Hi experts,
I am having a device based on IMX6ULG3 that works well with secure boot from u-boot-imx_2016-03 and linux 4.1.15. HAB tree of keys and certificates were generated, signing scripts, csf templates were generated. They all work great with u-boot-imx_2016-3.
Because of security, I am upgrading u-boot-imx_2016-03 to u-boot-imx_2020-04 along with linux 5.4.70. U-boot works find in non-secure boot. Using the same cst tool, certificates, scripts, templates... to sign u-boot-imx_2020-04, but secure boot fails with HAB_INV_CERTIFICATE. Could you help me to address the issue? Thank you very much
CONFIG_IMX_HAB=y
CONFIG_CSF_SIZE=0x2000 (0x2060 as default does not work either)
Hi Carrie
answer from team:
---------------
Please let customer share us the csf file and all the binaries for both version. It seems like that the IVT header part is invalid.
---------------
Best regards
igor