Hello,
I'm using CST 3.1.0 that has been download from the following uri, a few days ago:
i.MX High Assurance Boot Reference Code Signing Tool
I followed instructions in AN12312 to generate pki:
./ahab_pki_tree.sh
Do you want to use an existing CA key (y/n)?: n
Do you want to use Elliptic Curve Cryptography (y/n)?: y
Enter length for elliptic curve to be used for PKI tree:
Possible values p256, p384, p521: p384
Enter the digest algorithm to use: sha384
Enter PKI tree duration (years): 10
Do you want the SRK certificates to have the CA flag set? (y/n)?: n
Moreover, "-d" seems only allowed with "-h4".