Hello Yuri
I have followed the HAB procedure , signing the kernel image is also fine and I loaded it with load mmc and checked with hab_auth_image as suggested in https://boundarydevices.com/high-assurance-boot-hab-i-mx8m-edition/
I get no HAB Events for both u-boot and kernel , that said I have not burned the fuses yet..
1. Is there a way to use shadow register and verify the signed images are fine before burning the fuses ?
2. The platform is i.MX8mm and we are having Android Pie on it. Is the Kernel verification in HAB required as we will have AVB too ?
If Kernel verification in HAB is not required , any code of u-boot which does this has to be commented ?
3. AVB , keystore provisioing/rpmb keys etc. other security features, should any of these be done before burning the fuses for HAB ? we have not enabled any of these on the platform yet.
Regards,
Keerthi
@keerthi-karanth
Hello,
Theoretically it is possible to use the shadow register, but we do not have
considerations how to implement it.
As for Android - please refer to "i.MX Android Security User’s Guide".
https://www.nxp.com/docs/en/user-guide/IMX_ANDROID_SECURITY_USERS_GUIDE.pdf
Regards,
Yuri.