POLICY_OBJ_ALLOW_DELETE and Reset

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

POLICY_OBJ_ALLOW_DELETE and Reset

跳至解决方案
3,751 次查看
psvz
Contributor IV

Hi

If I attached POLICY_OBJ_ALLOW_DELETE = False to a key object - would it help to preserve it over ssscli se05x reset?

标签 (1)
0 项奖励
回复
1 解答
3,740 次查看
psvz
Contributor IV

Hi Kan

I am trying to achieve the opposite effect. I want a key that I have provisioned to stay in secure element forever and couldn't be deleted - same way as NXP keys and certificates. Is it possible?

在原帖中查看解决方案

0 项奖励
回复
5 回复数
3,694 次查看
psvz
Contributor IV

Se05x_API_DeleteAll() fails if I open session with kSSS_AuthType_None. Do you know if session with kSSS_AuthType_SCP03 would work? any working demo using Se05x_API_DeleteAll()?

0 项奖励
回复
3,691 次查看
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @psvz ,

 

Actually this command can only be used in the session authenticated using the
credential with index RESERVED_ID_FACTORY_RESET, and this Auth ID might be not available in your device, but you may provision it with the help of ssscli tool. 

Please kindly refer to https://www.nxp.com/webapp/Download?colCode=AN12543 for more details.

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 项奖励
回复
3,744 次查看
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @psvz ,

 

Yes, you can do that, and usually we set up POLICY_OBJ_ALLOW_DELETE = True for some Auth ID to a key object so that you may still perform the deletion in some cases.

 

Hope that makes sense,

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 项奖励
回复
3,741 次查看
psvz
Contributor IV

Hi Kan

I am trying to achieve the opposite effect. I want a key that I have provisioned to stay in secure element forever and couldn't be deleted - same way as NXP keys and certificates. Is it possible?

0 项奖励
回复
3,704 次查看
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @psvz ,

 

No , I don't think it is possible, you know, the DeleteAll command may delete all secure objects which are not trust provisioned by NXP.

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 项奖励
回复