IMX8MP secure boot signs a container image that includes the Kernel and DTB

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IMX8MP secure boot signs a container image that includes the Kernel and DTB

570 Views
ZongYue
Contributor I

Hi,

Is i.MX8MP Secure Boot supports signing a container image that includes both the Kernel and Device Tree Blob (DTB)?

I found an example for iMX8QM where soc.mak in imx-mkimage modifies "flash_kernel", but soc.mak in imx8mp does not have "flash_kernel".
Can soc.mak in imx8mp produce a container image with Kernel and DTB like soc.mak in iMX8QM?

 

Best regards

0 Kudos
Reply
5 Replies

552 Views
Harvey021
NXP TechSupport
NXP TechSupport

Hi,

Please have a reference to the section <3. Authenticating additional boot images> of This guide 

 

Regards

Harvey

0 Kudos
Reply

515 Views
ZongYue
Contributor I

Hi Harvey021,

I would like to use a Kernel + DTB ITB container image and sign it using NXP’s sign-tool.
In this case, what information or sections are required in the .its file to ensure that both the Kernel and DTB are properly signed?


Are there any sample .its files or reference examples available for this purpose?

And would it be possible to provide an example of how to run the sign-tool command with this case?

 

Regards,

ZongYue

0 Kudos
Reply

507 Views
Harvey021
NXP TechSupport
NXP TechSupport

Hi @ZongYue 

We don't have such implementation container structure for i.MX8MP.

 

Regards

Harvey

0 Kudos
Reply

502 Views
ZongYue
Contributor I

Hi @Harvey021 

Based on the documents introduction_ahab.txt, sign_os_cntr.txt, mx8_mx8x_secure_boot.txt, and csf_linux_img.txt, as well as the related web resources, it is mentioned that tools such as "sign_tool" and "nxpimage" are available. 

I would appreciate it if you could provide the official download links or instructions for obtaining these tools.

Regards

ZongYue

0 Kudos
Reply

495 Views
Harvey021
NXP TechSupport
NXP TechSupport

Hi @ZongYue 

Here are three tools might help as your requirements.

IMX_CST_TOOL_NEW 

nxp-cst-signer 

spsdk 

 

Regards

Harvey

0 Kudos
Reply