Dear NXP experts,
I have used cst tool to generate SRK and SGK for secure boot.
I found the private keys in the "keys" folder and certificates in the "crts" folder,
and the private keys are encrypted.
My questions:
can I use the generated SGK private key to sign my private image such OTA package?
For example:
openssl dgst -sign SGK1_1_sha256_2048_65537_v3_usr_key.pem -sha256 -out privinfo.sign privinfo
And then, can I use the generated SGK certificate to verify the signature "privinfo.sign"?
Thanks!
Best regards,
Liweihua