Hello,
is there a method for authenticating images signed by external PKI? Let me explain better my question.
I would like to enable secure boot by burning fuse CUST_PROD_OEMFW_AUTH_PUK with sha-256 of public key. I have the certificate with the public key provided by the OEM but I don't have the related private key because I am not the signer. I can only sign my plain test by external portal with a dedicated PKI and obtain ECDSA signature.
I was referring to the following image

but, assuming that i can obtain the signature, how can I know the exact tbs? in particular the data contained in the vector table?

I hope I have explained my question in a good way.
Thank you,
Alessandro