Secure boot fails when upgrade u-boot

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

Secure boot fails when upgrade u-boot

903件の閲覧回数
tuyennguyen
Contributor I

Hi experts,

I am having a device based on IMX6ULG3 that works well with secure boot from u-boot-imx_2016-03 and linux 4.1.15. HAB tree of keys and certificates were generated, signing scripts, csf templates were generated. They all work great with u-boot-imx_2016-3.

Because of security, I am upgrading u-boot-imx_2016-03 to u-boot-imx_2020-04 along with linux 5.4.70. U-boot works find in non-secure boot. Using the same cst tool, certificates, scripts, templates... to sign u-boot-imx_2020-04, but secure boot fails with HAB_INV_CERTIFICATE. Could you help me to address the issue? Thank you very much

CONFIG_IMX_HAB=y

CONFIG_CSF_SIZE=0x2000 (0x2060 as default does not work either)

tuyennguyen_0-1630614599502.png

 

ラベル(3)
0 件の賞賛
返信
1 返信

879件の閲覧回数
igorpadykov
NXP Employee
NXP Employee

Hi Carrie

 

answer from team:

---------------

Please let customer share us the csf file and all the binaries for both version. It seems like that the IVT header part is invalid. 

---------------

Best regards
igor

 

0 件の賞賛
返信