i.MX8M Nano Secure Boot (HABv4) Compliance

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

i.MX8M Nano Secure Boot (HABv4) Compliance

跳至解决方案
168 次查看
Nethaji1510
Contributor II

Hello Team,

            We have an IMX8MNano board. We have successfully enabled the HABv4 feature on this board and also signed the bootloader kernel and DTB file using the NXP code signing tool.


Our queries,
           Our understanding is that NXP supplied the "hab4_pki_tree.sh" script and the code signing tool for HABv4. The PKI keys were created using this "hab4_pki_tree.sh" script, and the image signatures were done using CST. But as per our cyber team compliance, we can't access the private key (it will reside in a secure server) in this case we cant use CST which require the private key. Can you provide us a solution for this?

0 项奖励
回复
1 解答
101 次查看
Nethaji1510
Contributor II

Ok. Thanks for your quick support @Harvey021

Hi @Harvey021,

Kindly share the NXP CST tool 3.3.1 source code package.

在原帖中查看解决方案

标记 (1)
0 项奖励
回复
2 回复数
133 次查看
Harvey021
NXP TechSupport
NXP TechSupport

Hi,

You can refer to the section <Using Code-Signing Tool with Hardware Security Module> CST User guide 

IMX_CST_TOOL_NEW 

 

Regards

Harvey

0 项奖励
回复
102 次查看
Nethaji1510
Contributor II

Ok. Thanks for your quick support @Harvey021

Hi @Harvey021,

Kindly share the NXP CST tool 3.3.1 source code package.

标记 (1)
0 项奖励
回复