Secure boot fails when upgrade u-boot

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

Secure boot fails when upgrade u-boot

891 次查看
tuyennguyen
Contributor I

Hi experts,

I am having a device based on IMX6ULG3 that works well with secure boot from u-boot-imx_2016-03 and linux 4.1.15. HAB tree of keys and certificates were generated, signing scripts, csf templates were generated. They all work great with u-boot-imx_2016-3.

Because of security, I am upgrading u-boot-imx_2016-03 to u-boot-imx_2020-04 along with linux 5.4.70. U-boot works find in non-secure boot. Using the same cst tool, certificates, scripts, templates... to sign u-boot-imx_2020-04, but secure boot fails with HAB_INV_CERTIFICATE. Could you help me to address the issue? Thank you very much

CONFIG_IMX_HAB=y

CONFIG_CSF_SIZE=0x2000 (0x2060 as default does not work either)

tuyennguyen_0-1630614599502.png

 

标签 (3)
0 项奖励
回复
1 回复

867 次查看
igorpadykov
NXP Employee
NXP Employee

Hi Carrie

 

answer from team:

---------------

Please let customer share us the csf file and all the binaries for both version. It seems like that the IVT header part is invalid. 

---------------

Best regards
igor

 

0 项奖励
回复