Hello,
In order to generate a blob with the CAAM OTPMK, a secure boot with HAB should be
in closed config, otherwise the blob will be created using CAAM default master key.
OTPMK, when burned (“the OTPMK are burned by Freescale prior to shipping the device”),
is unique and is used as the Key Encryption Key, therefore for different boards encrypted
data may be the same, if the same Key is applied for encryption, but encrypted key part
of the blob should differ.
One can determine if a valid OTPMK has been burned by checking the OTPMK_ZERO
bit in the SNVS_HP Status Register.
Best regards
Yuri
-----------------------------------------------------------------------------------------------------------------------
Note: If this post answers your question, please click the Correct Answer button. Thank you!
-----------------------------------------------------------------------------------------------------------------------