HAB4 Secure Boot Keys Stored on YubiKey 5 Nano

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

HAB4 Secure Boot Keys Stored on YubiKey 5 Nano

2,761 Views
Mihajlo
Contributor III

Hello everyone,

Has anyone tried/succeeded to store public and private keys for i.MX8-MP platform secure boot on YubiKey 5 Nano device?

I'm using CST version 3.1.0 and so far signing and secure booting are successful, but the keys (created by hab4_pki_tree script) are being kept alongside the code, i.e. in the source tree.

The whole system image (bootloader, kernel, filesystem) is being build under Yocto 3.0

To make everything more secure, the idea is to have keys stored on YubiKey5 Nano.

The questions are: 

1. Is it at all possible to use YubiKey 5 Nano for that purpose?

     AFAIK, paths to public keys are in .csf file used by CST, and CST then finds private key by itself, given that the keys are named properly and that keys and crts folders are on the same level. I couldn't find a way to give path/command to be used by CST in order to fetch keys from YubiKey 5 Nano

2. It the answer to 1) is yes, then should OpenPGP or PIV application for YubiKey 5 Nano be used?

Thanks a lot in advance.

0 Kudos
Reply
5 Replies

2,623 Views
Mihajlo
Contributor III

Yes, that's absolutely correct.

At the moment, and as a proof of concept, the keys are integral part of source tree used in Yocto 3.0 build, but we would like to have them stored only on YubiKey 5 Nano.

Mihajlo

2,704 Views
Mihajlo
Contributor III

Yes, that's exactly the case.

The work so far is based on this example from Variscite:

https://variwiki.com/index.php?title=High_Assurance_Boot_MX8&release=RELEASE_HARDKNOTT_V2.3_DART-MX8...

and now the final goal is to remove keys from source tree where they are now and use them from a more secure location, i.e.
YubiKey.

So far I have only found one application where keys are used from YubiKey, but unfortunately, that's YubiKey HSM, not YubiKey 5 Nano, and IMHO, those two probably have different firmware and support different key access(es):

https://www.thegoodpenguin.co.uk/blog/i-mx-code-signing-using-a-yubihsm-2-hardware-token-from-yubico...


0 Kudos
Reply

2,680 Views
AldoG
NXP TechSupport
NXP TechSupport

Hello,

I have contacted internal expert team, they do confirm that this should be doable and that it can be used.

Unfortunately as I said before I do not have much experience with yubikey for providing more details on the how.

Best regards/Saludos,
Aldo.

2,728 Views
AldoG
NXP TechSupport
NXP TechSupport

Hello,

Unfortunately I do not have experience using Yubikey, so I cannot be completely sure if this can be used or not but will double check, as far as I know from your description you want to create a signed image with keys stored in the Yubikey, is this correct?

Best regards/Saludos,
Aldo.

2,556 Views
Mihajlo
Contributor III

NOTE: Repeating this reply so it could be easy to follow the conversation.

Yes, that's exactly the case.

The work so far is based on this example from Variscite:

https://variwiki.com/index.php?title=High_Assurance_Boot_MX8&release=RELEASE_HARDKNOTT_V2.3_DART-MX8...

and now the final goal is to remove keys from source tree where they are now and use them from a more secure location, i.e.
YubiKey.

So far I have only found one application where keys are used from YubiKey, but unfortunately, that's YubiKey HSM, not YubiKey 5 Nano, and IMHO, those two probably have different firmware and support different key access(es):

https://www.thegoodpenguin.co.uk/blog/i-mx-code-signing-using-a-yubihsm-2-hardware-token-from-yubico...

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2147744%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHAB4%20Secure%20Boot%20Keys%20Stored%20on%20YubiKey%205%20Nano%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2147744%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%20everyone%2C%3CBR%20%2F%3E%3CBR%20%2F%3EHas%20anyone%20tried%2Fsucceeded%20to%20store%20public%20and%20private%20keys%20for%20i.MX8-MP%20platform%20secure%20boot%20on%20YubiKey%205%20Nano%20device%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI'm%20using%20CST%20version%203.1.0%20and%20so%20far%20signing%20and%20secure%20booting%20are%20successful%2C%20but%20the%20keys%20(created%20by%20%3CSTRONG%3Ehab4_pki_tree%20script%3C%2FSTRONG%3E)%20are%20being%20kept%20alongside%20the%20code%2C%20i.e.%20in%20the%20source%20tree.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20whole%20system%20image%20(bootloader%2C%20kernel%2C%20filesystem)%20is%20being%20build%20under%20Yocto%203.0%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20make%20everything%20more%20secure%2C%20the%20idea%20is%20to%20have%20keys%20stored%20on%20YubiKey5%20Nano.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20questions%20are%3A%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E1.%20%3CSTRONG%3EIs%20it%20at%20all%20possible%20to%20use%20YubiKey%205%20Nano%20for%20that%20purpose%3F%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3BAFAIK%2C%20paths%20to%20public%20keys%20are%20in%20.csf%20file%20used%20by%20%3CSTRONG%3ECST%3C%2FSTRONG%3E%2C%20and%20%3CSTRONG%3ECST%3C%2FSTRONG%3E%20then%20finds%20private%20key%20by%20itself%2C%20given%20that%20the%20keys%20are%20named%20properly%20and%20that%20%3CSTRONG%3Ekeys%3C%2FSTRONG%3E%20and%20%3CSTRONG%3Ecrts%3C%2FSTRONG%3E%20folders%20are%20on%20the%20same%20level.%20I%20couldn't%20find%20a%20way%20to%20give%20path%2Fcommand%20to%20be%20used%20by%20CST%20in%20order%20to%20fetch%20keys%20from%20YubiKey%205%20Nano%3CBR%20%2F%3E%3CBR%20%2F%3E2.%20It%20the%20answer%20to%201)%20is%20yes%2C%20then%20should%20OpenPGP%20or%20PIV%20application%20for%20YubiKey%205%20Nano%20be%20used%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%20a%20lot%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2147744%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3Ei.MX%208M%20%7C%20i.MX%208M%20Mini%20%7C%20i.MX%208M%20Nano%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EYocto%20Project%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2155022%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20HAB4%20Secure%20Boot%20Keys%20Stored%20on%20YubiKey%205%20Nano%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2155022%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3ENOTE%3A%20Repeating%20this%20reply%20so%20it%20could%20be%20easy%20to%20follow%20the%20conversation.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3EYes%2C%20that's%20exactly%20the%20case.%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3EThe%20work%20so%20far%20is%20based%20on%20this%20example%20from%20Variscite%3A%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fvariwiki.com%2Findex.php%3Ftitle%3DHigh_Assurance_Boot_MX8%26amp%3Brelease%3DRELEASE_HARDKNOTT_V2.3_DART-MX8M-PLUS%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fvariwiki.com%2Findex.php%3Ftitle%3DHigh_Assurance_Boot_MX8%26amp%3Brelease%3DRELEASE_HARDKNOTT_V2.3_DART-MX8...%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3Eand%20now%20the%20final%20goal%20is%20to%20remove%20keys%20from%20source%20tree%20where%20they%20are%20now%20and%20use%20them%20from%20a%20more%20secure%20location%2C%20i.e.%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EYubiKey.%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3ESo%20far%20I%20have%20only%20found%20one%20application%20where%20keys%20are%20used%20from%20YubiKey%2C%20but%20unfortunately%2C%20that's%20YubiKey%20HSM%2C%20not%20YubiKey%205%20Nano%2C%20and%20IMHO%2C%20those%20two%20probably%20have%20different%20firmware%20and%20support%20different%20key%20access(es)%3A%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.thegoodpenguin.co.uk%2Fblog%2Fi-mx-code-signing-using-a-yubihsm-2-hardware-token-from-yubico%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.thegoodpenguin.co.uk%2Fblog%2Fi-mx-code-signing-using-a-yubihsm-2-hardware-token-from-yubico...%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2153329%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20HAB4%20Secure%20Boot%20Keys%20Stored%20on%20YubiKey%205%20Nano%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2153329%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EYes%2C%20that's%20absolutely%20correct.%3CBR%20%2F%3E%3CBR%20%2F%3EAt%20the%20moment%2C%20and%20as%20a%20proof%20of%20concept%2C%20the%20keys%20are%20integral%20part%20of%20source%20tree%20used%20in%20Yocto%203.0%20build%2C%20but%20we%20would%20like%20to%20have%20them%20stored%20only%20on%20YubiKey%205%20Nano.%3CBR%20%2F%3E%3CBR%20%2F%3EMihajlo%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2151079%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20HAB4%20Secure%20Boot%20Keys%20Stored%20on%20YubiKey%205%20Nano%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2151079%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20have%20contacted%20internal%20expert%20team%2C%20they%20do%20confirm%20that%20this%20should%20be%20doable%20and%20that%20it%20can%20be%20used.%3CBR%20%2F%3E%3CBR%20%2F%3EUnfortunately%20as%20I%20said%20before%20I%20do%20not%20have%20much%20experience%20with%20yubikey%20for%20providing%20more%20details%20on%20the%20how.%3CBR%20%2F%3E%3CBR%20%2F%3EBest%20regards%2FSaludos%2C%3CBR%20%2F%3EAldo.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2149959%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20HAB4%20Secure%20Boot%20Keys%20Stored%20on%20YubiKey%205%20Nano%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2149959%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EYes%2C%20that's%20exactly%20the%20case.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20work%20so%20far%20is%20based%20on%20this%20example%20from%20Variscite%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fvariwiki.com%2Findex.php%3Ftitle%3DHigh_Assurance_Boot_MX8%26amp%3Brelease%3DRELEASE_HARDKNOTT_V2.3_DART-MX8M-PLUS%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fvariwiki.com%2Findex.php%3Ftitle%3DHigh_Assurance_Boot_MX8%26amp%3Brelease%3DRELEASE_HARDKNOTT_V2.3_DART-MX8M-PLUS%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3Eand%20now%20the%20final%20goal%20is%20to%20remove%20keys%20from%20source%20tree%20where%20they%20are%20now%20and%20use%20them%20from%20a%20more%20secure%20location%2C%20i.e.%3CBR%20%2F%3EYubiKey.%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20far%20I%20have%20only%20found%20one%20application%20where%20keys%20are%20used%20from%20YubiKey%2C%20but%20unfortunately%2C%20that's%20YubiKey%20HSM%2C%20not%20YubiKey%205%20Nano%2C%20and%20IMHO%2C%20those%20two%20probably%20have%20different%20firmware%20and%20support%20different%20key%20access(es)%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.thegoodpenguin.co.uk%2Fblog%2Fi-mx-code-signing-using-a-yubihsm-2-hardware-token-from-yubico%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.thegoodpenguin.co.uk%2Fblog%2Fi-mx-code-signing-using-a-yubihsm-2-hardware-token-from-yubico%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2149446%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20HAB4%20Secure%20Boot%20Keys%20Stored%20on%20YubiKey%205%20Nano%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2149446%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3CBR%20%2F%3E%3CBR%20%2F%3EUnfortunately%20I%20do%20not%20have%20experience%20using%20Yubikey%2C%20so%20I%20cannot%20be%20completely%20sure%20if%20this%20can%20be%20used%20or%20not%20but%20will%20double%20check%2C%20as%20far%20as%20I%20know%20from%20your%20description%20you%20want%20to%20create%20a%20signed%20image%20with%20keys%20stored%20in%20the%20Yubikey%2C%20is%20this%20correct%3F%3CBR%20%2F%3E%3CBR%20%2F%3EBest%20regards%2FSaludos%2C%3CBR%20%2F%3EAldo.%3C%2FP%3E%3C%2FLINGO-BODY%3E