Hello NXP Experts,
I have followed this guide uboot-imx/doc/imx/ahab/guides/mx8ulp_9x_secure_boot.txt at lf_v2023.04 · nxp-imx/uboot-imx in order to generate a PKI Tree and SRK_Table compatible with my target: IMX9332.
I have followed also the "i.MX Linux User's Guide" chapter "10.9.1 Automated image signing for secure boot", in order to generate a signed image with Yocto.
Looking at the generated binaries, I have found the SRK_Table generated, so I'm confident that bitbake works correctly.
I have also flashed my EVK with UUU.
In u-boot, I runned ahab_status and below there is the result:
.
Looking on other ticket in this wonderfull community, It seems that the problem is that I have not flashed the eFuse (and I did not).
What can I do If I want to test the signature on the SWs over the public keys in the SRK Table flashed? In other terms, Can I flash an OS without signature and during the boot I will have an error on the signature?
Please help me!
Regards,
Alessandro.