be%20able%20to%20help%3F%20Difference%20between%20presentation%20and%20my%20case%20is%20that%20I%20am%20using%20ls1028a.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20chain%20needs%20to%20be%20configured%20differently%20(%7Bls1028a%20dap%2Fsap2%7D%20vs%20%7Bls1043a%20dap%20sap2%7D).%20But%20it%20is%20hard%20to%20tell%20if%20this%20is%20a%20real%20issue%20here.%20I%20guess%20there%20is%20no%20such%20thing%20as%20CCS%20documentation%20-%20without%20this%20it%20is%20hard%20to%20even%20debug%20further.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20will%20go%20back%20to%20one%20of%20my%20questions.%20Does%20Secure%20Debug%20needs%26nbsp%3B%3CSPAN%3Eadditional%20conditions%20under%20which%20it%20can%20work%3F%20ITS%20set%3F%20Maybe%20SB_EN%20will%20be%20enough%3F%20Maybe%20other%20bit%20of%20RCW%20should%20be%20set%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2320007%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2320007%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3Edear%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F255919%22%20target%3D%22_blank%22%3E%40tomzy_0%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CDIV%3E%3CSTRONG%3EWhat%20is%20SAP2%3C%2FSTRONG%3E%26nbsp%3Bmeaning%3F%20ans.%20it%20is%20the%20%3CEM%3ESecure%20Access%20Port%3C%2FEM%3E.%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3EIf%20the%20device%20is%20set%20to%20open%26nbsp%3Bthe%20JTAG%20port%2C%20the%20SAP2%20stays%20locked%20until%20you%20authenticate%20by%20the%20challenge%2Fresponse%20event.%3C%2FDIV%3E%0A%3CDIV%3EAny%20attempt%20to%20enumerate%20or%20access%20it%20before%20you%20passed%20the%20challenge%2Fresponse%20event%2C%20it%20will%20yield%20a%20%3CSTRONG%3E%E2%80%9CSecure%20debug%20violation%E2%80%9D%3C%2FSTRONG%3E%2C%20that%E2%80%99s%20why%20your%20are%20seeing%20the%20CCS%20logs%20message%20%22Secure%20debug%20violation%E2%80%9D%20and%20%E2%80%9CSAP2%20error%20%E2%80%93%20read%20SAP_STATUS%E2%80%9D.%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3Eplease%20review%20the%20next%20case%2C%20it%20is%20related%20your%20case.%3C%2FDIV%3E%0A%3CDIV%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FCodeWarrior-for-QorIQ%2FJTAG-debug-challenge-response-in-CodeWarrior-connection-server%2Fm-p%2F1281386%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fcommunity.nxp.com%2Ft5%2FCodeWarrior-for-QorIQ%2FJTAG-debug-challenge-response-in-CodeWarrior-connection-server%2Fm-p%2F1281386%3C%2FA%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3EBR%3C%2FDIV%3E%0A%3CDIV%3ELFGP%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2319460%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2319460%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EAre%20there%20any%20additional%20conditions%20under%20which%20the%20Secure%20Debug%20can%20work%3F%20Do%20I%20need%20to%20boot%20with%20Secure%20Boot%3F%20Be%20in%20any%20kind%20of%20SECMON%20state%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2325291%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2325291%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3Edear%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F255919%22%20target%3D%22_blank%22%3E%40tomzy_0%3C%2FA%3E%2C%3CBR%20%2F%3E%3CBR%20%2F%3Eyou%20need%20to%20set%20the%20SB_EN%20%3D%201%20and%3CBR%20%2F%3EIT_S%20%3D0%20%3CBR%20%2F%3Edownload%20the%20SEC%20reference%20manual%20%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fwebapp%2Fsps%2Fdownload%2FpreDownload.jsp%3Frender%3Dtrue%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fwebapp%2Fsps%2Fdownload%2FpreDownload.jsp%3Frender%3Dtrue%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3Eyou%20could%20try%20the%20next%20approach%20(adjust%20it%20for%20LS1028a)%20%20%3A%3CBR%20%2F%3ECheck%20the%20SecMon_HP%20Status%20Register%20(location%200x1e90014)%2C%20Bits%20OTPMK_ZERO%2C%20OTMPK_SYNDROME%20and%20PE%20should%20be%200%20otherwise%20there%20is%20some%20error%20in%20the%20OTPMK%20fuse%20blown%20by%20you.%3CBR%20%2F%3Eb.%20If%20OTMPK%20fuse%20is%20correct%20(see%20Step%201)%2C%20check%20the%20SCRATCHRW2(0x1ee0204)%20register%20for%20errors.%3CBR%20%2F%3Ec.%20If%20Error%20code%20of%20step%20b%20is%200%20then%20check%20the%20System%20Security%20Monitor%20State%20filed%20of%20HPSR.%3CBR%20%2F%3ESystem%20Security%20Monitor%20State%20(0x9)%3CBR%20%2F%3EIf%20ITS%20fuse%20%3D%201%2C%20then%20it%20means%20ISBC%20code%20has%20reset%20the%20board.%20This%20may%20be%20due%20to%20the%20following%20reasons%3A%3CBR%20%2F%3EHash%20of%20the%20public%20key%20used%20to%20sign%20the%20ESBC%20u-boot%20doesn't%20match%20with%20the%20value%20in%20SRK%20Hash%20Fuse%3CBR%20%2F%3EOr%3CBR%20%2F%3ESignature%20verification%20of%20the%20image%20failed.%3CBR%20%2F%3ESSM_STATE%20(0xd)%20or%20Non%20Secure%20State%20(0xb)%3CBR%20%2F%3ECheck%20the%20entry%20point%20field%20in%20the%20ESBC%20header.%20%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20entry%20point%20is%20correct%2C%20ensure%20that%20u-boot%20image%20has%20been%20compiled%20with%20the%20required%20secure%20boot%20configuration.%20%3CBR%20%2F%3E%3CBR%20%2F%3EBR%3CBR%20%2F%3ELFGP%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2337444%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2337444%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203371%22%20target%3D%22_blank%22%3E%40LFGP%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EHi%2C%20sorry%20for%20late%20reply.%20Below%20are%20outputs%20from%20the%20U-Boot%20shell.%3CBR%20%2F%3E%3CBR%20%2F%3E%60%60%60%3CBR%20%2F%3E%3D%26gt%3B%20md%200x1e90014%201%3CBR%20%2F%3E01e90014%3A%2080002900%20.)..%3CBR%20%2F%3E%60%60%60%3CBR%20%2F%3E%3CBR%20%2F%3ESo%2C%20SecMon%20State%20set%20to%20Check.%20OTPMK_ZERO%20is%200.%20I%20do%20not%20know%20what%20is%20the%20OTPMK_SYNDROM%20or%20PE.%3CBR%20%2F%3E%3CBR%20%2F%3E%60%60%60%3CBR%20%2F%3E%3D%26gt%3B%20md%200x1ee0204%201%3CBR%20%2F%3E01ee0204%3A%2000000000%20....%3CBR%20%2F%3E%60%60%60%3CBR%20%2F%3E%3CBR%20%2F%3ESCRATCHRW2%20set%20to%200%20so%20no%20errors.%20BTW%2C%20Hamming%20code%20is%20also%20zero%20-%20so%20everything%20should%20be%20ok.%3CBR%20%2F%3E%3CBR%20%2F%3E%60%60%60%3CBR%20%2F%3E%3D%26gt%3B%20md%200x1e80024%3CBR%20%2F%3E01e80024%3A%2000000000%20....%3CBR%20%2F%3E%60%60%60%3CBR%20%2F%3E%3CBR%20%2F%3EShould%20the%20Secure%20Monitor%20be%20in%20different%20state%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2337524%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Debug%20on%20ls1028a%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2337524%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EI%20also%20checked%20the%20connection%20from%20CodeWarrior%20GUI%20with%20CCS%20logs%20set%20to%20DEBUG%20-%20this%20is%20what%20I%20found%3CBR%20%2F%3E%3CBR%20%2F%3Eccs_get_config_chain%3CBR%20%2F%3Eserverh%20%3D%200%3CBR%20%2F%3Edevice_list%3A%20(size%20%3D%203)%3CBR%20%2F%3Eccs_get_config_chain%3B%20ccs_error%20%3D%200%3CBR%20%2F%3Eccs_get_config_chain%3CBR%20%2F%3Eserverh%20%3D%200%3CBR%20%2F%3Edevice_list%3A%20(size%20%3D%203)%3CBR%20%2F%3Edevice%5B0%5D%3A%3A%20core_type%3DLS1028A(301)%3CBR%20%2F%3Edevice%5B1%5D%3A%3A%20core_type%3DDAP(232)%3CBR%20%2F%3Edevice%5B2%5D%3A%3A%20core_type%3DSAP2(272)%3CBR%20%2F%3Eccs_get_config_chain%3B%20ccs_error%20%3D%200%3CBR%20%2F%3Eccs_read_register%3CBR%20%2F%3Ecoreh%20%3D%20%5Bserverh%3A0%3Bcc_index%3A0%3Bchain_pos%3A0%5D%3CBR%20%2F%3Eindex%20%3D%208192%3CBR%20%2F%3Ecount%20%3D%201%3CBR%20%2F%3Esize%20%3D%208%3CBR%20%2F%3Evalue%3A%20(size%20%3D%20%3CLI-EMOJI%20id%3D%22lia_smiling-face-with-sunglasses%22%20title%3D%22%3Asmiling_face_with_sunglasses%3A%22%3E%3C%2FLI-EMOJI%3E%3CBR%20%2F%3E00000000%2000000000%3CBR%20%2F%3Eccs_read_register%3B%20ccs_error%20%3D%2056%3CBR%20%2F%3EError%20message%3A%20SAP2%20error%20-%20read%20SAP_STATUS%3CBR%20%2F%3Eccs_get_config_chain%3CBR%20%2F%3Eserverh%20%3D%200%3CBR%20%2F%3Edevice_list%3A%20(size%20%3D%203)%3CBR%20%2F%3Eccs_get_config_chain%3B%20ccs_error%20%3D%200%3CBR%20%2F%3Eccs_get_config_chain%3CBR%20%2F%3Eserverh%20%3D%200%3CBR%20%2F%3Edevice_list%3A%20(size%20%3D%203)%3CBR%20%2F%3Edevice%5B0%5D%3A%3A%20core_type%3DLS1028A(301)%3CBR%20%2F%3Edevice%5B1%5D%3A%3A%20core_type%3DDAP(232)%3CBR%20%2F%3Edevice%5B2%5D%3A%3A%20core_type%3DSAP2(272)%3CBR%20%2F%3Eccs_get_config_chain%3B%20ccs_error%20%3D%200%3CBR%20%2F%3Eccs_write_register%3CBR%20%2F%3Ecoreh%20%3D%20%5Bserverh%3A0%3Bcc_index%3A0%3Bchain_pos%3A0%5D%3CBR%20%2F%3Eindex%20%3D%208193%3CBR%20%2F%3Ecount%20%3D%201%3CBR%20%2F%3Esize%20%3D%208%3CBR%20%2F%3Evalue%3A%20(size%20%3D%20%3CLI-EMOJI%20id%3D%22lia_smiling-face-with-sunglasses%22%20title%3D%22%3Asmiling_face_with_sunglasses%3A%22%3E%3C%2FLI-EMOJI%3E%3CBR%20%2F%3E6168745F%205F726E6E%3CBR%20%2F%3Eccs_write_register%3B%20ccs_error%20%3D%2056%3CBR%20%2F%3EError%20message%3A%20SAP2%20error%20-%20read%20SAP_STATUS%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20looks%20like%20reading%20Challenge%20Value%20return%20all%200's%20and%20SAP2%20error%20where%20it%20should%20return%20the%20challenge%20value%20that%20I%20am%20able%20to%20read%20from%20U-Boot%20shell.%20Why%20is%20that%20happening%3F%3C%2FLINGO-BODY%3E