imx 93 Win10 IoT: Securing UEFI and Windows

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

imx 93 Win10 IoT: Securing UEFI and Windows

442 次查看
aditya_h
Contributor II

I am currently exploring secure boot for imx93. I was able to enable secure boot up to UEFI stage using steps given in user guide (User Guide) . But steps for securing UEFI and windows image is not clearly described. For securing UEFI we need PK,KEK and databases. Do I need to create all the variables or it should be already present? If it is already present how do I enable it?

标签 (1)
0 项奖励
回复
2 回复数

385 次查看
Naveen_V_M
Contributor I

Do we need to create the Signature Database and forbidden signature database explicitly or are they part of UEFI infrastructure?

0 项奖励
回复

416 次查看
Harvey021
NXP TechSupport
NXP TechSupport

UEFI and Windows use their own chain of trust, which is composed of Platform Key (PK), Key Exchange Key
(KEK), forbidden signature database (dbx) and valid signature database (db). Those credentials are stored as
UEFI Secure variables. Those variables must be programmed at OEM site.

 

Regards

Harvey

0 项奖励
回复