In my opinion this is not solved. Why can't we just use a standard signed FIt Image? This works perfect on an IMX6 and IMX8.
The OS containier is basicly a signed kernel, but what if we also want to use an initramfs, how can we protect that?
We also need to protect our cryptsetup keys. There is no DCP or CAAM on the IMX93. Is there no simple solution to safely store the cryptsetup keys on the the device?
Many others have these problems. But there are still no solutions. Please fix them as soon as possible.