Enabling kernel verification on IMX8MP

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

Enabling kernel verification on IMX8MP

606 次查看
kartheek
Contributor III

Hi,

I am working kernel authentication and booting through u-boot.  The below is u-boot cmd used to authenticate kernel. I have tried with signed kernel with correct and different keys. But i am getting only "Kernel authentication passed!". 

Is there any other way to get the verify the kernel image.

u-boot=>setenv auth_kernel 'if fatload mmc 1:1 ${loadaddr} Image &&                                                                                                 hab_auth_img   ${loadaddr} ${filesize} 0x1a90000; then \
                                                         echo "Kernel authentication passed!"; \
                                                     else \
                                                         echo "Kernel authentication failed!"; \
                                                     fi'
Thanks,
Kartheek

0 项奖励
回复
1 回复

529 次查看
Harvey021
NXP TechSupport
NXP TechSupport

Hi,

There will be error log printed if there are events. There is offline tool provided in CST - hab_image_verifier.

 

Regards

Harvey

 

0 项奖励
回复
%3CLINGO-SUB%20id%3D%22lingo-sub-2200927%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9C%A8%20IMX8MP%20%E4%B8%8A%E5%90%AF%E7%94%A8%E5%86%85%E6%A0%B8%E9%AA%8C%E8%AF%81%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2200927%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E6%82%A8%E5%A5%BD%EF%BC%8C%3C%2FP%3E%3CP%3E%E6%88%91%E6%AD%A3%E5%9C%A8%E8%BF%9B%E8%A1%8C%E5%86%85%E6%A0%B8%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E5%B9%B6%E9%80%9A%E8%BF%87%20u-boot%20%E5%90%AF%E5%8A%A8%E3%80%82%E4%BB%A5%E4%B8%8B%E6%98%AF%E7%94%A8%E4%BA%8E%E5%AF%B9%E5%86%85%E6%A0%B8%E8%BF%9B%E8%A1%8C%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%9A%84%20u-%E5%90%AF%E5%8A%A8%20%E5%91%BD%E4%BB%A4%E3%80%82%E6%88%91%E8%AF%95%E8%BF%87%E4%BD%BF%E7%94%A8%E5%B7%B2%E7%AD%BE%E5%90%8D%E7%9A%84%E5%86%85%E6%A0%B8%E5%92%8C%E6%AD%A3%E7%A1%AE%E7%9A%84%E5%AF%86%E9%92%A5%EF%BC%8C%E4%B9%9F%E8%AF%95%E8%BF%87%E4%BD%BF%E7%94%A8%E4%B8%8D%E5%90%8C%E7%9A%84%E5%AF%86%E9%92%A5%E3%80%82%E4%BD%86%E6%88%91%E5%8F%AA%E5%BE%97%E5%88%B0%22%E5%86%85%E6%A0%B8%E9%AA%8C%E8%AF%81%E9%80%9A%E8%BF%87%EF%BC%81%22%20%E3%80%82%20%3C%2FP%3E%3CP%3E%E6%9C%89%E6%B2%A1%E6%9C%89%E5%85%B6%E4%BB%96%E6%96%B9%E6%B3%95%E5%8F%AF%E4%BB%A5%E9%AA%8C%E8%AF%81%E5%86%85%E6%A0%B8%E6%98%A0%E5%83%8F%EF%BC%9F%3C%2FP%3E%3CP%3Eu-boot%3D%20%26gt%3B%20setenv%20auth_kernel%20'if%20fatload%20mmc%201%3A1%20%24%7Bloadaddr%7D%20%E5%9B%BE%E7%89%87%20%26amp%3B%20%26amp%3B%20hab_auth_img%20%24%7Bloadaddr%7D%20%24%7Bfilesize%7D%200x1a90000%EF%BC%9B%E7%84%B6%E5%90%8E%5C%20echo%20%22%20%E5%86%85%E6%A0%B8%E8%AE%A4%E8%AF%81%E9%80%9A%E8%BF%87%E4%BA%86%EF%BC%81%3CBR%20%2F%3E%22%3B%5C%20%3CBR%20%2F%3E%20else%5C%20%3CBR%20%2F%3E%20echo%20%22%20%E5%86%85%E6%A0%B8%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E5%A4%B1%E8%B4%A5%EF%BC%81%22%3B%5C%20%3CBR%20%2F%3E%20fi'%20%3CBR%20%2F%3E%20%E8%B0%A2%E8%B0%A2%EF%BC%8C%3CBR%20%2F%3EKartheek%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2203313%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Enabling%20kernel%20verification%20on%20IMX8MP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2203313%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E6%82%A8%E5%A5%BD%EF%BC%8C%3C%2FP%3E%0A%3CP%3E%E5%A6%82%E6%9E%9C%E6%9C%89%E4%BA%8B%E4%BB%B6%E5%8F%91%E7%94%9F%EF%BC%8C%E5%B0%86%E6%89%93%E5%8D%B0%E9%94%99%E8%AF%AF%E6%97%A5%E5%BF%97%E3%80%82%20%3CSPAN%20data-teams%3D%22true%22%3ECST%20%E4%B8%AD%E6%8F%90%E4%BE%9B%E4%BA%86%E4%B8%80%E4%B8%AA%E7%A6%BB%E7%BA%BF%E5%B7%A5%E5%85%B7%20-%20hab_image_verifier%E3%80%82%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%3CSPAN%20data-teams%3D%22true%22%3E%E6%AD%A4%E8%87%B4%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-teams%3D%22true%22%3E%E5%93%88%E7%BB%B4%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E