iMX8M Mini Yocto secure boot

cancel
Showing results for 
Search instead for 
Did you mean: 

iMX8M Mini Yocto secure boot

394 Views
antonio_santagi
Contributor IV

Hello,

I am using iMX8M Mini .

I haven't found any references to possibility of automatically signing bootloaders and images by Yocto for HAB secure Boot.

I read 

IMX8M YOCTO how to sign image to secure boot  

and 

mx8m_mx8mm_secure_boot.txt\guides\habv4\imx\doc - uboot-imx - i.MX U-Boot  

But there are manual steps to get offsets and other data from images just build and feed CST tool with them to produce signed images.

Are there Yocto layers implementing this automatically ?

thank you

Tags (3)
0 Kudos
2 Replies

91 Views
petter-osterlund
Contributor I

Perhaps not easy but possible, something like this would be very very useful if NXP could incorporate

https://www.digi.com/resources/documentation/digidocs/embedded/dey/3.0/cc8mmini/yocto-trustfence_t_s...

0 Kudos

271 Views
gusarambula
NXP TechSupport
NXP TechSupport

Hello Antonio Santagiuliana,

The Linux BSP for i.MX does not have recipes that allow for automation of this process and I haven’t seen any similar recipes on the Yocto Project layers outside of our BSP either. This because the process requires several steps that will depend on your configuration and are not easy to automate. Although you may create your own recipes or scripts to automate as much as possible, this is not a trivial task.

My apologies for the inconvenience.

Regards,