Run unsigned kernel and dtb images on closed device

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

Run unsigned kernel and dtb images on closed device

1,271件の閲覧回数
mohamed-ali_fod
Contributor I

Hi,

Is it possible to run unsigned kernel and dtb on closed imx6 device using signed u-boot but without CONFIG_SECURE_BOOT and CONFIG_IMX_HUB config flags (so the authentication steps done by u-boot for the kernel and dtb will not be performed) ?

Best regards,

Mohamed Ali

 

0 件の賞賛
返信
2 返答(返信)

1,239件の閲覧回数
Harvey021
NXP TechSupport
NXP TechSupport

Hi @mohamed-ali_fod 

Should be no problem to run Kernel and dtb. But not sure why you do that, as you see (uboot-imx/mx6_mx7_secure_boot.txt at lf_v2022.04 · nxp-imx/uboot-imx · GitHub)

1.1 Building a u-boot-dtb.imx image supporting secure boot

The U-Boot provides support to secure boot configuration and also provide
access to the HAB APIs exposed by the ROM vector table, the support is
enabled by selecting the CONFIG_IMX_HAB option.

When built with this configuration, the U-Boot provides extra functions for
HAB, such as the HAB status logs retrievement through the hab_status command
and support for extending the root of trust.

 

Best regards

Harvey

0 件の賞賛
返信

1,233件の閲覧回数
mason2036
Contributor I

Harvey,

That is your description:

 

1.1 Building a u-boot-dtb.imx image supporting secure boot

The U-Boot provides support to secure boot configuration and also provide
access to the HAB APIs exposed by the ROM vector table, the support is
enabled by selecting the CONFIG_IMX_HAB option.

When built with this configuration, the U-Boot provides extra functions for
HAB, such as the HAB status logs retrievement through the hab_status command
and support for extending the root of trust.

 

This is u-boot software to do that. It is optional. authenticating any data, here is kernel and/or dtb, is customized software. Again, it is software.

Authenticating boot loader, here is u-boot of i.MX6, is mandatory. It is ROM code to do that. 

 

Here is your "why":

"But not sure why you do that"

My question is, why you ask "why"? 

and you copy the description of "1.1 Building a u-boot-dtb.imx image supporting secure boot"

Have you even read it by yourself before you put here. 

 

0 件の賞賛
返信