Unable to export NXP_PROD_KA_PUB on imx93

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Unable to export NXP_PROD_KA_PUB on imx93

Jump to solution
2,209 Views
JonhDoe
Contributor II

Hello, 

Following the response I got from this forum question  here , this seems to be the thing we are looking for. However, we are unable to export NXP_PROD_KA_PUB key at id 0x70000000. 

We tried from the linux userspace with the nvm_daemon, which starts correctly but fails when trying to export it when sending the ELE message.

We also tried from U-Boot and spdsk and the problem still persists : 

user@vbox:/data/gitclone/src_spsdk/spsdk$ uv run spsdk nxpele -f mimx9352 -p /dev/ttyACM0 -d uboot_serial export-nxp-prod-ka-puk -o file
Step 1/4: Initializing SAB...
SAB Init successful
Step 2/4: Opening session...
Session opened successfully. Handle: 0xE59B04F0
Step 3/4: Opening keystore...
Keystore opened successfully. Handle: 0xE59B0970
Step 4/4: Exporting public key...
Error during NXP Production Key Agreement Public Key export: SPSDK: ELE Message failed.
Command: PUBLIC_KEY_EXPORT_REQ - (0x32)
Command words: 7
Command data: False
Response words: 4
Response data: True
Response status: Failure
Response indication: ResponseIndication:Unknown_0x1b - (0x1b)
Response abort code: 0x0

Public Key Export Command:
- Key store handle: 0xE59B0970
- Key ID: 0x70000000
- Output buffer size: 64 bytes
- Exports public key of asymmetric key from key store
- Public key is re-calculated (except Twisted Edwards/Montgomery)
- Must be called after opening valid key store service

Key store handle: 0xE59B0970
Key ID: 0x70000000
Output public key size: 0 bytes
No public key data received

Cleaning up: Closing keystore...
Cleaning up: Closing session...
Failed to export NXP Production Key Agreement Public Key

And everything seems correct from get-info, SRKH is fused and from my knowledge the device does not needs to be OEM closed to export it. Below is the content of get-info : 

user@vbox:/data/gitclone/src_spsdk/spsdk$ uv run spsdk nxpele -f mimx9352 -p /dev/ttyACM0 -d uboot_serial get-info
ELE get info ends successfully:
Command: 0xda
Version: 2
Length: 160
SoC ID: MX93 - 0x9300
SoC version: A100
Life Cycle: OEM_OPEN - 0x0010
SSSM state: 4
Attest API version: 2
UUID: 86ee42794bb64887bddcb53e5666e040
SHA256 ROM PATCH: e9b0338e5f4a0a92025f764c5eeae2d26be1211c77ee51e49a9ee36a7185d587
SHA256 FW: 7d0dd0b6d993e4df39eb69cee18b4f7eb6ac1622aaf7d144c25c00cc4908ca60
Advanced information:
OEM SRKH: 2a6b7811117a8f2d16e1b506b587f6f44e2e444111f8ec7df047eec5200e6fd9
IMEM state: The IMEM is fully loaded and all ELE functionality can be used - 0xCA
CSAL state: EdgeLock secure enclave random context initialization succeed - 0x02
TRNG state: TRNG entropy is valid and ready to be read - 0x03

 

Thanks in advance for your response.

0 Kudos
Reply
1 Solution
2,122 Views
JonhDoe
Contributor II

Hello again, 

I just needed to update the ELE fw, I mark this as solved.

Thanks for your time.

View solution in original post

Tags (1)
0 Kudos
Reply
3 Replies
2,135 Views
Harvey021
NXP TechSupport
NXP TechSupport

Hello,

Which version of BSP and ELE FW are you using? 

 

Best regards

Harvey

0 Kudos
Reply
2,131 Views
JonhDoe
Contributor II
Hello Harvey,

We are using lf-6.12-y for linux, lf_2024.07 for u-boot and here is the output of "get-ele-fw-version":
(spsdk) eliott@vbox:/data/gitclone/src_spsdk/spsdk$ uv run nxpele -f mimx9352 -p /dev/ttyUSB0 -d uboot_serial get-ele-fw-version

Get ELE firmware version ends successfully:
EdgeLock Enclave firmware version: 0800000B
Readable form: 0.0.11
Commit SHA1 (First 4 bytes): 33CDA99A

John
0 Kudos
Reply
2,123 Views
JonhDoe
Contributor II

Hello again, 

I just needed to update the ELE fw, I mark this as solved.

Thanks for your time.

Tags (1)
0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2232723%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EUnable%20to%20export%20NXP_PROD_KA_PUB%20on%20imx93%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2232723%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%26nbsp%3B%3C%2FP%3E%3CP%3EFollowing%20the%20response%20I%20got%20from%20this%20forum%20question%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fi-MX-Processors%2Fquot-Fleet-certificate-quot-on-imx93%2Fm-p%2F2205862%2Femcs_t%2FS2h8ZW1haWx8YWNjZXB0X2FzX3NvbHV0aW9uX3JlbWluZGVyfE1JODMyVzFGRUIzWU9BfDIyMDU4NjJ8T1RIRVJTfGhL%23M242210%20%22%20target%3D%22_self%22%3Ehere%26nbsp%3B%3C%2FA%3E%2C%20this%20seems%20to%20be%20the%20thing%20we%20are%20looking%20for.%20However%2C%20we%20are%20unable%20to%20export%20NXP_PROD_KA_PUB%20key%20at%20id%26nbsp%3B0x70000000.%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20tried%20from%20the%20linux%20userspace%20with%20the%20nvm_daemon%2C%20which%20starts%26nbsp%3Bcorrectly%20but%20fails%20when%20trying%20to%20export%20it%20when%20sending%20the%20ELE%20message.%3C%2FP%3E%3CP%3EWe%20also%20tried%20from%20U-Boot%20and%20spdsk%20and%20the%20problem%20still%20persists%20%3A%26nbsp%3B%3C%2FP%3E%3CP%3Euser%40vbox%3A%2Fdata%2Fgitclone%2Fsrc_spsdk%2Fspsdk%24%20uv%20run%20spsdk%20nxpele%20-f%20mimx9352%20-p%20%2Fdev%2FttyACM0%20-d%20uboot_serial%20export-nxp-prod-ka-puk%20-o%20file%3CBR%20%2F%3EStep%201%2F4%3A%20Initializing%20SAB...%3CBR%20%2F%3ESAB%20Init%20successful%3CBR%20%2F%3EStep%202%2F4%3A%20Opening%20session...%3CBR%20%2F%3ESession%20opened%20successfully.%20Handle%3A%200xE59B04F0%3CBR%20%2F%3EStep%203%2F4%3A%20Opening%20keystore...%3CBR%20%2F%3EKeystore%20opened%20successfully.%20Handle%3A%200xE59B0970%3CBR%20%2F%3EStep%204%2F4%3A%20Exporting%20public%20key...%3CBR%20%2F%3EError%20during%20NXP%20Production%20Key%20Agreement%20Public%20Key%20export%3A%20SPSDK%3A%20ELE%20Message%20failed.%3CBR%20%2F%3ECommand%3A%20PUBLIC_KEY_EXPORT_REQ%20-%20(0x32)%3CBR%20%2F%3ECommand%20words%3A%207%3CBR%20%2F%3ECommand%20data%3A%20False%3CBR%20%2F%3EResponse%20words%3A%204%3CBR%20%2F%3EResponse%20data%3A%20True%3CBR%20%2F%3EResponse%20status%3A%20Failure%3CBR%20%2F%3EResponse%20indication%3A%20ResponseIndication%3AUnknown_0x1b%20-%20(0x1b)%3CBR%20%2F%3EResponse%20abort%20code%3A%200x0%3C%2FP%3E%3CP%3EPublic%20Key%20Export%20Command%3A%3CBR%20%2F%3E-%20Key%20store%20handle%3A%200xE59B0970%3CBR%20%2F%3E-%20Key%20ID%3A%200x70000000%3CBR%20%2F%3E-%20Output%20buffer%20size%3A%2064%20bytes%3CBR%20%2F%3E-%20Exports%20public%20key%20of%20asymmetric%20key%20from%20key%20store%3CBR%20%2F%3E-%20Public%20key%20is%20re-calculated%20(except%20Twisted%20Edwards%2FMontgomery)%3CBR%20%2F%3E-%20Must%20be%20called%20after%20opening%20valid%20key%20store%20service%3C%2FP%3E%3CP%3EKey%20store%20handle%3A%200xE59B0970%3CBR%20%2F%3EKey%20ID%3A%200x70000000%3CBR%20%2F%3EOutput%20public%20key%20size%3A%200%20bytes%3CBR%20%2F%3ENo%20public%20key%20data%20received%3C%2FP%3E%3CP%3ECleaning%20up%3A%20Closing%20keystore...%3CBR%20%2F%3ECleaning%20up%3A%20Closing%20session...%3CBR%20%2F%3EFailed%20to%20export%20NXP%20Production%20Key%20Agreement%20Public%20Key%3CBR%20%2F%3E%3CBR%20%2F%3EAnd%20everything%20seems%20correct%20from%20get-info%2C%20SRKH%20is%20fused%20and%20from%20my%20knowledge%20the%20device%20does%20not%20needs%20to%20be%20OEM%20closed%20to%20export%20it.%20Below%20is%20the%20content%20of%20get-info%20%3A%26nbsp%3B%3C%2FP%3E%3CP%3Euser%40vbox%3A%2Fdata%2Fgitclone%2Fsrc_spsdk%2Fspsdk%24%20uv%20run%20spsdk%20nxpele%20-f%20mimx9352%20-p%20%2Fdev%2FttyACM0%20-d%20uboot_serial%20get-info%3CBR%20%2F%3EELE%20get%20info%20ends%20successfully%3A%3CBR%20%2F%3ECommand%3A%200xda%3CBR%20%2F%3EVersion%3A%202%3CBR%20%2F%3ELength%3A%20160%3CBR%20%2F%3ESoC%20ID%3A%20MX93%20-%200x9300%3CBR%20%2F%3ESoC%20version%3A%20A100%3CBR%20%2F%3ELife%20Cycle%3A%20OEM_OPEN%20-%200x0010%3CBR%20%2F%3ESSSM%20state%3A%204%3CBR%20%2F%3EAttest%20API%20version%3A%202%3CBR%20%2F%3EUUID%3A%2086ee42794bb64887bddcb53e5666e040%3CBR%20%2F%3ESHA256%20ROM%20PATCH%3A%20e9b0338e5f4a0a92025f764c5eeae2d26be1211c77ee51e49a9ee36a7185d587%3CBR%20%2F%3ESHA256%20FW%3A%207d0dd0b6d993e4df39eb69cee18b4f7eb6ac1622aaf7d144c25c00cc4908ca60%3CBR%20%2F%3EAdvanced%20information%3A%3CBR%20%2F%3EOEM%20SRKH%3A%202a6b7811117a8f2d16e1b506b587f6f44e2e444111f8ec7df047eec5200e6fd9%3CBR%20%2F%3EIMEM%20state%3A%20The%20IMEM%20is%20fully%20loaded%20and%20all%20ELE%20functionality%20can%20be%20used%20-%200xCA%3CBR%20%2F%3ECSAL%20state%3A%20EdgeLock%20secure%20enclave%20random%20context%20initialization%20succeed%20-%200x02%3CBR%20%2F%3ETRNG%20state%3A%20TRNG%20entropy%20is%20valid%20and%20ready%20to%20be%20read%20-%200x03%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EThanks%20in%20advance%20for%20your%20response.%3C%2FP%3E%3C%2FLINGO-BODY%3E