IMX8M - No HAB event while SRK_HASH is undefined

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

IMX8M - No HAB event while SRK_HASH is undefined

ソリューションへジャンプ
1,222件の閲覧回数
Romain-PC
Contributor II

Hi,

I'm experimenting with the HAB on IMX8M, I'm using a U-boot image that I would like to verify on boot.

Once the HAB is activated, the hab_status command generates 4 HAB events. Which is normal since the image is not signed.
However once the image is signed with my keys, I no longer have any HAB event. I didn't burn SRK_HASH.

Is it normal behavior not to throw an error when no hashes are burned in the fuses? (i.e. bank 6 and 7 all bits at 0).
Besides, does the hab_status command allow you to recheck the image after boot? Allowing to experiment with fuse override.

Best regards,

Romain.

ラベル(1)
タグ(3)
0 件の賞賛
返信
1 解決策
1,140件の閲覧回数
hector_delgado
NXP TechSupport
NXP TechSupport

Hi @Romain-PC ,

I hope you're doing well. This depends on the HAB version you're using. I'll attach a screenshot from one of our application notes that goes into detail regarding version differences regarding SRK_HASH check in open mode. I would also recommend checking the following guides:

hash_check_HABVersions.png

Let me know if this information was useful.

Best regards,
Hector.

 

元の投稿で解決策を見る

0 件の賞賛
返信
4 返答(返信)
1,190件の閲覧回数
hector_delgado
NXP TechSupport
NXP TechSupport

Hi @Romain-PC ,

I hope you're doing well. Could you let us know which i.MX 8M are you using exactly? And is it a custom board or one of our EVKs? Thank you.

Best regards,
Hector.

0 件の賞賛
返信
1,183件の閲覧回数
Romain-PC
Contributor II

Hi @hector_delgado 

I am using an i.MX 8M Quad. It is a custom board : Boundary Devices Nitrogen 8M rev 1.1.

Moreover, when the signed image is verified, there is therefore no HAB event, but there is also no message "No HAB event".

Best regards,

Romain.

0 件の賞賛
返信
1,141件の閲覧回数
hector_delgado
NXP TechSupport
NXP TechSupport

Hi @Romain-PC ,

I hope you're doing well. This depends on the HAB version you're using. I'll attach a screenshot from one of our application notes that goes into detail regarding version differences regarding SRK_HASH check in open mode. I would also recommend checking the following guides:

hash_check_HABVersions.png

Let me know if this information was useful.

Best regards,
Hector.

 

0 件の賞賛
返信
1,133件の閲覧回数
Romain-PC
Contributor II

Hi,

I missed this array, thank you it's really clear !

Best regards,

Romain.

0 件の賞賛
返信