Hello @Yuri
Maybe I could have below understanding, check my point, please.
1. Our verify process could only support from power on to kernel start, this means that the uboot could verify the kernel but kernel can not do more.
2. if we can not use the imx-mkimage to generate a container that how to use the cst tool to sign it?