Hi,
Are you writing any commands after you enable MU1 under menuconfig?
We have the following commands provided by the internal team:
"NOTICE: Reset status: Power-On Reset
NOTICE: BL2: v2.5(release):bsp36.0_cd-2.5
NOTICE: BL2: Built : 10:52:45, Mar 16 2023
NOTICE: BL2: Booting BL31
U-Boot 2020.04 (Mar 16 2023 - 10:49:34 +0800)
...
[ 0.894802] hse 40211000.mu1b: MU interface not active
...
root@s32g274ardb2:~# ls
hse-encrypt hse-secboot hse-sysimg pkcs-key-provision pkcs-keyop
root@s32g274ardb2:~# ldconfig -l /usr/lib/libpkcs-hse.so
root@s32g274ardb2:~# ldconfig -l /usr/lib/libcrypto.so.1.1
root@s32g274ardb2:~# ldconfig -l /usr/lib/libhse.so.1.0
root@s32g274ardb2:~# ldconfig -l /usr/lib/libp11.so.3.4.3
root@s32g274ardb2:~# ./hse-secboot -h
format HSE key catalogs or set up HSE-based advanced secure boot
Usage:
./hse-secboot [-h] [-f|s] [-k keypath] [-d devpath]
-h: display this help string
-f: format key catalogs
requires -d
mutually exclusive with -s
-o: force overwrite of HSE key catalog
-s: set up advanced secure boot
requires -d and -k
mutually exclusive with -f
-k: specify full path to PEM format key file
-d: specify full path to SD device (e.g. /dev/sdb)
root@s32g274ardb2:~# ./hse-secboot -f -d /dev/mmcblk0
[INFO] Formatting HSE key catalog
hse: device initialized, status 0x0920
[INFO] Retrieving IVT from device /dev/mmcblk0
[INFO] Enabling MUs
[INFO] Formatting NVM and RAM key catalogs
[INFO] Retrieving SYSIMG size
[INFO] Publishing SYSIMG
[INFO] Writing SYSIMG to /dev/mmcblk0
root@s32g274ardb2:~# NOTICE: Reset status: Power-On Reset
NOTICE: BL2: v2.5(release):bsp36.0_cd-2.5
NOTICE: BL2: Built : 10:52:45, Mar 16 2023
NOTICE: BL2: Booting BL31
...
[ 0.894824] hse 40211000.mu1b: premium firmware, version 1.0.1
[ 0.901025] hse 40211000.mu1b: registered algs sha1,hmac(sha1)
[ 0.907198] hse 40211000.mu1b: registered algs sha224,hmac(sha224)
[ 0.913718] hse 40211000.mu1b: registered algs sha256,hmac(sha256)
[ 0.920235] hse 40211000.mu1b: registered algs sha384,hmac(sha384)
[ 0.922555] mmc0: SDHCI controller on 402f0000.mmc [402f0000.mmc] using ADMA
[ 0.930734] hse 40211000.mu1b: registered algs sha512,hmac(sha512)
[ 0.940252] hse 40211000.mu1b: registered alg ctr(aes)
[ 0.945651] hse 40211000.mu1b: registered alg cbc(aes)
[ 0.951007] hse 40211000.mu1b: registered alg ecb(aes)
[ 0.956409] hse 40211000.mu1b: registered alg cfb(aes)
[ 0.961761] hse 40211000.mu1b: registered alg ofb(aes)
[ 0.967133] hse 40211000.mu1b: registered alg gcm(aes)
[ 0.972530] hse 40211000.mu1b: registered hwrng-hse
[ 0.977527] hse 40211000.mu1b: device ready, status 0x4B20
"
Please, let us know.